1

Grc Risk Analyst Jobs in California (NOW HIRING)

GRC Risk Management Analyst

San Jose, CA ยท On-site

$68 - $72/hr

Experience: 1-4 years in enterprise risk, third-party risk, GRC, information security, or a related ... Strong analytical, organizational, stakeholder-management, and written and verbal communication ...

GRC Risk Management Analyst

San Jose, CA ยท On-site

$68.97 - $72.80/hr

Experience: 1 4 years in enterprise risk, third-party risk, GRC, information security, or a related ... Strong analytical, organizational, stakeholder-management, and written and verbal communication ...

The GRC Risk Manager, a thought leader residing within our security organization, is responsible ... Strong analytical and problem-solving skills. * Strong written and verbal communication skills ...

The GRC Risk Manager, a thought leader residing within our security organization, is responsible ... Strong analytical and problem-solving skills. * Strong written and verbal communication skills ...

Assisting in the upkeep of governance, risk and compliance (GRC) software applications Interacting with team members and department/division personnel on other GRC related tasks Documenting data and ...

next page

Showing results 1-20

Grc Risk Analyst information

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What cities in California are hiring for Grc Risk Analyst jobs?

Cities in California with the most Grc Risk Analyst job openings:

Infographic showing various Grc Risk Analyst job openings in California as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution.

GRC Risk Management Analyst

CYNET SYSTEMS

San Jose, CA โ€ข On-site

$68 - $72/hr

Contractor

Medical, Dental, Vision, Life, Retirement

Posted 12 days ago


Job description

Job Overview:

Pay Range: $68.97hr - $72.8hr

Requirement/Must Have:

  • Education: Bachelor’s degree in Information Security, Risk Management, Business, Computer Science, or a related field.
  • Experience: 1–4 years in enterprise risk, third-party risk, GRC, information security, or a related area.
  • Knowledge of inherent and residual risk, likelihood and impact, controls, treatment, acceptance, and monitoring.
  • Working technical knowledge of enterprise and cloud environments, including networking, operating systems, identity and access management, encryption, secure configuration, vulnerability management, logging and monitoring, application security, and incident response.
  • Ability to interpret technical evidence such as architecture and data-flow diagrams, access reviews, configuration outputs, vulnerability and penetration-test reports, security logs, and independent assurance reports, and to identify when deeper technical validation is required.
  • Ability to assess business impact, apply risk criteria, and communicate clear, defensible recommendations.
  • Strong analytical, organizational, stakeholder-management, and written and verbal communication skills.
  • Proficiency with Microsoft Office and familiarity with GRC, analytics, or automation tools.
  • Practical experience using generative AI, scripting, workflow automation, or low-code tools to improve repeatable business processes, with an understanding of prompt design, output validation, sensitive-data handling, access controls, model limitations, and responsible human oversight.
  • Must be able to commute to San Jose, CA or Austin, TX and work on-site at least 3 days per week.

Responsibilities:

  • Conduct end-to-end third-party risk assessments, including due diligence, inherent-risk tiering, control evaluation, residual-risk determination, periodic reassessment, and offboarding review.
  • Administer risk-based vendor questionnaires covering security governance, data protection, access control, vulnerability management, incident response, business continuity, cloud services, and subcontractor oversight; review responses and supporting evidence, clarify gaps with vendors, and translate findings into risk ratings and remediation actions.
  • Maintain enterprise and vendor risk registers with clear risk statements, ratings, owners, treatment plans, and status.
  • Analyze security, privacy, resilience, regulatory, concentration, and fourth-party risks based on business criticality and data sensitivity.
  • Perform technical risk analysis by reviewing system architecture, data flows, cloud and network configurations, identity and access models, encryption, logging, vulnerability results, penetration-test findings, software dependencies, and incident-response capabilities; distinguish design intent from operating effectiveness and document evidence-based conclusions.
  • Apply hands-on security knowledge to validate control implementation through practical review of technical artifacts, targeted demonstrations, sample-based testing, and collaboration with engineers and system owners; translate technical weaknesses and threat scenarios into clear likelihood, impact, residual-risk, and remediation recommendations.
  • Partner with Security, IT, Legal, Privacy, Procurement, and business owners to validate findings and drive proportionate mitigation.
  • Track remediation, escalate material risks and exceptions, and prepare concise leadership reporting, including KRIs, trends, and heat maps.
  • Support policy governance, control testing, issue management, compliance monitoring, and alignment with NIST, ISO 27001, CMMC, and applicable requirements.
  • Design and use analytics, automation, and AI-assisted workflows to improve questionnaire triage, evidence extraction, control mapping, risk-statement drafting, issue classification, continuous monitoring, and reporting; measure process gains and maintain human approval, secure handling of sensitive data, output validation, auditability, and compliance with organizational AI governance requirements.

