1

Grc Risk Jobs in California (NOW HIRING)

The GRC Risk Manager, a thought leader residing within our security organization, is responsible for implementing and maintaining the risk management framework and program. This position will be part ...

The GRC Risk Manager, a thought leader residing within our security organization, is responsible for implementing and maintaining the risk management framework and program. This position will be part ...

As a key member of GRC Risk Management Systems team, you will play a critical role in the understanding and driving organization's risk management goals. This is an excellent opportunity for a ...

Risk and Compliance Lead

Sunnyvale, CA · On-site

$160K - $190K/yr

Own and mature the security GRC program, including policy lifecycle management, risk register maintenance, and control framework alignment across the organization * Conduct comprehensive enterprise ...

Risk and Compliance Lead

Sunnyvale, CA · On-site

$184.30K/yr

Own and mature the security GRC program, including policy lifecycle management, risk register maintenance, and control framework alignment across the organization * Conduct comprehensive enterprise ...

ServiceNow SecOps Developer

Fremont, CA · On-site

$59 - $81.25/hr

Partner onsite with SOC, GRC, Risk, and IT teams for requirements, UAT, and production support. * Ensure implementations align with enterprise security standards and audit requirements.

The Senior Manager, GRC (Governance, Risk, and Compliance) will lead the strategy, implementation, and effective management of Bloom Energy's GRC framework. The ideal candidate will be focusing on ...

The Senior Manager, GRC (Governance, Risk, and Compliance)will lead the strategy, implementation, and effective management of Bloom Energy's GRC framework. The ideal candidate will be focusing on ...

next page

Showing results 1-20

Grc Risk information

What is the difference between Grc Risk vs Grc Analyst?

AspectGrc RiskGrc Analyst
CertificationsISO 31000, CRISC, COSOCISA, CRISC, CISSP
Work EnvironmentRisk management teams, compliance departmentsIT, audit, compliance teams
Industry UsageFinancial, healthcare, corporate sectorsIT, finance, consulting firms
Primary FocusIdentifying and managing enterprise risksAnalyzing controls, assessing risks in systems

Grc Risk professionals focus on enterprise-wide risk management strategies, while Grc Analysts typically analyze specific controls and systems to identify vulnerabilities. Both roles require similar certifications and often work within the same industries, but Grc Risk has a broader scope in risk oversight, whereas Grc Analysts concentrate on detailed control assessments.

What cities in California are hiring for Grc Risk jobs? Cities in California with the most Grc Risk job openings:
Infographic showing various Grc Risk job openings in California as of May 2026, with employment types broken down into 98% Full Time, and 2% Contract. Highlights an 5% Physical, 35% Hybrid, and 60% Remote job distribution.

Full-time

This job post has expired 1 day ago. Applications are no longer accepted.


Job description

Job Summary:
SHEIN Technology is a leading global online retailer that emphasizes innovation and security. The GRC Risk Manager will implement and maintain the risk management framework, collaborating with various teams to ensure effective risk assessment and management across the organization.
Responsibilities:
• Develop, implement, mature, and champion risk management processes and concepts.
• Deploy the risk management framework, processes, and tools to conduct risk assessments effectively and consistently.
• Manage the risk register and define and report key risk metrics to management on a regular basis.
• Conduct risk assessments of business units, critical processes and information assets.
• Conduct third-party risk assessments and security reviews of third-party agreements.
• Work closely with technology and legal partners and business units to ensure appropriate security and data protection requirements are incorporated into third-party engagements.
• Prepare risk assessment reports to inform risk treatment decisions.
• Track and monitor remediation and risk management activities.
• Maintain a current and comprehensive understanding of relevant industry standards to incorporate into the risk management strategy, framework, and program.
• Support integration and maturation of policy, compliance, and risk frameworks.
Qualifications:
Required:
• A minimum of 7 years of experience in information security risk management, including business impact analysis, risk assessment and treatment, risk metrics and trend analysis.
• Possess a bachelor’s degree or higher in the field of information security, engineering, computer science or equivalent advance technology field of study.
• Relevant security certifications, such as CISSP, CISM, CISA, ISO 27001 Lead Auditor are highly desired.
• Strong knowledge of security and data privacy standards and regulations such as ISO 27k, NIST, CIS, GDPR, CCPA, PCI DSS.
• Team management experience, including setting and aligning team and individual goals, providing clear and timely feedback, and fostering collaboration.
• Experience developing and deploying risk management frameworks and programs, preferably with international experience in an e-commerce or technology related industry.
• Experience with deploying GRC tools is desirable.
• Practical knowledge and experience working with threat modeling frameworks such as STRIDE, MITRE ATT&CK, OCTAVE is desirable.
• Strong analytical and problem-solving skills.
• Strong written and verbal communication skills, with the ability to translate complex and technical issues to all levels of personnel.
• Detail oriented and highly organized, with the ability to thrive in a fast-paced environment and prioritize accordingly.
• High level of personal integrity, with the ability to professionally handle confidential matters and exudes the appropriate level of judgment and maturity.
Preferred:
• Relevant security certifications, such as CISSP, CISM, CISA, ISO 27001 Lead Auditor are highly desired.
• Experience with deploying GRC tools is desirable.
• Practical knowledge and experience working with threat modeling frameworks such as STRIDE, MITRE ATT&CK, OCTAVE is desirable.
Company:
SHEIN is a global online fashion and lifestyle retailer, offering SHEIN branded apparel and products from a global network of vendors, all at affordable prices. Founded in 2008, the company is headquartered in Los Angeles, USA, with a team of 10001+ employees. The company is currently Late Stage.