1

Grc Third Party Risk Analyst Jobs in California (NOW HIRING)

GRC Engineer

Foster City, CA · On-site

$210K - $320K/yr

Third-Party Risk: Architect a scalable framework for assessing third-party vendors and AI model ... Experience with GRC automation tools (e.g., Vanta, Drata) and a bias toward reducing manual toil.

AVP, Business Risk Analyst

El Monte, CA · On-site

$93K - $114K/yr

... third party onboarding and ongoing monitoring activities by supporting respective BRCOs and ... Experience with risk systems or governance, risk, and compliance (GRC) platforms. Understanding of ...

We are looking for a dependable and analytical Risk Analyst I to monitor merchant activity ... Complete business verification and additional research using internal tools and third-party ...

Risk Analyst

Anaheim, CA · On-site

$50K - $60K/yr

We are looking for a dependable and analytical Risk Analyst I to monitor merchant activity ... Complete business verification and additional research using internal tools and third-party ...

Risk Analyst

Anaheim, CA · On-site

$50K - $60K/yr

We are looking for a dependable and analytical Risk Analyst I to monitor merchant activity ... third-party resourcesApprove, pend, decline, or escalate applications based on company ...

Showing results 41-60

Grc Third Party Risk Analyst information

What is a GRC Third Party Risk Analyst?

A GRC Third Party Risk Analyst is a professional who assesses and manages the risks associated with an organization’s external vendors, suppliers, or partners. Their role involves evaluating third-party compliance with regulatory standards and internal policies, identifying potential risks such as data breaches or non-compliance, and recommending mitigation strategies. They use frameworks like GRC (Governance, Risk, and Compliance) to help ensure that third-party relationships do not compromise the organization's security or reputation. This role often collaborates with procurement, legal, and IT teams to maintain robust risk management processes.

What are some typical challenges a GRC Third Party Risk Analyst may encounter when assessing vendors?

As a GRC Third Party Risk Analyst, you may face challenges such as obtaining timely and complete responses from vendors, especially when dealing with large or international organizations. Navigating varying levels of vendor maturity in risk management practices can also be difficult. Additionally, balancing the need for thorough risk assessments with fast-paced business timelines requires strong communication and prioritization skills. Collaborating closely with procurement, legal, and IT teams is essential to ensure all risks are properly identified and managed.

What are the key skills and qualifications needed to thrive as a GRC Third Party Risk Analyst, and why are they important?

To thrive as a GRC Third Party Risk Analyst, you need a strong understanding of risk management frameworks, compliance regulations, and vendor risk assessment methodologies, typically supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (like Archer or ServiceNow), third-party risk management tools, and certifications such as CISA or CRISC is highly beneficial. Strong analytical thinking, attention to detail, and effective communication skills are essential soft skills for this role. These competencies ensure that organizations can accurately assess and mitigate third-party risks, maintaining compliance and protecting sensitive data.

What is the difference between Grc Third Party Risk Analyst vs Grc Vendor Risk Analyst?

AspectGrc Third Party Risk AnalystGrc Vendor Risk Analyst
CertificationsCertifications like CRISC, CISA often preferredSame certifications commonly required
Work EnvironmentFocuses on third-party relationships and risk assessmentsPrimarily evaluates vendor-specific risks and compliance
Industry UsageUsed across finance, healthcare, and tech sectorsCommonly found in industries with extensive vendor networks

The Grc Third Party Risk Analyst and Grc Vendor Risk Analyst roles overlap significantly in certifications and work environment. The main difference lies in scope: the Third Party Risk Analyst assesses overall third-party relationships, while the Vendor Risk Analyst concentrates specifically on individual vendors. Both roles are vital for managing third-party risks in various industries.

What are popular job titles related to Grc Third Party Risk Analyst jobs in California?

For Grc Third Party Risk Analyst jobs in California, the most frequently searched job titles are:

What job categories do people searching Grc Third Party Risk Analyst jobs in California look for?

The top searched job categories for Grc Third Party Risk Analyst jobs in California are:

What cities in California are hiring for Grc Third Party Risk Analyst jobs?

Cities in California with the most Grc Third Party Risk Analyst job openings:

Infographic showing various Grc Third Party Risk Analyst job openings in California as of August 2026, with employment types broken down into 1% As Needed, 87% Full Time, 10% Part Time, and 2% Contract. Highlights an 87% Physical, 4% Hybrid, and 9% Remote job distribution.

Associate Analyst, IT Governance Risk & Compliance

Neurocrine Biosciences

San Diego, CA • On-site

$99K - $100K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

This job post has expired today. Applications are no longer accepted.


