1

Governance Risk And Compliance Jobs in California

Assisting in the upkeep of governance, risk and compliance (GRC) software applications Interacting with team members and department/division personnel on other GRC related tasks Documenting data and ...

Risk & Compliance Lead

El Segundo, CA ยท On-site

$115K - $168K/yr

As Risk & Compliance Lead , you will build and own Radiant's risk management function from the ... You will mature our programs into a proactive, structured risk governance, and you'll be the ...

Showing results 21-40

Governance Risk And Compliance information

See California salary details

$97.7K

$189.3K

$379K

How much do governance risk and compliance jobs pay per year?

As of Sep 5, 2026, the average yearly pay for governance risk and compliance in California is $189,252.00, according to ZipRecruiter salary data. Most workers in this role earn between $166,300.00 and $188,000.00 per year, depending on experience, location, and employer.

What are governance risk and compliance roles?

Governance, Risk, and Compliance (GRC) roles are positions within organizations focused on ensuring that business operations align with legal standards, manage risk effectively, and follow internal policies. Professionals in GRC help organizations set up frameworks to oversee compliance with laws and regulations, identify and mitigate potential risks, and establish governance structures to guide decision-making. These roles are essential for protecting organizations from financial, legal, and reputational harm while promoting ethical practices and efficient processes.

What are the key skills and qualifications needed to thrive as a governance risk and compliance professional?

To thrive as a Governance, Risk, and Compliance (GRC) professional, you need a solid understanding of regulatory frameworks, risk assessment methodologies, and compliance requirements, often supported by a degree in business, finance, or a related field. Familiarity with GRC platforms (like RSA Archer or MetricStream), audit management tools, and relevant certifications such as CISA, CRISC, or CISSP is highly beneficial. Strong analytical thinking, attention to detail, and effective communication skills set top performers apart in this field. These skills are crucial for identifying risks, ensuring organizational compliance, and supporting informed decision-making to protect the business.

What are some common challenges faced by professionals in governance risk and compliance roles, and how can they be addressed?

Professionals in Governance, Risk, and Compliance (GRC) roles often face challenges such as staying updated with changing regulations, ensuring company-wide adherence to policies, and managing cross-functional collaboration. To address these, GRC specialists must develop strong communication skills to educate and train staff, leverage technology to automate compliance tracking, and build effective relationships with departments such as IT, legal, and operations. Regular professional development and proactive engagement with regulatory updates are also key to overcoming these challenges and maintaining effective governance.

What is the difference between Governance Risk And Compliance vs Compliance Analyst?

AspectGovernance Risk And ComplianceCompliance Analyst
CertificationsISO 31000, ISO 27001, Certified Risk Management ProfessionalCertified Compliance & Ethics Professional (CCEP), ISO 19600
Work EnvironmentCorporate, regulated industries, risk management departmentsLegal, audit, compliance departments within organizations
Employer & Industry UsageFinancial services, healthcare, energy, governmentFinancial institutions, healthcare, manufacturing, retail

Governance Risk And Compliance professionals focus on establishing frameworks, managing risks, and ensuring overall compliance strategies across organizations. Compliance Analysts primarily focus on implementing and monitoring specific compliance policies, often within legal or audit teams. While both roles require understanding regulations and certifications, Governance Risk And Compliance roles have a broader scope involving risk management and governance structures.

Is governance risk and compliance a good career?

Governance, Risk, and Compliance (GRC) is a growing field that offers opportunities in industries such as finance, healthcare, and technology. It involves developing policies, managing risks, and ensuring regulatory adherence, often requiring certifications like CISA or CRISC. The role typically offers stable employment, competitive salaries, and the chance to work in a dynamic regulatory environment.

What is the work of governance risk and compliance?

Governance, Risk, and Compliance (GRC) professionals develop and implement policies to ensure organizations adhere to legal and regulatory requirements, manage risks effectively, and maintain ethical standards. They often use tools like risk assessments, audits, and compliance frameworks to identify vulnerabilities and ensure organizational integrity. This role requires strong analytical skills and knowledge of industry regulations.

