1

Cybersecurity Grc Jobs (NOW HIRING)

They are looking for a Cybersecurity GRC Engineer who can bridge the gap between governance, risk, compliance, and technical security operations in a mission-driven healthcare environment. The role ...

$130 - $216/hr

Active Top Secret (TS) What You Will Do Guidehouse is seeking an experienced Cybersecurity Governance, Risk, and Compliance (GRC) Program Manager to lead a large, complex federal cybersecurity ...

Cybersecurity GRC Program Manager

Arlington, VA · On-site

$148K - $180K/yr

Guidehouse is seeking an experienced Cybersecurity Governance, Risk, and Compliance (GRC) Program Manager to lead a large, complex federal cybersecurity program supporting enterprise security ...

GRC Data Security - Cybersecurity Location: Phoenix, AZ Duration: 6 months Requested skills: · Cyber Security - GRC - Data Security - 7+ years · Experience conducting security architecture or ...

Guidehouse is seeking an experienced Cybersecurity Governance, Risk, and Compliance (GRC) Program Manager to lead a large, complex federal cybersecurity program supporting enterprise security ...

Showing results 41-60

Cybersecurity Grc information

See salary details

$38.5K

$58.2K

$87K

How much do cybersecurity grc jobs pay per year?

As of Sep 6, 2026, the average yearly pay for cybersecurity grc in the United States is $58,171.00, according to ZipRecruiter salary data. Most workers in this role earn between $48,000.00 and $64,500.00 per year, depending on experience, location, and employer.

What is Cybersecurity GRC?

Cybersecurity GRC stands for Governance, Risk, and Compliance in the context of cybersecurity. It involves establishing frameworks and processes to ensure an organization's information security aligns with business objectives, regulatory requirements, and risk management strategies. Professionals in this field help identify and manage security risks, create policies and controls, and ensure compliance with laws and standards such as GDPR, HIPAA, or ISO 27001. The goal of Cybersecurity GRC is to protect the organization’s digital assets while enabling responsible growth and innovation.

What are the key skills and qualifications needed to thrive as a Cybersecurity GRC professional?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of cybersecurity frameworks, risk management principles, and regulatory compliance, often supported by a degree in information security or a related field. Familiarity with tools like GRC platforms (e.g., RSA Archer, ServiceNow), as well as certifications such as CISSP, CISM, or CRISC, is typically required. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating with stakeholders and translating technical risks into business implications. These competencies ensure organizations can proactively manage cyber risks, meet regulatory requirements, and maintain trust with clients and partners.

What are some common challenges faced by professionals in Cybersecurity GRC roles, and how can they be addressed?

Professionals in Cybersecurity GRC (Governance, Risk, and Compliance) often encounter challenges such as keeping up with evolving regulatory requirements, balancing business objectives with security mandates, and fostering collaboration between IT, legal, and business teams. These challenges can be addressed by staying current with industry standards, utilizing automated tools for compliance tracking, and building strong communication channels across departments. Proactively engaging stakeholders and fostering a culture of security awareness also play a crucial role in overcoming these obstacles and ensuring effective risk management.

What is the difference between Cybersecurity Grc vs Cybersecurity Analyst?

AspectCybersecurity GrcCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentPolicy development, risk management, complianceThreat detection, incident response, vulnerability assessment
Employer & Industry UsageOrganizations focusing on governance and complianceSecurity operations centers, IT departments

Cybersecurity Grc professionals focus on establishing policies, managing risks, and ensuring compliance with regulations. In contrast, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require similar certifications and work within the cybersecurity field, Grc roles are more strategic and policy-oriented, whereas Analysts are more technical and operational.

Is cybersecurity GRC in demand?

Cybersecurity GRC (Governance, Risk, and Compliance) professionals are in high demand due to increasing cybersecurity threats and regulatory requirements. Organizations seek experts with skills in risk management, compliance frameworks, and security policies, often requiring certifications like CISSP or CISA. The role offers strong job growth prospects across various industries, including finance, healthcare, and technology.

Is cybersecurity GRC in high demand?

Cybersecurity GRC (Governance, Risk, and Compliance) professionals are in high demand due to increasing cybersecurity threats and regulatory requirements. Organizations seek experts with skills in risk management, compliance frameworks, and security policies, often requiring certifications like CISSP or CISA. The role offers strong job growth prospects across various industries.
More about Cybersecurity Grc jobs

What cities are hiring for Cybersecurity Grc jobs?

Cities with the most Cybersecurity Grc job openings:

What are the most commonly searched types of Cybersecurity Grc jobs?

The most popular types of Cybersecurity Grc jobs are:

What states have the most Cybersecurity Grc jobs?

States with the most job openings for Cybersecurity Grc jobs include:

What job categories do people searching Cybersecurity Grc jobs look for?

The top searched job categories for Cybersecurity Grc jobs are:

Infographic showing various Cybersecurity Grc job openings in the United States as of August 2026, with employment types broken down into 94% Full Time, 3% Part Time, and 3% Contract. Highlights an 81% Physical, 6% Hybrid, and 13% Remote job distribution, with an average salary of $58,171 per year, or $28 per hour.

Senior Cybersecurity GRC Analyst

AMRO Fabricating Corporation

Huntington Beach, CA • On-site

$120K - $136K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 11 days ago


Key responsibilities

  • Interprets and operationalizes cybersecurity, regulatory, contractual, and customer requirements with stakeholders.

