1

Grc Risk Analyst Jobs in Irvine, CA (NOW HIRING)

IS Analyst

Los Alamitos, CA ยท On-site

$79K - $95K/yr

As an Information Services Analyst, you'll play an important role in protecting that trust. You'll ... Experience with Governance, Risk, and Compliance (GRC) platforms. * Experience supporting financial ...

Lead Security Engineer, GRC

Costa Mesa, CA ยท On-site

$110K - $144K/yr

ABOUT THE TEAM Anduril's Security Engineering team is looking for a Governance, Risk, and ... analysis * Surface control drift and route findings to system owners with clear remediation and ...

Lead Security Engineer, GRC

Costa Mesa, CA ยท On-site

$166K - $253K/yr

Experience with continuous control monitoring or GRC platforms (Vanta, Drata, Hyperproof, OneTrust ... This third-party service provider provides risk-intelligence services that may include analysis of ...

IS Analyst

Los Alamitos, CA ยท On-site

$79K - $95K/yr

As an Information Services Analyst, you'll play an important role in protecting that trust. You'll ... Experience with Governance, Risk, and Compliance (GRC) platforms. * Experience supporting financial ...

As an Information Services Analyst, you'll play an important role in protecting that trust. You'll ... Experience with Governance, Risk, and Compliance (GRC) platforms. * Experience supporting financial ...

Corporate

Irvine, CA

$90K - $95K/yr

The GRC-RegulatoryCompliance Senior Analyst require proficient knowledge and understanding of ... Conduct risk assessments, compliance audits, and testing of controls to identify gaps and ...

Help track evidence and controls using compliance and GRC tools such as OneTrust, Drata, or similar ... Participate in risk assessments and vulnerability identification efforts. * Assist with ...

Showing results 21-40

Grc Risk Analyst information

See Irvine, CA salary details

$16

$43

$70

How much do grc risk analyst jobs pay per hour?

As of Sep 3, 2026, the average hourly pay for grc risk analyst in Irvine, CA is $43.46, according to ZipRecruiter salary data. Most workers in this role earn between $32.02 and $52.88 per hour, depending on experience, location, and employer.

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What job categories do people searching Grc Risk Analyst jobs in Irvine, CA look for?

The top searched job categories for Grc Risk Analyst jobs in Irvine, CA are:

What cities near Irvine, CA are hiring for Grc Risk Analyst jobs?

Cities near Irvine, CA with the most Grc Risk Analyst job openings:

Infographic showing various Grc Risk Analyst job openings in Irvine, CA as of June 2026, with employment types broken down into 90% Full Time, 1% Part Time, 1% Temporary, and 8% Contract. Highlights an 71% Physical, 7% Hybrid, and 22% Remote job distribution, with an average salary of $90,390 per year, or $43.5 per hour.

Senior Cybersecurity GRC Analyst

AMRO Fabricating Corporation

Huntington Beach, CA โ€ข On-site

$120K - $136K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 8 days ago


Job description

Karman Space & Defense is a leader in the rapid design, development, and production of critical, next-generation system solutions that align with the U.S. Department of War and its allies’ core mission priorities, and meet the accelerating demand for access to space. Building on nearly 50 years of success, we deliver Payload & Protection Systems, Aero/Hydrodynamic Interstage Systems, and Propulsion & Launch Systems to more than 80 prime contractors supporting over 130 space and defense programs.

This role helps drive enterprise-wide cybersecurity governance, risk, compliance, and assurance activities that strengthen control quality, evidence readiness, and risk management across Karman. You will translate regulatory, contractual, and customer requirements into clear controls and reliable evidence; independently assess control effectiveness and risk; and partner with business and technology owners to embed sustainable practices that support audit, assessment, and operational readiness.

