1

Information Security Grc Analyst Jobs (NOW HIRING)

THE POSITION NMC² is hiring a GRC Analyst to join the Information Security team, reporting to the GRC & Privacy Manager and based at our Dallas, TX offices at Victory Commons. This role is the ...

GRC Analyst We are looking for an individual who is personable, comfortable working within a ... Analyze vendor services and information security requirements, maintaining relationships with key ...

THE POSITION NMC² is hiring a GRC Analyst to join the Information Security team, reporting to the GRC & Privacy Manager and based at our Dallas, TX offices at Victory Commons. This role is the ...

Senior GRC Analyst Salary: $120k-$140k + bonus Location: Chicago, IL or Austin, TX Hybrid: 3 days ... Bachelor s degree and 4+ years of Information Security experience * Strong working knowledge of ...

Senior GRC Analyst Salary: $120k-$140k + bonus Location: Chicago, IL or Austin, TX Hybrid: 3 days ... Bachelor s degree and 4+ years of Information Security experience * Strong working knowledge of ...

Information Security / Risk & Compliance Reports To: Director, Global Information Security Job Summary The GRC Analyst - SOX & Data Security Focus plays a critical role in ensuring the effectiveness ...

GRC Analyst We are looking for an individual who is personable, comfortable working within a ... Analyze vendor services and information security requirements, maintaining relationships with key ...

Showing results 41-60

Information Security Grc Analyst information

See salary details

$40K

$96.7K

$158K

How much do information security grc analyst jobs pay per year?

As of Sep 11, 2026, the average yearly pay for information security grc analyst in the United States is $96,652.00, according to ZipRecruiter salary data. Most workers in this role earn between $73,500.00 and $114,500.00 per year, depending on experience, location, and employer.

What is an information security GRC analyst?

An Information Security GRC (Governance, Risk, and Compliance) Analyst is a professional responsible for helping organizations manage their information security risks and ensure compliance with relevant regulations and standards. They assess organizational processes, identify potential vulnerabilities, and develop strategies to mitigate risks. Their role often includes creating and maintaining security policies, conducting risk assessments, and ensuring that the company adheres to frameworks such as ISO 27001, NIST, or GDPR. By doing so, they help protect sensitive data and maintain the organization’s reputation.

What are the key skills and qualifications needed to thrive as an information security GRC analyst?

To excel as an Information Security GRC Analyst, you need a strong understanding of governance, risk management, compliance frameworks (such as ISO 27001 or NIST), and a background in information security, often backed by a relevant degree or certifications like CISSP or CISA. Familiarity with risk assessment tools, GRC platforms (like Archer or ServiceNow), and regulatory requirements is crucial. Attention to detail, analytical thinking, and effective communication are standout soft skills for interpreting complex regulations and collaborating with stakeholders. These competencies are vital to ensuring organizations manage security risks proactively and maintain compliance with industry standards.

How does an information security GRC analyst typically collaborate with other departments to ensure compliance and manage risk?

An Information Security GRC Analyst regularly works cross-functionally with departments such as IT, legal, human resources, and business operations to identify, assess, and mitigate information security risks. This collaboration often involves facilitating risk assessments, ensuring that policies and controls are well understood and implemented, and providing guidance on compliance requirements. Effective communication and relationship-building are crucial, as the analyst must translate technical requirements into actionable steps for non-technical staff. By working closely with other teams, the GRC Analyst helps foster a culture of security and ensures that organizational objectives align with regulatory and security standards.

What is the difference between Information Security Grc Analyst vs Cybersecurity Analyst?

AspectInformation Security Grc AnalystCybersecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, CompTIA Security+, CEH
Work EnvironmentPolicy development, risk management, complianceThreat detection, incident response, technical analysis
Employer & Industry UsageFinancial, healthcare, government sectors focusing on governanceTech companies, security firms, organizations focusing on technical security

The main difference is that an Information Security Grc Analyst focuses on governance, risk management, and compliance, ensuring policies align with standards. In contrast, a Cybersecurity Analyst primarily handles technical security measures, threat detection, and incident response. Both roles require similar certifications but serve different functions within an organization's security framework.

What cities are hiring for Information Security Grc Analyst jobs?

Cities with the most Information Security Grc Analyst job openings:

What states have the most Information Security Grc Analyst jobs?

States with the most job openings for Information Security Grc Analyst jobs include:

What are popular job titles related to Information Security Grc Analyst jobs?

For Information Security Grc Analyst jobs, the most frequently searched job titles are:

Infographic showing various Information Security Grc Analyst job openings in the United States as of September 2026, with employment types broken down into 100% Full Time. Highlights an 57% In-person, and 43% Remote job distribution, with an average salary of $96,652 per year, or $46.5 per hour.

