1

Grc Risk Jobs in California (NOW HIRING)

GRC Engineer

Palo Alto, CA · On-site

$130K - $170K/yr

Zania is building agentic AI for Governance, Risk, and Compliance (GRC) to solve this massive problem. We are on a rocketship trajectory , creating intelligent agents that automate and augment the ...

Senior Security GRC Analyst

San Mateo, CA

$109K - $142K/yr

As a member of the Roblox Security Governance, Risk, and Compliance (GRC) team, you will play a key role in supporting the Security team's mission. The GRC team is at the heart of Roblox's security ...

Senior Director, GRC

San Francisco, CA · On-site

$264K - $363K/yr

We don't view Governance, Risk, and Compliance (GRC) as a passive reporting function or an administrative checklist-we build engineering-forward, automated, and AI-driven GRC programs capable of ...

New

Senior Security GRC Analyst

San Mateo, CA · On-site

$209K - $271K/yr

As a member of the Roblox Security Governance, Risk, and Compliance (GRC) team, you will play a key role in supporting the Security team's mission. The GRC team is at the heart of Roblox's security ...

Leverage modern GRC platforms and automation (e.g., ServiceNow IRM, OneTrust) to scale risk management processes * Serve as a trusted advisor to leadership on security risk posture and decisions

Leverage modern GRC platforms and automation (e.g., ServiceNow IRM, OneTrust) to scale risk management processes * Serve as a trusted advisor to leadership on security risk posture and decisions

GRC Analyst

Los Angeles, CA · On-site

$100K - $135K/yr

Who you are Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to join our expanding Security team. Reporting to the Senior Manager, GRC, you will mature information security ...

Senior GRC Lead

San Francisco, CA · On-site +1

$134K - $185K/yr

What you'll do Brex's Governance, Risk, and Compliance function is at an exciting and pivotal point ... As a Senior GRC Engineer, you will drive critical GRC processes that mitigate risk, keep us ...

The Security Governance, Risk, and Compliance (GRC) team is part of Plaid's security organization, focused on enabling the business by proactively managing information security risks and maintaining ...

The Security Governance, Risk, and Compliance (GRC) team is part of Plaid's security organization, focused on enabling the business by proactively managing information security risks and maintaining ...

Showing results 41-60

Grc Risk information

What is the difference between Grc Risk vs Grc Analyst?

AspectGrc RiskGrc Analyst
CertificationsISO 31000, CRISC, COSOCISA, CRISC, CISSP
Work EnvironmentRisk management teams, compliance departmentsIT, audit, compliance teams
Industry UsageFinancial, healthcare, corporate sectorsIT, finance, consulting firms
Primary FocusIdentifying and managing enterprise risksAnalyzing controls, assessing risks in systems

Grc Risk professionals focus on enterprise-wide risk management strategies, while Grc Analysts typically analyze specific controls and systems to identify vulnerabilities. Both roles require similar certifications and often work within the same industries, but Grc Risk has a broader scope in risk oversight, whereas Grc Analysts concentrate on detailed control assessments.

What cities in California are hiring for Grc Risk jobs?

Cities in California with the most Grc Risk job openings:

Infographic showing various Grc Risk job openings in California as of August 2026, with employment types broken down into 90% Full Time, and 10% Contract. Highlights an 70% In-person, 10% Hybrid, and 20% Remote job distribution.

GRC TPRM Assessment and Remediation SME

Tata Consultancy Service Limited

Sunnyvale, CA • On-site

$80K - $140K/yr

Full-time

Re-posted 11 days ago


Job description

We are seeking an experienced Third-Party Risk Management (TPRM) Assessment and Remediation Subject Matter Expert to manage the end-to-end lifecycle of supplier/vendor cybersecurity risk assessments and remediation from inventory governance through assessment coordination, escalation management, and executive reporting in a fully remote, client-facing environment. This role serves as the process authority for vendor risk assessments, findings management, and cross-functional remediation, requiring precise, proactive communication to maintain trust with high-visibility stakeholders.
Key Responsibilities
1. Supplier Inventory Management
• Maintain the Supplier Inventory (GRC platform, e.g., SupplierNinja) as the single source of truth for assessment status.
• Tier/filter suppliers requiring reassessment vs. new assessment per program criteria.
• Maintain accurate Direct Responsible Individual (DRI) records in the GRC tool (e.g., OneTrust).
2. Assessment Execution
• Evaluate suppliers against standard frameworks (SIG, CAIQ, NIST CSF, ISO 27001, SOC 2) and validate evidence (audit reports, certifications, pen test results).
• Confirm DRI ownership and obtain kick-off acknowledgement before initiating assessments.
• Log and track assessment tasks in a workflow tool (e.g., Wrike), including acknowledgement evidence.
• Confirm onsite-assessed suppliers have current-year coverage (e.g., in AirTable).
• Participate in recurring findings-review meetings (e.g., CSFA), advising on policy and evidence standards.
3. Remediation Management
• Own Corrective Action Plans (CAPs) end-to-end: define SLAs, track progress, drive closure with vendors and business owners.
• Coordinate with Legal, Procurement, and InfoSec on remediation timelines and compensating controls.
4. Stakeholder Communication & Escalation
• Run a structured outreach cadence with DRIs (kick-off 3 follow-ups 3 escalations to management).
• Track response/non-response rates for every outreach cycle.
• Escalate unresolved/high-risk findings to client leadership and track to closure.
5. Weekly Reporting
Deliver a standing weekly metrics report to leadership: outreach volume, response rates, follow-up/escalation status, suppliers approved for (re)assessment, and overall assessment/remediation coverage.
Required Qualifications
• 5+ years in cybersecurity, TPRM, GRC operations, or supplier risk coordination.
• Working knowledge of NIST CSF, ISO 27001, SOC 2, SIG/CAIQ.
• Hands-on experience with GRC/TPRM tools (OneTrust, Archer, ServiceNow GRC, SupplierNinja, or similar).
• Proven ownership of high-volume, multi-step communication workflows with strict tracking/documentation.
• Excellent written communication for remote, client-facing engagement.
• Experience operating in distributed/remote teams.
Preferred Qualifications
• Certification: CTPRP, CRISC, CISA, or CISSP.
• Experience with Wrike, AirTable, Jira, or similar tracking tools.
• Prior experience in regulated industries (financial services, healthcare, insurance).
• Track record producing leadership-facing weekly reporting.
Location : Sunnyvale, CA/Austin, TX
Salary Range : $80,000-$140,000 a year
#LI-AS3