2

Full Time Cyber Security Grc Jobs (NOW HIRING)

GRC Engineer

Foster City, CA ยท On-site

$210K - $320K/yr

You will operate the Cybersecurity Risk Register . You will be responsible for identifying ... This is a full-time role that can be held from our Foster City, CA office. The role has an in ...

Senior GRC Analyst

Boston, MA ยท On-site

$130K - $170K/yr

The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are ... S. base salary range for this full-time position is $130,000 - $170,000. Salary ranges are ...

This is a full-time position based at Sub-Zero Group's headquarters in Fitchburg, Wisconsin, just ... Contribute to governance, risk, compliance, cybersecurity, and responsible AI awareness initiatives ...

This is a full-time position based at Sub-Zero Group's headquarters in Fitchburg, Wisconsin, just ... Contribute to governance, risk, compliance, cybersecurity, and responsible AI awareness initiatives ...

GRC Analyst - Third Party Risk

Boston, MA ยท On-site

$70K - $110K/yr

Understanding of Cybersecurity compliance frameworks and cybersecurity compliance controls - ISO ... S. base salary range for this full-time position is $70,000 - $110,000. Salary ranges are ...

You will work directly with the Cybersecurity Manager and a vCISO partner, collaborate with the ... Join us in this full-time role, based in our Dallas Office at the Link: 2601 Olive Street, Dallas ...

Showing results 41-60

Full Time Cyber Security Grc information

See salary details

$40.5K

$122.9K

$180K

How much do full time cyber security grc jobs pay per year?

As of Aug 21, 2026, the average yearly pay for full time cyber security grc in the United States is $122,890.00, according to ZipRecruiter salary data. Most workers in this role earn between $102,000.00 and $142,000.00 per year, depending on experience, location, and employer.

What is a full time Cyber Security GRC professional?

Full Time Cyber Security GRC (Governance, Risk, and Compliance) professionals are experts who help organizations identify, assess, and manage cybersecurity risks in alignment with regulatory requirements and internal policies. They develop and implement frameworks, policies, and procedures to ensure the organization's digital information is protected and compliant with laws and standards. Their work often includes conducting risk assessments, monitoring compliance, and advising on best practices to mitigate cybersecurity threats. These professionals play a crucial role in maintaining an organization's security posture and ensuring data integrity across all systems.

What are the key skills and qualifications needed to thrive as a full time Cyber Security GRC professional?

To thrive as a Full Time Cyber Security GRC (Governance, Risk, and Compliance) professional, you need a solid understanding of information security principles, risk management frameworks, and regulatory requirements, often demonstrated by a relevant degree and certifications like CISSP or CISA. Familiarity with tools such as GRC platforms (e.g., RSA Archer), risk assessment software, and compliance management systems is typical for this role. Strong analytical thinking, attention to detail, effective communication, and stakeholder management set exceptional professionals apart. These skills ensure that organizations can identify risks, maintain compliance, and build robust security postures in an evolving threat landscape.

What are the typical challenges faced by professionals in a full time Cyber Security GRC role, and how can they be addressed?

Professionals in full-time Cyber Security GRC (Governance, Risk, and Compliance) roles often face the challenge of keeping up with constantly evolving regulatory requirements and cyber threats. Balancing the needs of compliance with practical risk management can be complex, especially when collaborating with technical teams and business stakeholders. To address these challenges, strong communication skills, continuous learning, and staying updated with industry frameworks are essential. Many organizations support this by encouraging cross-departmental collaboration and providing opportunities for professional development.

What is the difference between Full Time Cyber Security Grc vs Cyber Security Analyst?

AspectFull Time Cyber Security GrcCyber Security Analyst
CertificationsISO 27001, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, compliance, risk managementThreat detection, incident response, system monitoring
Employer & Industry UsageOrganizations focusing on governance and complianceOrganizations focusing on security operations and analysis

Full Time Cyber Security Grc roles primarily focus on governance, risk management, and compliance activities, requiring certifications like ISO 27001 and CISA. Cyber Security Analysts concentrate on monitoring security threats and responding to incidents, often holding certifications like Security+ or CEH. While Grc roles emphasize policy and compliance, Analysts are more involved in technical threat detection. Both roles are essential in a comprehensive cybersecurity strategy but differ in daily tasks and focus areas.

More about Full Time Cyber Security Grc jobs

What cities are hiring for Full Time Cyber Security Grc jobs?

Cities with the most Full Time Cyber Security Grc job openings:

What are the most commonly searched types of Cyber Security Grc jobs?

The most popular types of Cyber Security Grc jobs are:

What states have the most Full Time Cyber Security Grc jobs?

States with the most job openings for Full Time Cyber Security Grc jobs include:

Infographic showing various Full Time Cyber Security Grc job openings in the United States as of August 2026, with employment types broken down into 87% Full Time, 11% Part Time, and 2% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $122,890 per year, or $59.1 per hour.

