1

Grc Analyst Jobs in Rialto, CA (NOW HIRING)

Grc Analyst information

See Rialto, CA salary details

$36.6K

$97.9K

$229.1K

How much do grc analyst jobs pay per year?

As of Jul 28, 2026, the average yearly pay for grc analyst in Rialto, CA is $97,930.00, according to ZipRecruiter salary data. Most workers in this role earn between $55,200.00 and $111,300.00 per year, depending on experience, location, and employer.

Is GRC a good career?

A GRC (Governance, Risk, and Compliance) analyst plays a key role in managing an organization’s security policies, risk assessments, and regulatory compliance. It is a growing field with demand for professionals skilled in frameworks like ISO, NIST, and tools such as audit management software. The role often requires certifications like CISA or CISSP and offers opportunities for career advancement in cybersecurity and risk management.

Is GRC an entry level job?

GRC Analyst roles can be entry-level or require some experience, depending on the organization. Entry-level positions typically focus on basic compliance, risk management, and security controls, often requiring foundational knowledge of cybersecurity or IT. More advanced roles may demand certifications like CISSP or CISA and prior experience in security or audit functions.

What are the key skills and qualifications needed to thrive in the Grc Analyst position, and why are they important?

To thrive as a GRC Analyst, you need a solid understanding of governance, risk management, and compliance frameworks, often complemented by a degree in information security, business, or a related field. Experience with GRC platforms (like RSA Archer, ServiceNow, or LogicManager), and certifications such as CISA, CRISC, or CISSP are highly valued. Strong analytical thinking, attention to detail, effective communication, and collaboration skills set outstanding GRC Analysts apart. These capabilities are vital for ensuring organizations meet regulatory requirements, identify and mitigate risks, and foster a culture of compliance.

What does a GRC analyst do?

A GRC analyst (Governance, Risk, and Compliance analyst) is responsible for managing an organization’s compliance with regulations, assessing and mitigating risks, and developing governance frameworks. They often use tools like risk management software and require knowledge of industry standards such as ISO or NIST. The role involves analyzing policies, conducting audits, and ensuring security controls are effective.

Do GRC analysts work from home?

GRC analysts can often work remotely, especially if their employer supports telecommuting and the role involves tasks like risk assessment, policy development, and compliance monitoring that can be performed online. However, some positions may require on-site presence for meetings, audits, or access to secure systems.

What are the typical daily responsibilities of a GRC Analyst?

GRC Analysts are responsible for monitoring and assessing organizational policies, procedures, and controls to ensure compliance with internal and external regulations. Their daily tasks often include performing risk assessments, maintaining documentation, supporting audits, analyzing data for potential security gaps, and preparing reports for management. They regularly collaborate with IT, legal, and business teams to remediate vulnerabilities and strengthen compliance programs. This dynamic role requires both independent research and cross-departmental communication to help organizations proactively manage risk and regulatory obligations.

What is a GRC Analyst job?

A GRC (Governance, Risk, and Compliance) Analyst is responsible for ensuring that an organization adheres to regulatory requirements, industry standards, and internal policies. They assess risks, implement compliance programs, and monitor security controls to protect data and systems. Their role often involves working with various departments to identify vulnerabilities, develop risk mitigation strategies, and prepare reports for audits. GRC Analysts play a key role in maintaining regulatory compliance and enhancing an organization's overall security posture.

What are popular job titles related to Grc Analyst jobs in Rialto, CA? For Grc Analyst jobs in Rialto, CA, the most frequently searched job titles are:
What cities near Rialto, CA are hiring for Grc Analyst jobs? Cities near Rialto, CA with the most Grc Analyst job openings:
Infographic showing various Grc Analyst job openings in Rialto, CA as of July 2026, with employment types broken down into 86% Full Time, 9% Part Time, 1% Temporary, and 4% Contract. Highlights an 86% Physical, 6% Hybrid, and 8% Remote job distribution, with an average salary of $97,930 per year, or $47.1 per hour.

Full-time

Posted 8 days ago


Job description

Under the direction of the Director, Information Security Operations, the Governance Analyst III is responsible for the strategic oversight and leadership of the enterprise's information security and data privacy governance framework. This senior-level position focuses on the development, implementation, and continuous improvement of comprehensive security and privacy policies, standards, baselines, and guidelines to protect enterprise assets, safeguard sensitive and personal data, and ensure the confidentiality, integrity, availability, and appropriate use of information in compliance with applicable privacy regulations.
This role leads high-impact security and privacy initiatives, conducts advanced risk and privacy impact assessments, and drives the adoption of leading practices across the organization. This role requires a deep understanding of information security frameworks, privacy principles (e.g., data minimization, purpose limitation, and protection by design), industry standards, emerging threats, and regulatory requirements (e.g., PCI DSS, CCPA/CPRA, and other applicable privacy laws).

