1

Grc Engineer Jobs in California (NOW HIRING)

GRC Engineer

Palo Alto, CA · On-site

$130K - $170K/yr

GRC Engineer Why Zania Every enterprise spends millions of dollars on Governance, Risk, and Compliance (GRC). It's one of the most critical, yet universally painful, parts of running a business. For ...

We seek a Senior GRC Engineer who combines deep GRC expertise with strong engineering skills to build and scale automation across governance, risk, and compliance. This is a hands-on technical role ...

GRC Engineer

Foster City, CA · On-site

$210K - $320K/yr

We are looking for a GRC Engineer to serve as a key technical contributor for our compliance and risk management ecosystem. You will architect the systems and processes that automate trust ...

GRC Engineer Location: San Jose CA Duration: 6 Months 100% Onsite- ** LOCAL CANDIDATES ONLY** Seeking a hands-on GRC Engineer with expertise in Python, API development, and modern architectures ...

Senior GRC Engineer

San Francisco, CA · On-site

$180K - $200K/yr

We seek a Senior GRC Engineer who combines deep GRC expertise with strong engineering skills to build and scale automation across governance, risk, and compliance. This is a hands-on technical role ...

About the Role As the Staff GRC Engineer, you will report to the Lead of Security and be the first dedicated hire establishing Kikoff's Trust & Assurance function within Security. You will own the ...

MUST HAVE SKILLS: Data Governance, AI development and Governance, Security Risk Management The GRC Engineer will contribute to the development and operational execution of the program.

Work cross functionally with Security, IT, Engineering, Product and Legal to provide guidance on ... GRC goals. * Implement the development and oversight of required corrective action plans relating ...

Work cross functionally with Security, IT, Engineering, Product and Legal to provide guidance on ... GRC goals. * Implement the development and oversight of required corrective action plans relating ...

Work cross functionally with Security, IT, Engineering, Product and Legal to provide guidance on ... GRC goals. * Implement the development and oversight of required corrective action plans relating ...

GRC Engineering is how we make all of that scale -- turning compliance into code, evidence into telemetry, and audits into a continuous, automated capability. The Role: * You will own GRC Engineering ...

GRC Engineering is how we make all of that scale -- turning compliance into code, evidence into telemetry, and audits into a continuous, automated capability. The Role: * You will own GRC Engineering ...

Senior GRC Lead

San Francisco, CA · On-site +1

$134K - $185K/yr

Engineering Engineering at Brex is about building systems that scale with speed and intention. Our ... As a Senior GRC Engineer, you will drive critical GRC processes that mitigate risk, keep us ...

We don't view Governance, Risk, and Compliance (GRC) as a passive reporting function or an administrative checklist-we build engineering-forward, automated, and AI-driven GRC programs capable of ...

Senior Director, GRC

San Francisco, CA · On-site

$264 - $363/hr

We don't view Governance, Risk, and Compliance (GRC) as a passive reporting function or an administrative checklist--we build engineering-forward, automated, and AI-driven GRC programs capable of ...

Senior Director, GRC

San Francisco, CA · On-site

$264K - $363K/yr

We don't view Governance, Risk, and Compliance (GRC) as a passive reporting function or an administrative checklist-we build engineering-forward, automated, and AI-driven GRC programs capable of ...

next page

Showing results 1-20

Grc Engineer information

See California salary details

$58.7K

$110.2K

$200.3K

How much do grc engineer jobs pay per year?

As of Aug 24, 2026, the average yearly pay for grc engineer in California is $110,170.00, according to ZipRecruiter salary data. Most workers in this role earn between $79,400.00 and $130,800.00 per year, depending on experience, location, and employer.

What is a GRC engineer?

GRC Engineers are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization’s information security and IT frameworks. They help ensure that a company’s policies and procedures meet regulatory requirements, manage risks, and align with business objectives. GRC Engineers often implement and maintain tools, conduct risk assessments, and ensure compliance through audits and reporting. Their role is critical in minimizing risks and protecting organizational assets from security threats.

What are the key skills and qualifications needed to thrive as a GRC engineer?

To thrive as a GRC Engineer, you need a solid understanding of governance, risk management, and compliance frameworks, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as RSA Archer or ServiceNow GRC), risk assessment tools, and certifications like CISA or CISSP are highly valued. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating across departments and translating complex requirements. These competencies ensure that organizations can effectively manage risk, maintain regulatory compliance, and safeguard critical information assets.

