1

Grc Engineer Jobs in Texas (NOW HIRING)

The Sr GRC Programmer/Analyst modifies existing software/application programs, which are typically more complex in nature, or writes new programs to support user and management needs within the GRC ...

The Sr GRC Programmer/Analyst modifies existing software/application programs, which are typically more complex in nature, or writes new programs to support user and management needs within the GRC ...

The GRC Software Engineer provides technical and consultative support on the most complex technical matters within the GRC application space. Will be responsible for implementation of new and ...

The GRC Software Engineer provides technical and consultative support on the most complex technical matters within the GRC application space. Will be responsible for implementation of new and ...

The GRC Software Engineer provides technical and consultative support on the most complex technical matters within the GRC application space. Will be responsible for implementation of new and ...

The GRC Software Engineer provides technical and consultative support on the most complex technical matters within the GRC application space. Will be responsible for implementation of new and ...

Its engineers build critical infrastructure to eliminate friction in scientific research ... THE POSITION NMC² is hiring a GRC Analyst to join the Information Security team, reporting to the ...

GRC Analyst

Dallas, TX · On-site +1

Its engineers build critical infrastructure to eliminate friction in scientific research ... THE POSITION NMC is hiring a GRC Analyst to join the Information Security team, reporting to the ...

Our company provides application analysis, design, development and programming, software ... REQUIRED SAP GRC Modules * ARA (access risk analysis) * EAM (Emergency Access Module) WORK ...

GRC Controls Automation Engineer

Austin, TX · On-site

$82K - $109K/yr

As our GRC Controls Automation Engineer, you will play a key role building a scalable, efficient program and process using your technical leadership focusing on automation within Box. * You will work ...

next page

Showing results 1-20

Grc Engineer information

See Texas salary details

$55.4K

$104K

$189.1K

How much do grc engineer jobs pay per year?

As of Aug 31, 2026, the average yearly pay for grc engineer in Texas is $104,002.00, according to ZipRecruiter salary data. Most workers in this role earn between $75,000.00 and $123,400.00 per year, depending on experience, location, and employer.

What is a GRC engineer?

GRC Engineers are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization’s information security and IT frameworks. They help ensure that a company’s policies and procedures meet regulatory requirements, manage risks, and align with business objectives. GRC Engineers often implement and maintain tools, conduct risk assessments, and ensure compliance through audits and reporting. Their role is critical in minimizing risks and protecting organizational assets from security threats.

What are the key skills and qualifications needed to thrive as a GRC engineer?

To thrive as a GRC Engineer, you need a solid understanding of governance, risk management, and compliance frameworks, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as RSA Archer or ServiceNow GRC), risk assessment tools, and certifications like CISA or CISSP are highly valued. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating across departments and translating complex requirements. These competencies ensure that organizations can effectively manage risk, maintain regulatory compliance, and safeguard critical information assets.

What are some common challenges faced by GRC engineers when implementing new compliance frameworks?

GRC Engineers often encounter challenges such as integrating new compliance requirements with existing IT systems, ensuring consistent documentation, and keeping up with evolving regulatory standards. Collaboration with various departments—like IT, legal, and operations—is essential to map processes accurately and address potential gaps. Proactive communication and a strong understanding of both technical and regulatory aspects help GRC Engineers overcome these hurdles and support organizational compliance effectively.

What is the difference between Grc Engineer vs Security Analyst?

AspectGrc EngineerSecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, compliance, risk managementMonitoring, incident response, threat analysis
Industry UsageCorporate governance, compliance teamsSecurity operations centers, IT departments

Grc Engineers focus on establishing and maintaining governance, risk, and compliance frameworks, ensuring organizations meet regulatory standards. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity industry, Grc Engineers emphasize policy and compliance, whereas Security Analysts focus on threat detection and response.

Are GRC engineer jobs hard to get?

GRC (Governance, Risk, and Compliance) engineer jobs can be competitive, especially for entry-level positions, but having relevant skills in cybersecurity, risk management, and certifications like CISSP or CISA can improve chances. The difficulty of securing a GRC engineer role depends on experience, education, and the demand within the industry or organization. Strong knowledge of compliance frameworks and tools is often required to stand out.

How much do GRC engineers make?

GRC (Governance, Risk, and Compliance) engineers typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in cybersecurity tools and frameworks can earn higher salaries, often exceeding $150,000.

Is GRC engineer an entry-level job?

A GRC (Governance, Risk, and Compliance) engineer is typically an intermediate to senior role that requires relevant experience and knowledge of security frameworks, compliance standards, and risk management tools. Entry-level positions may be available but often require foundational skills, certifications, or internships in cybersecurity or IT governance.

What are popular job titles related to Grc Engineer jobs in Texas?

For Grc Engineer jobs in Texas, the most frequently searched job titles are:

What job categories do people searching Grc Engineer jobs in Texas look for?

The top searched job categories for Grc Engineer jobs in Texas are:

What cities in Texas are hiring for Grc Engineer jobs?

Cities in Texas with the most Grc Engineer job openings:

Infographic showing various Grc Engineer job openings in Texas as of August 2026, with employment types broken down into 66% Full Time, and 34% Contract. Highlights an 74% In-person, and 26% Remote job distribution, with an average salary of $104,002 per year, or $50 per hour.