Manager, Information Security (GRC) (Remote)

Salem, OR • On-site

Full-time

Posted 22 days ago


Job description

Job Summary:

We are seeking a Manager, Information Security (GRC) to own and mature Neumo's Governance, Risk, and Compliance program. This role is critical to maintaining our SOC 1, SOC 2, and PCI certifications and to raising our overall information security maturity. You will build the foundation for data governance, risk acceptance and exceptions processes, and a recurring cadence of monthly, quarterly, and annual risk mitigation. This is a hands-on leadership role: you will manage 1–2 direct reports while personally driving audits, risk assessments, and control automation, and participate in incident management alongside the broader security team.

You will be the connective tissue between security engineering, legal, engineering, and executive leadership: translating regulatory and contractual requirements into practical controls, and translating control performance into risk language leadership can act on.
 
This role directly protects Neumo's ability to do business: Our certifications are foundational to customer trust and revenue. You will have the mandate to modernize how we manage risk and compliance, including building automation and AI-driven workflows that scale the program without scaling headcount linearly.


Duties and Responsibilities:

Leadership & Program Ownership

  • Own and execute Neumo's GRC strategy and roadmap, in partnership with the CISO.
  • Manage, mentor, and grow 1–2 direct reports supporting compliance, risk, and audit activities.
  • Set the foundation for data governance: data classification, ownership, retention, and handling standards.
  • Build and maintain the risk register; lead monthly, quarterly, and annual risk mitigation cycles.
  • Own the risk acceptance and policy exception process, including documentation, approval workflows, and periodic review.
  • Report on compliance posture, audit status, and risk trends to executive stakeholders and the board as needed.

Compliance & Audit Management

  • Own end-to-end readiness and execution for SOC 1, SOC 2, and PCI DSS audits, including evidence collection, auditor coordination, and remediation tracking.
  • Maintain and continuously improve the internal control framework mapped to SOC 1/2, PCI, and other applicable frameworks (e.g., ISO 27001, NIST CSF).
  • Track control ownership, testing cadence, and control health across the organization using the GRC platform and Jira.
  • Partner with engineering and IT teams to close control gaps and drive remediation of audit findings within SLA.

Risk, Automation & Cross-Functional Work

  • Design and implement control automation to reduce manual evidence collection and continuous control monitoring (CCM).
  • Leverage AI/LLM tooling to accelerate evidence review, policy drafting, control testing, and risk analysis, with appropriate human oversight.
  • Participate in incident management as the GRC/risk representative: assessing regulatory and contractual impact and ensuring proper documentation.
  • Manage third-party/vendor risk assessments and questionnaires (customer security questionnaires, vendor due diligence).
  • Partner with Legal and Privacy on data protection, regulatory, and contractual compliance requirements.


 Education and Experience:

  • 6+ years of experience in GRC, information security compliance, or IT audit, including experience managing or mentoring others.
  • Direct experience owning SOC 1, SOC 2, and PCI DSS compliance programs end-to-end, including audit management.
  • Hands-on experience with GRC platforms (e.g., Vanta, Drata, ServiceNow GRC, OneTrust, Archer, or similar).
  • Experience building risk management programs: risk registers, risk acceptance/exception processes, and recurring risk mitigation cadences.
  • Foundational experience with data governance concepts (classification, ownership, retention).
  • Relevant certifications (e.g., CISA, CRISC, CISSP, CISM) are a plus but not required.


 Knowledge, Skills and Abilities:

  • Strong working knowledge of Jira for control tracking, remediation workflows, and cross-team coordination.
  • Demonstrated ability to build or deploy control automation and continuous control monitoring.
  • Comfort leveraging AI tools to scale GRC operations (evidence review, policy generation, risk analysis).
  • Ability to participate effectively in incident management, translating technical incidents into risk and compliance impact.
  • Excellent written and verbal communication skills; able to translate technical and regulatory detail for executive audiences.


 
Work Environment:

  • Office setting with a moderate noise level.
  • The employee will work at an individual workstation, using a telephone and computer.
  • Periodic flexibility outside standard business hours may be required to support audits or incident response.


 Physical Demands
:

  • Must be able to remain seated for extended periods.
  • Regular use of a computer and other office machinery, such as printers and copy machines.
  • Occasional movement around the office.
  • Frequent communication via telephone.


Neumo Summary:

With the backing of four decades of public sector expertise and corporate capability, Neumo has successfully supported government services. Neumo was honored and recognized for four (4) consecutive years as a GovTech 100 Company representing the top 100 companies focused on making a difference in and selling to state and local government agencies across the United States.

Neumo is committed to helping communities thrive and brings a wealth of experience combined with innovation. Today, Neumo offers more administrative and financial support to government officials than any other organization. And with a responsive, client-focused approach, we foster partnerships that give our customers the certainty they need to accomplish more.

Neumo offers a competitive benefits and compensation package and are looking for team members who will thrive in our dynamic environment.

Neumo is an Equal Opportunity Employer. Selection for a position will be made without regard to race, religion, national origin, sex, political affiliation, marital status, non-disqualifying physical handicap, and age.