ESSENTIAL DUTIES AND RESPONSIBILITIES

1. Regularly mentors and provides guidance to team members in the development of security and privacy policies, standards, and procedures, ensuring alignment with regulatory requirements and business objectives. Coaches staff on integrating privacy-by-design principles into governance processes and control development.

2. Leads all Payment Card Industry (PCI) efforts, including tracking remediation of control gaps and escalating critical issues to senior management. Acts as a cross-functional lead to ensure compliance readiness. Ensure that cardholder data and other sensitive personal information are handled in accordance with privacy and data protection requirements.

3. Engage with business units to identify security and privacy risks, facilitating risk assessments including Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) where applicable. Tracks mitigation plans and enhances enterprise risk management capabilities.

4. Leads vendor risk management efforts, including vendor intake and review process.

5. Develops and enhances metrics for Information Security and Privacy risk reporting dashboards, including key risk indicators (KRIs) related to data protection, regulatory compliance, and incident trends that inform executive decision-making and prioritize remediation efforts based on business impact.

6. Leverage specialized knowledge to guide project and operational decisions, clearly communicating security and privacy policies, regulatory requirements, and best practices to stakeholders across the enterprise.

7. Contribute to training and awareness initiatives, promoting security and privacy awareness, secure data handling practices, and compliance obligations among functional leaders, system owners, and employees.

8. Performs other duties as assigned to support the efficient operation of the department, including support for privacy incident response, breach notification coordination, and regulatory inquiries as needed.

EDUCATIONAL, EXPERIENCE AND QUALIFICATIONS

  • Bachelor's degree in information security, technology, statistics, mathematics, or related field required.

  • Minimum six (6) years of experience in documentation, procedures and/or policies of information technology, information systems, risk management, controls audit, vendor management, data privacy, or information security required.

  • Experience with Casino and Tribal government technology and security goals strongly preferred.

  • Experience with the following preferred:

    • Expertise in regulatory and legal requirements, with the ability to interpret and operationalize laws and standards (e.g., PCI DSS, privacy regulations, and enterprise frameworks)

    • Design and governance of enterprise policy architecture, including policy hierarchy, exception management, and alignment to business strategy

    • Advanced experience with GRC platforms, including implementation, optimization, and reporting for enterprise risk, compliance, and control assurance

    • Leadership of complex audits, regulatory engagements, and enterprise control assurance programs

  • Related, relevant, and/or direct experience may be considered in lieu of minimum educational requirements indicated above.

KNOWLEDGE, SKILLS AND ABILITIES (KSA)

  • Must have strong communication and presentation skills.

  • Must understand the value of standards, policy and procedures, operational effectiveness, and high availability.

LICENSES, CERTIFICATIONS AND REGISTRATIONS

  • At the discretion of the San Manuel Tribal Gaming Commission, you may be required to obtain and maintain a gaming license.

  • Driving Responsibilities: Role requires regular commuting between locations. A valid driver's license and vehicle insurance with minimum liability limits is required. Role will not operate or drive Tribe-owned vehicles or patron vehicles.

PHYSICAL REQUIREMENTS/ WORKING CONDITIONS - ENVIRONMENT

The physical demands and working environment described here are representative of those that an employee encounters and must be met by an employee to successfully perform the essential functions of this job.

  • Primary work environment is in a climate-controlled office setting.

  • Work requires travel to attend meetings, trade shows, and conferences.

  • Incumbents may be required to work evening, weekend and holiday shifts.

  • Must be able to work in a fast-paced, high-demand environment.

  • Strength sufficient to exert up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects and/or move up to 40 pounds occasionally.

  • Sedentary work: involves sitting most of the time. Constantly operates a computer and other office productivity machinery, such as a calculator, copy machine, and computer printer.

  • Physical activities that apply to the essential functions of the position are balancing, stooping, kneeling, crouching, reaching, pushing, pulling, lifting, grasping, talking, hearing, and repetitive motions.

  • Hearing sufficient to hear conversational levels in person, via videoconference and over the telephone.

  • Speech sufficient to make oneself heard and understood in person, in front of groups, in meetings, via videoconference and over the telephone.

  • Visual acuity that meets the requirements of the position: The worker is required to have close visual acuity to perform an activity such as preparing and analyzing data and figures; transcribing; viewing a computer terminal; expansive reading and visual inspection of employees, visitors or facility.

  • Mobility sufficient to safely move in an office environment, walk, stoop, bend and kneel, and enter, exit and operate a motor vehicle in the course of travel to promotional events, meetings, conferences, trade shows and San Manuel properties.

  • Endurance sufficient to sit, walk and stand for extended periods, and maintain efficiency throughout the entire work shift and during extended work hours.

  • The employee may be exposed to fumes or airborne particles including secondhand smoke.

Reasonable accommodation will be made in compliance with all applicable law.

As one of the largest private employers in the Inland Empire, San Manuel deeply cares about the future, growth and well-being of its employees. Join our team today!