What are some common challenges faced by GRC engineers when implementing new compliance frameworks?

GRC Engineers often encounter challenges such as integrating new compliance requirements with existing IT systems, ensuring consistent documentation, and keeping up with evolving regulatory standards. Collaboration with various departments—like IT, legal, and operations—is essential to map processes accurately and address potential gaps. Proactive communication and a strong understanding of both technical and regulatory aspects help GRC Engineers overcome these hurdles and support organizational compliance effectively.

What is the difference between Grc Engineer vs Security Analyst?

AspectGrc EngineerSecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, compliance, risk managementMonitoring, incident response, threat analysis
Industry UsageCorporate governance, compliance teamsSecurity operations centers, IT departments

Grc Engineers focus on establishing and maintaining governance, risk, and compliance frameworks, ensuring organizations meet regulatory standards. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity industry, Grc Engineers emphasize policy and compliance, whereas Security Analysts focus on threat detection and response.

Are GRC engineer jobs hard to get?

GRC (Governance, Risk, and Compliance) engineer jobs can be competitive, especially for entry-level positions, but having relevant skills in cybersecurity, risk management, and certifications like CISSP or CISA can improve chances. The difficulty of securing a GRC engineer role depends on experience, education, and the demand within the industry or organization. Strong knowledge of compliance frameworks and tools is often required to stand out.

How much do GRC engineers make?

GRC (Governance, Risk, and Compliance) engineers typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in cybersecurity tools and frameworks can earn higher salaries, often exceeding $150,000.

Is GRC engineer an entry-level job?

A GRC (Governance, Risk, and Compliance) engineer is typically an intermediate to senior role that requires relevant experience and knowledge of security frameworks, compliance standards, and risk management tools. Entry-level positions may be available but often require foundational skills, certifications, or internships in cybersecurity or IT governance.

What job categories do people searching Grc Engineer jobs in California look for?

The top searched job categories for Grc Engineer jobs in California are:

What cities in California are hiring for Grc Engineer jobs?

Cities in California with the most Grc Engineer job openings:

Infographic showing various Grc Engineer job openings in California as of August 2026, with employment types broken down into 100% Contract. Highlights an 100% In-person job distribution, with an average salary of $110,170 per year, or $53 per hour.

GRC Engineer

Palo Alto, CA • On-site

$130K - $170K/yr

Full-time

Medical, Dental, Vision, PTO

Re-posted 29 days ago


Job description

GRC Engineer
Why Zania
Every enterprise spends millions of dollars on Governance, Risk, and Compliance (GRC). It's one of the most critical, yet universally painful, parts of running a business. For decades, this industry has been dominated by legacy systems with notoriously low NPS scores, making it totally ripe for disruption.
Zania is building agentic AI for Governance, Risk, and Compliance (GRC) to solve this massive problem. We are on a rocketship trajectory, creating intelligent agents that automate and augment the most complex risk and compliance workflows. We have found exceptional product-market fit and are scaling our team very quickly. Some reasons to join Zania are:
  • Dream Customers: Our customers are the most notable enterprises in the world, including FAANG, Big 4 firms and a portfolio of top customers.
  • Tier 1 Backing: Funded by a leading Tier 1 venture capital fund - Series A led by NEA, with Anthropic and Menlo Ventures. $18M raised to build a generational company.
  • World-Class Team: Zania is hiring the best. Our team includes AI and Security leaders from Airbnb, Microsoft, Bain & Company, Deloitte, PwC, Brex, and Instacart.
  • Pioneering Technology: Our engineers and GRC experts work at the absolute forefront of applied AI, building the next generation of agentic systems that will define the future of compliance.
  • Hyper-Growth: We have seen 10x ARR growth in the last year and are rapidly expanding.
  • Competitive Compensation & Equity.

