1

Grc Risk Jobs in California (NOW HIRING)

GRC Engineer

Foster City, CA · On-site

$210K - $320K/yr

We are looking for a GRC Engineer to serve as a key technical contributor for our compliance and risk management ecosystem. You will architect the systems and processes that automate trust ...

Assisting in the upkeep of governance, risk and compliance (GRC) software applications Interacting with team members and department/division personnel on other GRC related tasks Documenting data and ...

GRC Engineer

Palo Alto, CA · On-site

$130K - $170K/yr

Zania is building agentic AI for Governance, Risk, and Compliance (GRC) to solve this massive problem. We are on a rocketship trajectory , creating intelligent agents that automate and augment the ...

Key Responsibilities Governance, Risk & Compliance * Design, implement, and maintain GRC controls aligned with organizational security and compliance requirements. * Support compliance initiatives ...

Design and build automated workflows for risk management and compliance, creating scalable systems ... Inform GRC platform strategy and implementation: in partnership with other programs, evaluate ...

Design and build automated workflows for risk management and compliance, creating scalable systems ... Inform GRC platform strategy and implementation: in partnership with other programs, evaluate ...

next page

Showing results 1-20

Grc Risk information

What is the difference between Grc Risk vs Grc Analyst?

AspectGrc RiskGrc Analyst
CertificationsISO 31000, CRISC, COSOCISA, CRISC, CISSP
Work EnvironmentRisk management teams, compliance departmentsIT, audit, compliance teams
Industry UsageFinancial, healthcare, corporate sectorsIT, finance, consulting firms
Primary FocusIdentifying and managing enterprise risksAnalyzing controls, assessing risks in systems

Grc Risk professionals focus on enterprise-wide risk management strategies, while Grc Analysts typically analyze specific controls and systems to identify vulnerabilities. Both roles require similar certifications and often work within the same industries, but Grc Risk has a broader scope in risk oversight, whereas Grc Analysts concentrate on detailed control assessments.

What cities in California are hiring for Grc Risk jobs? Cities in California with the most Grc Risk job openings:
Infographic showing various Grc Risk job openings in California as of May 2026, with employment types broken down into 98% Full Time, and 2% Contract. Highlights an 5% Physical, 35% Hybrid, and 60% Remote job distribution.

Other

Posted 20 days ago


Job description

Title: GRC Analyst
Location: San Francisco, CA (4 days onsite)
Duration: 6+ months

Key Responsibilities:
• Conduct technical vendor risk assessments (security, privacy, architecture, data handling) for new and existing third parties
• Review security documentation (SOC 2, ISO 27001, pentest reports, architecture diagrams, data flows) and identify risks
• Drive risk-based decisions - recommend approve / conditional approve / reject with clear rationale
• Track and manage vendor risk findings, remediation plans, and exceptions
• Partner with Legal/Procurement on security terms, DPAs, and contractual requirements
• Respond to internal GRC queries (security questionnaires, audits, customer due diligence)
Qualifications:
• Experience in GRC / Vendor Risk / Security Risk roles
• Strong understanding of cloud/SaaS architectures and common security controls
• Familiarity with frameworks like SOC 2, ISO 27001, NIST, HIPAA, PCI
• Ability to balance risk vs. business enablement in a fast-paced environment
• Strong communication skills with both technical and non-technical stakeholders