Nice to Have:

  • Relevant certification or active pursuit, such as Security+ or an AI fundamentals credential.
  • Experience with GRC platforms, vendor monitoring tools, audit support, or control evidence collection.
  • Familiarity with NIST CSF, ISO 27001, CMMC, SOC 2, GDPR, CCPA, or similar requirements.
  • Experience creating clear procedures, SOPs, or workflow documentation in a technology or regulated environment.

Benefits
 
Our Benefits Include:
  • Medical, Dental, and Vision Insurance
  • 401(k) Retirement Plan
  • Health Savings Account (HSA)
  • Disability Insurance (Short-Term and Long-Term)
  • Life and AD&D Insurance
  • Paid Sick Leave (where required by applicable state or local law)
  • Supplemental Insurance Plans
  • Identity Theft Protection
  • Pet Insurance
  • Employee Wellness Programs
  • Employee Assistance Program (EAP)
  • Career Growth and Professional Development Opportunities
Disclaimer: Benefits eligibility, accrual rates, and usage limits may vary based on employment status, length of service, and work location. Paid Sick Leave is provided in strict accordance with applicable state and municipal mandates. Cynet Systems Inc. reserves the right to modify, amend, or terminate any benefit plans at any time in accordance with applicable laws.

About Cynet Systems

Founded in 2010 and headquartered in the Washington, DC metro area, Cynet Systems Inc. is a leading technology staffing and workforce solutions company serving Fortune 500 companies, government agencies, and enterprise organizations across the United States and Canada. We deliver agile, scalable talent solutions across IT, engineering, life sciences, clinical, and professional staffing, powered by a high-performing recruitment engine operating across North America and Asia.
As a nationally and locally certified Minority Business Enterprise (MBE), Cynet Systems is committed to helping organizations build high-performing teams while empowering professionals to grow rewarding careers. Our organization is certified to ISO 9001, ISO 14001, ISO 27001, and SOC 2 Type II standards, reflecting our commitment to quality, security, operational excellence, and customer success.

Cynet Systems logo

About Cynet Systems

Sourced by ZipRecruiter

Cynet Systems Inc is a staffing and recruiting corporation nestled in Ashburn, VA, USA. Established in 2010, the company operates within the Information Technology and Services sector, specializing in providing effective workforce solutions to different business needs, including IT consulting, direct hire, and contract staffing services. Through the years, Cynet Systems has built an impressive portfolio, going beyond borders and expanding its operations internationally in Canada and India. Rooted in its core values of teamwork, leadership, and commitment, Cynet Systems helps businesses unlock their full potential by providing versatile and competent professionals that perfectly align with their needs. Fueled by their unwavering mission to deliver top-tier talent to businesses worldwide, Cynet Systems garnered various recognitions including SIA's fastest-growing staffing firms and Best Place to Work in Virginia for 2019.

Industry

It services

Company size

501 - 1,000 Employees

Headquarters location

Sterling, VA, US

Year founded

2010

Social media