Information Security GRC Engineer (OneTrust / NIST)

Plano, TX • On-site

Prolim Global
IT Services • 201 - 500 employees

Contractor

Re-posted 29 days ago


Job description

Information Security GRC Engineer (OneTrust / NIST)

Plano, Texas (Hybrid)

Description

We are seeking a hands‑on GRC Engineer & Risk Analytics professional who will implement and scale a NIST‑aligned control and risk framework in OneTrust while also conducting targeted risk and control assessments to validate design and operating effectiveness. You will connect process, data, and automation so department leaders can see—and reduce—risk in near‑real time through role‑based dashboards and scorecards. You’ll partner with Security Engineering, IT, Audit, and business control owners to streamline assessments, evidence collection, POA&M tracking, and reporting.

Focus split: approximately 70% OneTrust configuration, integrations, data modeling, and dashboards; approximately 30% targeted assessments and facilitation.

Module ownership on Day 1: OneTrust Integrated Risk Management (IRM) and Third‑Party Risk Management (TPRM).

What you’ll be doing

  • Model the control framework in OneTrust: map NIST CSF and NIST 800‑53 control families, control objectives, test procedures, evidence types, and ownership.
  • Configure assessment templates (application/infrastructure, inherent/residual risk, third‑party due diligence, control attestations) with automated workflows, notifications, and approvals.
  • Stand up a POA&M lifecycle (defect creation, risk acceptance, due dates, escalations, verifications) and connect to tickets for remediation traceability.
  • Build role‑based dashboards and departmental scorecards that surface KRIs/KPIs (e.g., control coverage, overdue actions, risk heatmaps, SLA adherence).
  • Establish data taxonomy and metadata (assets, business processes, data classifications) aligned to controls and obligations to support consistent analytics.
  • Own the end‑to‑end third‑party risk workflow in OneTrust: inherent risk profiling, tiering, questionnaire selection, and residual risk calculation.
  • Design and maintain due‑diligence questionnaires and control attestations; streamline evidence collection and follow‑ups via automated reminders and SLAs.
  • Track remediation and POA&Ms for vendors; manage risk acceptances, exceptions, and expirations with clear ownership and timelines.
  • Publish vendor scorecards and portfolio‑level insights for department leaders; highlight concentration risk, critical suppliers, and overdue actions.
  • Integrate TPRM data with IRM objects (assets, processes, controls) to show end‑to‑end exposure and dependencies.
  • Integrate OneTrust with CMDB, Risk reporting platforms to auto‑enrich risks, controls, and assets.
  • Define data quality rules and reconciliation checks; implement connectors or API jobs to keep dashboards near‑real‑time and reduce manual evidence collection.
  • Partner with Analytics to publish curated Power BI datasets for executives and technical teams.
  • Conduct spot assessments and control testing to validate design and operating effectiveness and calibrate automation.
  • Translate FFIEC/GLBA/SOX and policy requirements into measurable controls and department‑owned obligations; document rationales and residual risk.
  • Facilitate remediation planning with control owners; track POA&Ms and risk acceptances to closure with clear RACI and deadlines.
  • Create playbooks, test scripts, and user guides; run enablement sessions for control owners and assessors to drive adoption.
    What you’ll deliver in the first 6–12 months:
  • A fully modeled NIST-aligned control catalog in OneTrust IRM and TPRM, complete with owners, testing procedures, evidence, and mapped obligations.
  • 3–5 data integrations operational (for instance, CMDB, Archer, Posture Management) enabling automated evidence and asset-to-control mapping.
  • Departmental scorecards along with an executive dashboard (showing trendlines, heatmaps, top risks, overdue actions, and risk reduction by department).
  • Enhanced assessment throughput with a reduced cycle time (targeting a 30–40% improvement from baseline).
  • Improved on-time completion of POA&M (targeting an increase of 20–30%) with a decrease in repeat findings through structured root-cause identification.
  • Published and operational governance framework artifacts (including a governance calendar, defined roles, training materials, and standard operating procedures).

Requirements

• 5+ years hands‑on experience implementing/administering GRC platforms (OneTrust preferred; Archer/ServiceNow GRC acceptable with commitment to OneTrust ramp‑up).

• Working knowledge of NIST CSF and NIST 800‑53 and how to translate obligations into measurable controls and tests.

• Experience configuring questionnaires, workflows, object models, APIs, and building role‑based dashboards.

• Data skills in Power BI, SQL, or Python for data prep/transformations that feed analytics.

• Ability to tell the risk story—translate technical signal into business‑relevant insights for department leaders.

• Bachelor’s degree or equivalent practical experience.

Added bonus if you have

• OneTrust GRC/IRM certifications; CRISC, CISA, or CISSP.

• Prior integrations with ServiceNow, Jira, SailPoint/IDP, Qualys/Tenable, or cloud platforms (AWS/Azure).

• Experience setting up control attestation/evidence automation and KRI/KPI scorecards across business units.

• Background in financial services or familiarity with FFIEC/GLBA/SOX supervisory expectations.