Responsibilities

  • Interprets and operationalizes cybersecurity, regulatory, contractual, and customer requirements with business, legal, and technology stakeholders.
  • Maintains cybersecurity governance artifacts including policies, standards, control documentation, mappings, ownership records, and assurance schedules.
  • Evaluates control design, operating effectiveness, evidence sufficiency, exceptions, and residual risk and recommends corrective actions or escalation.
  • Supports sustainable CMMC Level 2, NIST SP 800‑171, DFARS, and Controlled Unclassified Information (CUI) obligations through assessment, evidence validation, remediation, and monitoring.
  • Maintains the Enterprise System Security Plan (SSP), Controlled Site Addenda, system boundaries, inventories, and supporting evidence across regulated environments.
  • Coordinates contractual, regulatory, and CAGE-code traceability, ensuring accurate alignment among obligations, boundaries, sites, and assessment records.
  • Supports Sarbanes‑Oxley (SOX) Information Technology General Controls (ITGC) through narrative development, testing coordination, evidence quality, exception identification, and remediation tracking.
  • Governs cybersecurity risks, exceptions, remediation plans, compensating controls, and acceptance records and prepares leadership-ready materials that translate issues into decisions and business impact.
  • Oversees identity, access, and vulnerability governance, including coverage, aging, remediation performance, exceptions, and validation of closure across responsible teams.
  • Coordinates cybersecurity reviews for third-party services, Software-as-a-Service (SaaS), artificial intelligence (AI) tools, suppliers, and M &A activities, ensuring security, privacy, data-handling, and evidence requirements are met.

Required Qualifications

  • Bachelor’s degree in cybersecurity, information technology, information systems, business, risk management, accounting, audit, or a related field; equivalent relevant experience may be considered.
  • 5+ years of progressive experience in cybersecurity governance, risk, compliance (GRC), IT audit, risk management, control assurance, or related disciplines.
  • Experience assessing control design, operating effectiveness, and evidence sufficiency and translating findings into practical remediation and leadership reporting.
  • Working knowledge of CMMC Level 2, NIST SP 800‑171, DFARS, CUI, SOX ITGC, or comparable regulated control environments.
  • Experience maintaining cybersecurity policies, control narratives, SSPs or equivalent system documentation, evidence repositories, risk registers, Plans of Action and Milestones (POA &Ms), and remediation trackers.
  • Ability to exercise independent judgment, challenge unsupported conclusions, organize complex requirements, and escalate material risk appropriately.
  • Strong written, analytical, presentation, and stakeholder-management skills across technical teams, business owners, auditors, assessors, vendors, sites, and executives.
  • Proficiency with Microsoft 365 tools, including Excel, PowerPoint, Word, Teams, SharePoint, and Outlook.

Preferred Qualifications

  • Experience in aerospace, defense, manufacturing, engineering, or another highly regulated environment.
  • Experience supporting CMMC Level 2 readiness, NIST SP 800‑171 assessments, DFARS compliance, CUI governance, Supplier Performance Risk System (SPRS) requirements, or defense‑contractor cybersecurity needs.
  • Experience with SOX ITGC, internal or external audit, control testing, information technology risk, and remediation governance.
  • Experience with SSPs, site-specific control documentation, specialized‑asset scoping, CUI flows, system boundaries, evidence validation, and POA &M management.
  • Experience with supplier cyber risk, SaaS and AI governance, M &A due diligence, international operations, export controls, or cross-border access risk.
  • Experience using Governance, Risk, and Compliance (GRC) or audit platforms such as ServiceNow, Jira, Archer, AuditBoard, Drata, Vanta, or Hyperproof.
  • Security+, Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Governance, Risk and Compliance (CGRC), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Cybersecurity Maturity Model Certification Certified CMMC Professional (CMMC CCP), or comparable certification.

This position requires U.S. person status under U.S. export control laws, including U.S. citizens and nationals, lawful permanent residents, refugees, and asylees.

Benefits

  • Medical, dental, and vision insurance
  • 401(k) with company match
  • Paid time off
  • Health Savings Account (HSA) with company contribution
  • Flexible Spending Accounts (FSA)
  • Company‑paid life and AD &D insurance
  • Short‑ and long‑term disability coverage
  • Tuition reimbursement

Karman Space and Defense is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, protected veteran status, or any other status protected by applicable law.