2

Full Time Cyber Security Grc Jobs (NOW HIRING)

Cybersecurity GRC Engineer

New York, NY · On-site

$99K - $150K/yr

Emp Status Regular Full time Work Shift Compensation Range The base pay scale for this position is ... We are looking for a Cybersecurity GRC Engineer who can bridge the gap between governance, risk ...

Be Seen First

GRC Cybersecurity Specialist

Austin, TX · On-site

$115K - $144K/yr

Direct Hire / Full-Time Work Arrangement: Onsite Work Authorization: U.S. Citizen or Green Card Holder required Our client is seeking an experienced Cybersecurity Governance, Risk & Compliance (GRC ...

Participate in the on-boarding of clients into GRC tools like Apptega. * Provide training and ... Job Type: Full-time; Work mostly from home and occasionally at client sites. Benefits: Medical ...

next page

Showing results 1-20

Full Time Cyber Security Grc information

See salary details

$40.5K

$122.9K

$180K

How much do full time cyber security grc jobs pay per year?

As of Aug 22, 2026, the average yearly pay for full time cyber security grc in the United States is $122,890.00, according to ZipRecruiter salary data. Most workers in this role earn between $102,000.00 and $142,000.00 per year, depending on experience, location, and employer.

What is a full time Cyber Security GRC professional?

Full Time Cyber Security GRC (Governance, Risk, and Compliance) professionals are experts who help organizations identify, assess, and manage cybersecurity risks in alignment with regulatory requirements and internal policies. They develop and implement frameworks, policies, and procedures to ensure the organization's digital information is protected and compliant with laws and standards. Their work often includes conducting risk assessments, monitoring compliance, and advising on best practices to mitigate cybersecurity threats. These professionals play a crucial role in maintaining an organization's security posture and ensuring data integrity across all systems.

What are the key skills and qualifications needed to thrive as a full time Cyber Security GRC professional?

To thrive as a Full Time Cyber Security GRC (Governance, Risk, and Compliance) professional, you need a solid understanding of information security principles, risk management frameworks, and regulatory requirements, often demonstrated by a relevant degree and certifications like CISSP or CISA. Familiarity with tools such as GRC platforms (e.g., RSA Archer), risk assessment software, and compliance management systems is typical for this role. Strong analytical thinking, attention to detail, effective communication, and stakeholder management set exceptional professionals apart. These skills ensure that organizations can identify risks, maintain compliance, and build robust security postures in an evolving threat landscape.

What are the typical challenges faced by professionals in a full time Cyber Security GRC role, and how can they be addressed?

Professionals in full-time Cyber Security GRC (Governance, Risk, and Compliance) roles often face the challenge of keeping up with constantly evolving regulatory requirements and cyber threats. Balancing the needs of compliance with practical risk management can be complex, especially when collaborating with technical teams and business stakeholders. To address these challenges, strong communication skills, continuous learning, and staying updated with industry frameworks are essential. Many organizations support this by encouraging cross-departmental collaboration and providing opportunities for professional development.

What is the difference between Full Time Cyber Security Grc vs Cyber Security Analyst?

AspectFull Time Cyber Security GrcCyber Security Analyst
CertificationsISO 27001, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, compliance, risk managementThreat detection, incident response, system monitoring
Employer & Industry UsageOrganizations focusing on governance and complianceOrganizations focusing on security operations and analysis

Full Time Cyber Security Grc roles primarily focus on governance, risk management, and compliance activities, requiring certifications like ISO 27001 and CISA. Cyber Security Analysts concentrate on monitoring security threats and responding to incidents, often holding certifications like Security+ or CEH. While Grc roles emphasize policy and compliance, Analysts are more involved in technical threat detection. Both roles are essential in a comprehensive cybersecurity strategy but differ in daily tasks and focus areas.

More about Full Time Cyber Security Grc jobs

What cities are hiring for Full Time Cyber Security Grc jobs?

Cities with the most Full Time Cyber Security Grc job openings:

What are the most commonly searched types of Cyber Security Grc jobs?

The most popular types of Cyber Security Grc jobs are:

What states have the most Full Time Cyber Security Grc jobs?

States with the most job openings for Full Time Cyber Security Grc jobs include:

Infographic showing various Full Time Cyber Security Grc job openings in the United States as of August 2026, with employment types broken down into 87% Full Time, 11% Part Time, and 2% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $122,890 per year, or $59.1 per hour.