What are popular job titles related to Governance Risk And Compliance jobs in California?

For Governance Risk And Compliance jobs in California, the most frequently searched job titles are:

What job categories do people searching Governance Risk And Compliance jobs in California look for?

The top searched job categories for Governance Risk And Compliance jobs in California are:

What cities in California are hiring for Governance Risk And Compliance jobs?

Cities in California with the most Governance Risk And Compliance job openings:

Infographic showing various Governance Risk And Compliance job openings in California as of August 2026, with employment types broken down into 1% As Needed, 87% Full Time, 9% Part Time, and 3% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $189,252 per year, or $91 per hour.

Governance, Risk & Compliance (GRC) Manager

Northwoodspace

Torrance, CA โ€ข On-site

$150K - $190K/yr

Full-time

Re-posted 17 days ago


Job description

Northwood is a modern space infrastructure company bringing the benefits of space to the masses through advanced communications technology. We are building a global network of phased array ground stations that enable real-time, reliable communication for satellite missions such as national security, global connectivity, and disaster response. With a vertically integrated approach, Northwood designs, builds, and rapidly deploys scalable systems that power the next generation of space missions. If you like solving complex challenges and seeing your work deployed around the world with real impact, Northwood is the place to do it.
Role:
As Governance, Risk & Compliance (GRC) Lead, you will own Northwood's compliance program across CMMC, FedRAMP, SOC 2, and ITAR - building the policies, processes, and evidence frameworks that enable the company to operate as a trusted dual-use space communications provider. This is a senior individual contributor role for a practitioner who combines deep regulatory knowledge with the technical fluency to work directly with security engineering, network, and product teams to translate compliance requirements into operational reality.
You will serve as the primary point of contact for government customers, third-party assessors, and internal stakeholders on all matters related to compliance posture, risk management, and audit readiness. You will work across Northwood's full security stack - spanning on-premises infrastructure, AWS GovCloud, GCC, and corporate systems - to ensure controls are implemented, documented, and defensible. This role reports to the Head of Security.
Responsibilities:
Compliance Program Ownership
  • Own Northwood's compliance program across CMMC Level 2, FedRAMP, SOC 2 Type II, and ITAR, including control mapping, gap assessment, remediation tracking, and audit preparation.
  • Maintain Northwood's System Security Plan (SSP), Plan of Action and Milestones (POA&M), and associated compliance documentation in alignment with NIST 800-171 and applicable frameworks.
  • Coordinate and manage third-party assessments, including C3PAO engagements for CMMC, FedRAMP 3PAO assessments, and SOC 2 audits, serving as the primary assessor liaison.
  • Monitor the regulatory environment for changes to CMMC, FedRAMP, DFARS, and ITAR requirements and assess impact on Northwood's compliance posture.

Risk Management
  • Build and maintain Northwood's enterprise risk management program, including risk register development, risk scoring methodology, and executive-level risk reporting.
  • Conduct and facilitate periodic risk assessments across security domains, incorporating input from security engineering, network, product, and operations teams.
  • Identify, track, and drive remediation of compliance gaps and security control deficiencies, working directly with technical teams to ensure timely closure.
  • Develop and maintain risk acceptance processes, exception management workflows, and compensating control documentation.

Policy & Control Framework
  • Develop, maintain, and enforce Northwood's security policy library, including acceptable use, access control, incident response, data classification, and CUI handling policies.
  • Map Northwood's control environment across overlapping frameworks - NIST 800-171, NIST 800-53, SOC 2 Trust Services Criteria, and FedRAMP - to reduce duplicative compliance effort and maximize control reuse.
  • Define and maintain the control evidence collection program, ensuring audit artifacts are continuously gathered, organized, and accessible for assessment cycles.
  • Partner with the Security Engineering Lead, Security Operations Lead, and Product Security Lead to validate that technical controls are implemented in alignment with documented policies and compliance requirements.