  • Maintains cybersecurity governance artifacts including policies, standards, control documentation, and assurance schedules.

  • Evaluates control design, operating effectiveness, evidence sufficiency, and recommends corrective actions.


Job description

Karman Space & Defense is a leader in the rapid design, development, and production of critical, next-generation system solutions that align with the U.S. Department of War and its allies’ core mission priorities, and meet the accelerating demand for access to space. Building on nearly 50 years of success, we deliver Payload & Protection Systems, Aero/Hydrodynamic Interstage Systems, and Propulsion & Launch Systems to more than 80 prime contractors supporting over 130 space and defense programs.

This role helps drive enterprise-wide cybersecurity governance, risk, compliance, and assurance activities that strengthen control quality, evidence readiness, and risk management across Karman. You will translate regulatory, contractual, and customer requirements into clear controls and reliable evidence; independently assess control effectiveness and risk; and partner with business and technology owners to embed sustainable practices that support audit, assessment, and operational readiness.

Responsibilities

  • Interprets and operationalizes cybersecurity, regulatory, contractual, and customer requirements with business, legal, and technology stakeholders.
  • Maintains cybersecurity governance artifacts including policies, standards, control documentation, mappings, ownership records, and assurance schedules.
  • Evaluates control design, operating effectiveness, evidence sufficiency, exceptions, and residual risk and recommends corrective actions or escalation.
  • Supports sustainable CMMC Level 2, NIST SP 800‑171, DFARS, and Controlled Unclassified Information (CUI) obligations through assessment, evidence validation, remediation, and monitoring.
  • Maintains the Enterprise System Security Plan (SSP), Controlled Site Addenda, system boundaries, inventories, and supporting evidence across regulated environments.
  • Coordinates contractual, regulatory, and CAGE-code traceability, ensuring accurate alignment among obligations, boundaries, sites, and assessment records.
  • Supports Sarbanes‑Oxley (SOX) Information Technology General Controls (ITGC) through narrative development, testing coordination, evidence quality, exception identification, and remediation tracking.
  • Governs cybersecurity risks, exceptions, remediation plans, compensating controls, and acceptance records and prepares leadership-ready materials that translate issues into decisions and business impact.
  • Oversees identity, access, and vulnerability governance, including coverage, aging, remediation performance, exceptions, and validation of closure across responsible teams.
  • Coordinates cybersecurity reviews for third-party services, Software-as-a-Service (SaaS), artificial intelligence (AI) tools, suppliers, and M &A activities, ensuring security, privacy, data-handling, and evidence requirements are met.

Required Qualifications

  • Bachelor’s degree in cybersecurity, information technology, information systems, business, risk management, accounting, audit, or a related field; equivalent relevant experience may be considered.
  • 5+ years of progressive experience in cybersecurity governance, risk, compliance (GRC), IT audit, risk management, control assurance, or related disciplines.
  • Experience assessing control design, operating effectiveness, and evidence sufficiency and translating findings into practical remediation and leadership reporting.
  • Working knowledge of CMMC Level 2, NIST SP 800‑171, DFARS, CUI, SOX ITGC, or comparable regulated control environments.
  • Experience maintaining cybersecurity policies, control narratives, SSPs or equivalent system documentation, evidence repositories, risk registers, Plans of Action and Milestones (POA &Ms), and remediation trackers.
  • Ability to exercise independent judgment, challenge unsupported conclusions, organize complex requirements, and escalate material risk appropriately.
  • Strong written, analytical, presentation, and stakeholder-management skills across technical teams, business owners, auditors, assessors, vendors, sites, and executives.
  • Proficiency with Microsoft 365 tools, including Excel, PowerPoint, Word, Teams, SharePoint, and Outlook.

Preferred Qualifications

  • Experience in aerospace, defense, manufacturing, engineering, or another highly regulated environment.
  • Experience supporting CMMC Level 2 readiness, NIST SP 800‑171 assessments, DFARS compliance, CUI governance, Supplier Performance Risk System (SPRS) requirements, or defense‑contractor cybersecurity needs.
  • Experience with SOX ITGC, internal or external audit, control testing, information technology risk, and remediation governance.
  • Experience with SSPs, site-specific control documentation, specialized‑asset scoping, CUI flows, system boundaries, evidence validation, and POA &M management.
  • Experience with supplier cyber risk, SaaS and AI governance, M &A due diligence, international operations, export controls, or cross-border access risk.
  • Experience using Governance, Risk, and Compliance (GRC) or audit platforms such as ServiceNow, Jira, Archer, AuditBoard, Drata, Vanta, or Hyperproof.
  • Security+, Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Governance, Risk and Compliance (CGRC), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Cybersecurity Maturity Model Certification Certified CMMC Professional (CMMC CCP), or comparable certification.

This position requires U.S. person status under U.S. export control laws, including U.S. citizens and nationals, lawful permanent residents, refugees, and asylees.

Benefits

  • Medical, dental, and vision insurance
  • 401(k) with company match
  • Paid time off
  • Health Savings Account (HSA) with company contribution
  • Flexible Spending Accounts (FSA)
  • Company‑paid life and AD &D insurance
  • Short‑ and long‑term disability coverage
  • Tuition reimbursement

Karman Space and Defense is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, protected veteran status, or any other status protected by applicable law.