Cybersecurity GRC Engineer

HSS

New York, NY • On-site

$99K - $150K/yr

Full-time

Posted 17 days ago


Job description

How you move is why we're here. ®
Now more than ever.

Get back to what you need and love to do.
The possibilities are endless...
Now more than ever, our guiding principles are helping us in our search for exceptional talent - candidates who align with our unique workplace culture and who want to maximize the abundant opportunities for growth and success.
If this describes you then let's talk!
HSS is consistently among the top-ranked hospitals for orthopedics and rheumatology by U.S. News & World Report. As a recipient of the Magnet Award for Nursing Excellence, HSS was the first hospital in New York City to receive the distinguished designation. Whether you are early in your career or an expert in your field, you will find HSS an innovative, supportive and inclusive environment.
Working with colleagues who love what they do and are deeply committed to our Mission, you too can be part of our transformation across the enterprise.
Emp Status
Regular Full time
Work Shift
Compensation Range
The base pay scale for this position is $99,000.00 - $150,750.00. In addition, this position will be eligible for additional benefits consistent with the role. The salary of the finalist selected for this role will be determined based on various factors, including but not limited to: scope of role, level of experience, education, accomplishments, internal equity, budget, and subject to Fair Market Value evaluation. The hiring range listed is a good faith determination of potential compensation at the time of this job advertisement and may be modified in the future.
What you will be doing
PRINCIPAL DUTIES & RESPONSIBILITIES
Are you energized by the challenge of turning cybersecurity requirements into practical, measurable, and automated controls? We are looking for a Cybersecurity GRC Engineer who can bridge the gap between governance, risk, compliance, and technical security operations in a mission-driven healthcare environment.

This role is ideal for someone who understands both the language of security frameworks and the realities of modern technical infrastructure. You will help design, implement, validate, and continuously improve security controls across systems, applications, cloud platforms, vendors, and enterprise technologies. You will work closely with cybersecurity engineers, analysts, architects, IT teams, compliance partners, privacy stakeholders, and auditors to strengthen Hospital for Special Surgery's cybersecurity posture through risk-based, evidence-driven, and automation-enabled practices.
The Cybersecurity GRC Engineer will play a key role in advancing continuous compliance, improving audit readiness, supporting risk assessments, and developing repeatable methods for validating security controls. This position requires technical curiosity, sound judgment, strong documentation skills, and the ability to translate regulatory and framework requirements into actionable engineering outcomes.
Position Activities
  • Translate cybersecurity, privacy, regulatory, and framework requirements into technical control objectives, validation procedures, and measurable security outcomes.
  • Design, implement, and maintain automated workflows for security control testing, evidence collection, compliance monitoring, and audit readiness.
  • Develop and support policy-as-code, configuration checks, compliance dashboards, and repeatable validation methods to reduce manual assessment activities.
  • Perform technical risk assessments and gap analyses for new and existing technologies, systems, applications, cloud services, vendors, and business processes.
  • Partner with cybersecurity engineering, infrastructure, application, cloud, and networking teams to evaluate whether technical controls are implemented effectively and operating as intended.
  • Collaborate with IT and engineering teams to embed secure-by-design and data-by-default protection principles into applications, services, and infrastructure, while staying current on modern attack techniques and translating that knowledge into code and tooling.
  • Review operating systems, applications, cloud resources, network devices, security platforms, and third-party technologies against organizational policies, standards, and secure configuration baselines.
  • Correlate vulnerability findings, control gaps, compliance obligations, and business impact to support risk-based remediation prioritization.
  • Document control evidence, risk decisions, remediation plans, exceptions, and audit artifacts in a structured, accurate, and repeatable format.
  • Collaborate with internal stakeholders, external auditors, and compliance partners to support audits, assessments, regulatory inquiries, and control validation requests.
  • Develop metrics, reports, diagrams, and presentations that communicate cybersecurity risk, compliance posture, control effectiveness, and remediation status to technical and non-technical audiences.
  • Provide deep technical incident response support, including forensic analysis, custom scripting, and tool development during security investigations.
  • Performs other related duties as assigned.

Non-Discrimination Policy
Hospital for Special Surgery is committed to providing high quality care and skilled, compassionate, reliable service to our community in a safe and healing environment. Consistent with this commitment, Hospital for Special Surgery provides care, admits, and treats patients and provides all services without regard to age, race, color, creed, ethnicity, religion, national origin, culture, language, physical or mental disability, socioeconomic status, veteran or military status, marital status, sex, sexual orientation, gender identity or expression, or any other basis prohibited by federal, state, or local law or by accreditation standards.