GRC Engineer

Replit

Foster City, CA โ€ข On-site

$210K - $320K/yr

Full-time

Medical, Dental, Vision, Life, Retirement

Re-posted 9 days ago


Job description

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.
About the role
Replit is the agentic software creation platform that enables anyone to build applications using natural language. As we scale to support millions of developers and enterprise organizations, maintaining a robust, transparent, and technically sound Governance, Risk, and Compliance (GRC) program is critical.
We are looking for a GRC Engineer to serve as a key technical contributor for our compliance and risk management ecosystem. You will architect the systems and processes that automate trust, partnering deeply across the organization. We need a pragmatic operator who understands that GRC exists to enable the business-balancing rigorous standards with the velocity of a high-growth startup.
What You'll Do
Technical Excellence & Architecture
  • Technical Depth: Act as a technical subject matter expert for the GRC team. You will drive quality, technical depth, and operational efficiency in our security controls.
  • Program Architecture: Own the technical vision for Replit's GRC program, moving the team from manual workflows toward "Compliance-as-Code" and automated evidence collection.
  • Thought Leadership: Champion a culture of security and privacy across the company, educating teams on why controls exist rather than just enforcing them.

Cross-Functional Collaboration
  • Engineering & Architecture: Partner with Architects and Engineering Leads to "bake in" compliance requirements early in the design phase. You will translate complex technical implementations into narratives that satisfy frameworks without slowing down development.
  • Legal & Privacy: Work closely with Legal Counsel to interpret and implement requirements for Privacy (GDPR, CCPA) and emerging AI-specific regulations (e.g., EU AI Act).
  • Sales & GTM: Enable the Sales team by managing the Customer Trust Center and handling complex security questionnaires. You will serve as a subject matter expert in customer calls to build confidence with enterprise prospects.
  • Auditor Relationships: Own and cultivate the primary relationship with external auditors. You will serve as the bridge between auditors and internal teams, ensuring requests are reasonable, clear, and relevant to our tech stack.

Risk Management & Strategic Compliance
  • Risk Register Operator: You will operate the Cybersecurity Risk Register. You will be responsible for identifying, quantifying, and tracking risks, distinguishing between theoretical compliance gaps and meaningful business risks.
  • Framework Evolution: Manage and evolve our compliance posture across SOC 2, ISO 27001, and prepare the organization for future certifications in regulated markets (e.g., FedRAMP, ITAR, PCI, HIPAA).
  • Pragmatic Governance: Apply judgment to operate in "gray areas" when appropriate. You will prioritize issues that represent real security or business risk over "compliance theater."

Automation & Efficiency
  • Control Automation: Drive the shift from manual evidence collection to continuous monitoring. You will identify opportunities to automate audit work, ensuring GRC scales with the business.
  • Third-Party Risk: Architect a scalable framework for assessing third-party vendors and AI model providers, ensuring our supply chain remains secure without creating administrative bottlenecks.
Required Skills & Experience
  • 8+ years of experience in GRC or Information Security
  • Technical Fluency: Ability to speak the language of engineering, cloud (GCP/AWS), and security architecture. You can anticipate how architectural decisions impact risk and compliance.
  • Regulatory Breadth: Deep experience with SOC 2, ISO 27001, PCI, HIPPA, and Privacy laws.
  • Collaborative Communication: Strong ability to explain risk and tradeoffs to technical (Engineers), legal, and commercial (Sales/Execs) stakeholders.
  • Automation Mindset: Experience with GRC automation tools (e.g., Vanta, Drata) and a bias toward reducing manual toil.
Bonus Qualifications
  • Familiarity with FedRAMP, ITAR, or AI regulation is a strong plus.

What We Value
  • Pragmatism: You distinguish between "checking a box" and reducing risk. You focus on outcomes over optics.
  • Business Enablement: You understand that your role is to help Replit sell to the enterprise safely, supporting innovation through technical trust.
  • Solutions-Oriented: You are collaborative and low-ego. You prefer fixing root causes and empowering teams through automation over manual bureaucracy.
  • Clarity: You can take a complex regulation and explain exactly what it means for a specific engineering team in plain English.

This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday.
Full-Time Employee Benefits Include:
Competitive Salary & Equity
401(k) Program with a 4% match (US Only)
Health, Dental, Vision and Life Insurance
Short Term and Long Term Disability
Paid Parental, Medical, Caregiver Leave
Flexible Time Off (FTO) + Holidays
Commuter Benefits (In-Office & US Only)
Monthly Wellness Stipend
Autonomous Work Environment
In Office Set-Up Reimbursement (In-Office Only)
Quarterly Team Gatherings
In Office Amenities (In-Office Only)
Want to learn more about what we are up to?
  • Meet the Replit Agent
  • Replit: Make an app for that
  • Replit Blog
  • Amjad TED Talk

Interviewing + Culture at Replit
  • Operating Principles
  • Reasons not to work at Replit

To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.