ITAR & CUI Program Management
  • Own Northwood's CUI program, including data classification guidance, CUI handling procedures, marking standards, and employee training.
  • Maintain ITAR compliance program documentation, including technology control plans, export authorization tracking, and coordination with Northwood's legal counsel on regulatory obligations.
  • Ensure network segmentation, access controls, and data handling practices across Northwood's infrastructure appropriately enforce CUI and ITAR boundaries in coordination with security and network engineering teams.

Audit Readiness & Stakeholder Engagement
  • Serve as the primary compliance point of contact for government customers, prime contractors, and subcontractors, including responding to security questionnaires, flow-down requirement reviews, and customer audit requests.
  • Build and maintain audit readiness posture year-round, ensuring evidence collection, control testing, and documentation currency do not become point-in-time exercises.
  • Brief executive leadership and the Head of Security on compliance status, upcoming assessment milestones, and material risk items requiring business-level decisions.
  • Develop and deliver security awareness and compliance training programs for Northwood employees, with targeted content for personnel handling CUI or operating in ITAR-controlled environments.

Basic Qualifications:
  • 5+ years in a governance, risk, and compliance role with demonstrated ownership of enterprise compliance programs in a regulated environment.
  • Deep working knowledge of CMMC Level 2 and NIST SP 800-171, including SSP development, POA&M management, and C3PAO assessment preparation.
  • Experience managing FedRAMP authorization processes, including boundary definition, control implementation documentation, and 3PAO coordination.
  • Hands-on experience with SOC 2 Type II audits, including control mapping, evidence collection, and auditor engagement.
  • Familiarity with ITAR compliance requirements, including technology control plans, export authorization processes, and CUI program management.
  • Demonstrated ability to translate technical security controls into compliance documentation and audit evidence across multiple overlapping frameworks.
  • Experience conducting risk assessments and maintaining enterprise risk registers with executive-level reporting.
  • Strong technical fluency - this role works directly with security engineering and infrastructure teams and requires the ability to evaluate technical control implementations against compliance requirements.
  • Ability to obtain and maintain a TS/SCI clearance.
  • U.S. citizenship or status as a lawful permanent resident required to conform with ITAR export regulations.

Preferred Qualifications:
  • Active TS clearance or higher.
  • Experience working within the Defense Industrial Base, including prime or subcontractor compliance environments with DFARS flow-down obligations.
  • Familiarity with eMASS or similar government assessment and authorization management tools.
  • Experience with GRC platforms for control tracking, evidence management, and audit workflow automation.
  • Knowledge of Northwood's core infrastructure environment, including AWS GovCloud, Microsoft GCC, and on-premises security tooling, and how these map to FedRAMP and CMMC control boundaries.
  • Experience developing and delivering security awareness and CUI handling training programs.
  • Familiarity with DFARS 252.204-7012 incident reporting obligations and coordination with DIBCAC or DCSA.
  • Professional certifications such as CISSP, CISM, CISA, CCSK, or equivalent GRC credentials.
  • CMMC Registered Practitioner (RP) or Certified Professional (CP) designation.

Additional Requirements:
  • This position requires successfully obtaining and maintaining a Top Secret Security Clearance as a condition of employment. While the clearance may not be immediately necessary upon hire, we encourage you to initiate the application process promptly upon accepting this offer. Your ability to secure the necessary clearance is essential for fulfilling key responsibilities of the role. Should you be unable to obtain it, Northwood Space reserves the right to modify or terminate your employment to align with optional needs.

Additional Information:
If you need a reasonable accommodation as part of your application for employment or interviews with us, please let us know.
To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.
Northwood Space is an Equal Opportunity Employer; employment with Northwood Space is governed on the basis of merit, competence and qualifications and will not be influenced in any manner by race, color, religion, gender, national origin/ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability or any other legally protected status.