The Role
As a GRC Engineer at Zania, you are the bridge between our product and the enterprises that depend on it. You are not a support function - you are a compliance authority and a closer. You own the customer relationship from first implementation through a defined, measurable finish line, and you are accountable for getting them there.
You will set clear success goals with every customer on day one, work backwards from those goals to drive the engagement, and know exactly when you've landed the outcome you both committed to. Once a customer is live and successful, you transition them to a steady state and move your energy to the next challenge. You don't let engagements drift - you drive them to done.
In parallel, everything you learn in the field comes back into the product. Your pattern recognition across customer implementations will directly shape Zania's roadmap.
What You'll Do
  • Set the success contract upfront. In every new engagement, establish explicit, measurable goals with the customer before work begins - and align the entire implementation plan to hitting those milestones. No ambiguity about what "done" looks like.
  • Own implementations end-to-end and close them. Lead onboarding and deployment for enterprise customers from scoping and configuration through to a defined, celebrated go-live. You drive the engagement to closure - you don't let it become an open-ended managed service.
  • Be the GRC expert in the room. Serve as the primary compliance authority in all customer conversations. When a CISO or VP of Risk asks a hard question about how Zania maps to their control framework, you answer it - with precision and credibility.
  • Transition to steady state and monitor. Once a customer has hit their success goals, transition them to a lightweight monitoring cadence. Check in, track outcomes, flag risks early - but protect your bandwidth for the next implementation.
  • Drive product feedback. Synthesize what you hear across implementations into structured, prioritized product insights. Bring them directly to our product and engineering teams. Your input will shape the roadmap.
  • Build the implementation playbook. As an early team member, define how Zania implementations work at scale - the processes, templates, success metrics, and handoff criteria the team will run on as we grow.
  • Support pre-sales. Partner with the sales team on technical discovery and proof-of-concept engagements for strategic prospects, helping close deals by demonstrating deep GRC credibility.

Representative Projects
  • Kick off a new enterprise implementation by running a structured goal-setting session with the customer's CISO and GRC lead - defining three measurable success outcomes and a 60-day plan to achieve them.
  • Lead the end-to-end deployment of Zania for a Fortune 500 financial services firm, drive the engagement to a signed-off go-live, and formally close the implementation against the goals you set on day one.
  • Design a steady-state monitoring framework for post-implementation customers - a lightweight quarterly check-in cadence with clear escalation criteria - so successful customers stay successful without requiring ongoing heavy investment.
  • Compile and present a quarterly product feedback report to the Head of Product, distilling patterns from 20+ customer engagements into a prioritized list of platform gaps and feature requests.

What You Have
  • 3-8 years of experience spanning GRC, information security compliance, risk management, audit, or customer success in an enterprise technology context.
  • Framework fluency. Deep working knowledge of at least two major compliance frameworks (SOC 2, ISO 27001, NIST CSF, FedRAMP, HIPAA, PCI-DSS, or similar). You've lived inside these frameworks, not just read about them.
  • A closer's instinct. You define success before you start, drive engagements toward it with urgency, and know how to bring a customer to a clear finish line rather than letting things drift into indefinite managed services.
  • Customer-facing experience. You are comfortable owning relationships with senior security and risk stakeholders - presenting, advising, pushing back when needed - with confidence and credibility.
  • Outcome orientation. You measure your own success the same way you measure your customers': against specific, agreed-upon goals. Vague progress doesn't satisfy you.
  • Product instinct. You pay attention to friction. When something doesn't work for a customer, you don't just fix it in the moment - you document it and make sure the product team hears about it.
  • Strong communication. You can run a technical workshop with a customer's GRC team in the morning and write a clear, structured product brief in the afternoon. Both matter equally in this role.

Minimum Qualifications
  • Minimum Qualifications
  • Bachelor's degree in Information Security, Business, Risk Management, or a related field, or equivalent practical experience
  • 3-8 years of experience in GRC, information security compliance, risk management, audit, enterprise technology customer success, or a customer success manager role - ideally in a SaaS or technical product environment
  • Working knowledge of at least two major compliance frameworks (e.g., SOC 2, ISO 27001, NIST CSF, FedRAMP, HIPAA, or PCI-DSS), with direct experience applying them professionally
  • Demonstrated ability to project manage complex, multi-stakeholder enterprise engagements - setting the agenda, holding customers accountable to timelines, and driving to a clear finish line with authority
  • Strong written and verbal communication skills - you will be the primary GRC authority in conversations with CISOs and senior risk leaders, and must command the room, align stakeholders, and earn trust at the executive level quickly

Compensation & Benefits
  • Competitive salary + significant equity
  • Flexible PTO
  • Medical, dental, and vision insurance
  • Meals and snacks in the office
  • Relocation and immigration support

Zania is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.