Job description

Who We Are:

Neurocrine Biosciencesis a leading biopharmaceutical company with a simple purpose: to relieve suffering for people with great needs. We are dedicated to discovering, developing and commercializing life-changing treatments for patients with under-addressed neurological, psychiatric, endocrine and immunological disorders. The company's diverse portfolio includes FDA-approved treatments for tardive dyskinesia, chorea associated with Huntington's disease, classic congenital adrenal hyperplasia, hyperphagia in Prader-Willi syndrome, endometriosis* and uterine fibroids*, as well as a robust pipeline including multiple compounds in mid- to late-phase clinical development across our core therapeutic areas. For more than three decades, we have applied our unique insight into neuroscience and the interconnections between brain and body systems to treat complex conditions. We relentlessly pursue medicines to ease the burden of debilitating diseases and disorders, because you deserve brave science. For more information, visitneurocrine.com, and follow the company onLinkedIn,X, Facebook and YouTube. (*in collaboration with AbbVie)


About the Role:Provides entry-level support for the Cyber Security Governance, Risk, and Compliance (GRC) program, under regular guidance and direction from the GRC Lead. Supports risk assessments, third-party reviews, audit and compliance support, policy administration, evidence collection, issue tracking, and reporting. Builds practical knowledge of GRC processes, business objectives, regulatory requirements, and cybersecurity frameworks while delivering accurate, timely work.

_

Your Contributions (include, but are not limited to):
  • Assist with routine IT and Cyber Security risk assessments by gathering evidence, documenting results in established templates, and escalating questions, exceptions or potential concerns for review
  • Supports third-party risk activities by tracking requests and questionnaires, organizing vendor evidence, completing initial completeness checks, and maintaining assessment records
  • Supports framework assessments, audits and compliance reviews by coordinating evidence requests, organizing artifacts, reviewing submissions for completeness against established requirements, and documenting follow-up items
  • Maintains accurate GRC records, including risk registries, controls, issues, action plans, exceptions, and assessment status, in approved systems and repositories
  • Assists with mapping policies, controls, and evidence to requirements and frameworks, such as NIST CSF 2.0, ISO 27001, and CIS Controls, using documented procedures
  • Tracks assigned remediation activities and due dates, follows up with action owners, documents updates, and escalates overdue or unclear items
  • Supports policy and procedure administration through formatting, review routing, version control, publication, and maintenance of communication or training records
  • Prepares routine metrics, dashboards, and status reports using established templates; validates data accuracy and supports investigation of identified data variances under guidance
  • Participates in meetings, training, assigned research and process improvements activities; communicates professionally, protects confidential information, and performs assigned GRC support duties
Requirements:
  • Bachelor's degree in Cybersecurity, IT, Information Systems, Business, Risk Management, or a related field and 0-2 years of related experience; internships, co-ops, academic projects, labs, or equivalent practical experience qualify OR
  • Associate's degree in Cybersecurity, IT, Information Systems, Business, Risk Management, or a related field and 1+ year of related experience, including internships, co-ops, military service, or equivalent practical experience
  • Certification is not required; relevant coursework, training, or a foundational certification is preferred
  • Understands Neurocrine's objectives and begins to develop knowledge of its business, services, customers, and operating environment
  • Ability to work collaboratively, follow direction, ask questions, and apply feedback
  • Proficiency with Microsoft 365 applications
  • Good communication, problem-solving, and analytical skills
  • Detail oriented, with a focus on data quality, accuracy, and follow-through
  • Ability to organize work, follow established priorities, and meet deadlines with guidance
  • Foundational understanding of IT cybersecurity, governance, risk, compliance and IT controls gained through education, training, internships, projects or related experience.
  • Interest in pursuing relevant foundational cybersecurity or GRC certifications as part of ongoing professional development.
  • Familiarity with NIST CSF, ISO 27001, CIS Controls, or SOC 2 through coursework or experience
  • Ability to collect, organize, and review evidence against defined criteria under supervision
  • Basic spreadsheet skills to sort, filter, reconcile, and summarize information accurately
  • Ability to document processes, notes, and findings clearly using established templates
  • Ability to handle confidential information with discretion and follow established procedures
  • Ability and willingness to learn GRC processes, tools, and authoritative guidance; receive coaching and apply feedback; and pursue ongoing professional development. Familiarity with automation tools and Artificial Intelligence (A.I.) concepts, including responsible use, privacy, and security

Neurocrine Biosciences is an EEO/Disability/Vets employer.

We are committed to building a workplace of belonging, respect, and empowerment, and we recognize there are a variety of ways to meet our requirements. We are looking for the best candidate for the job and encourage you to apply even if your experience or qualifications don't line up to exactly what we have outlined in the job description.

_

The hourly rate we reasonably expect to pay is $30.97-$41.37. Individual pay decisions depend on various factors, such as primary work location, complexity and responsibility of role, job duties/requirements, and relevant experience and skills. In addition, this position offers an annual bonus with a target of 15% of the earned base salary and eligibility to participate in our equity based long term incentive program. Benefits offered include a retirement savings plan (with company match), paid vacation, holiday and personal days, paid caregiver/parental and medical leave, and health benefits to include medical, prescription drug, dental and vision coverage in accordance with the terms and conditions of the applicable plans.