The Information Security Governance, Risk, and Compliance (GRC) Manager is responsible for leading the development, implementation, and ongoing management of the organization's security governance ...
The Information Security Governance, Risk, and Compliance (GRC) Manager is responsible for leading the development, implementation, and ongoing management of the organization's security governance ...
As the Lead, Information Security GRC (Governance, Risk, and Compliance) Automation , you will help build and scale Prudential's automated control testing, monitoring, telemetry, and evidence ...
As the Lead, Information Security GRC (Governance, Risk, and Compliance) Automation , you will help build and scale Prudential's automated control testing, monitoring, telemetry, and evidence ...
Lead, Information Security GRC Automation
Newark, NJ · On-site
$115 - $189/hr
As the Lead, Information Security GRC Automation, you will help build and scale Prudential's automated control testing, monitoring, telemetry, and evidence capabilities. Reporting to the Director of ...
Lead, Information Security GRC Automation
Newark, NJ · On-site
$115 - $189/hr
As the Lead, Information Security GRC Automation, you will help build and scale Prudential's automated control testing, monitoring, telemetry, and evidence capabilities. Reporting to the Director of ...
As the Lead, Information Security GRC (Governance, Risk, and Compliance) Automation , you will help build and scale Prudential's automated control testing, monitoring, telemetry, and evidence ...
As the Lead, Information Security GRC (Governance, Risk, and Compliance) Automation , you will help build and scale Prudential's automated control testing, monitoring, telemetry, and evidence ...
Job Title: SAP Security / GRC Administrator Support Consultant Job Type: Full-Time Job Location ... Minimum Education: · Bachelor's Degree in Computer Science, Information Systems, Engineering, or ...
Quick apply
Job Title: SAP Security / GRC Administrator Support Consultant Job Type: Full-Time Job Location ... Minimum Education: · Bachelor's Degree in Computer Science, Information Systems, Engineering, or ...
Information Security GRC Engineer (OneTrust / NIST) Plano, Texas (Hybrid) Description We are seeking a hands‑on GRC Engineer & Risk Analytics professional who will implement and scale a ...
Quick apply
Information Security GRC Engineer (OneTrust / NIST) Plano, Texas (Hybrid) Description We are seeking a hands‑on GRC Engineer & Risk Analytics professional who will implement and scale a ...
GRC Specialist II
Chicago, IL · On-site
$116K - $144K/yr
GRC Specialist II Salary: $116,000-$144,000 As a Security GRC Specialist II , you'll be a key ... Serve as an Information Security subject matter expert, advising technical and non-technical ...
GRC Specialist II
Chicago, IL · On-site
$116K - $144K/yr
GRC Specialist II Salary: $116,000-$144,000 As a Security GRC Specialist II , you'll be a key ... Serve as an Information Security subject matter expert, advising technical and non-technical ...
Lead, develop, mentor, and retain a high-performing Information Security GRC team. * Establish team objectives, performance measures, responsibilities, and development plans. * Develop, maintain, and ...
Lead, develop, mentor, and retain a high-performing Information Security GRC team. * Establish team objectives, performance measures, responsibilities, and development plans. * Develop, maintain, and ...
Manager, IT Security, GRC
Burlington, NJ · On-site
$150K - $175K/yr
Our client is currently seeking a Manager, IT Security, GRC. This is FT perm role and hybrid in Burlington, NJ Position Overview The Manager of Governance, Risk and Compliance (GRC) plays a critical ...
Manager, IT Security, GRC
Burlington, NJ · On-site
$150K - $175K/yr
Our client is currently seeking a Manager, IT Security, GRC. This is FT perm role and hybrid in Burlington, NJ Position Overview The Manager of Governance, Risk and Compliance (GRC) plays a critical ...
Information Security GRC Analyst III - CISSP preferred
$94K - $164K/yr
The Information Security GRC Analyst III managed day to day, short and long term information security risks and ensures activities are within risk tolerance and in compliance with approved risk ...
Information Security GRC Analyst III - CISSP preferred
$94K - $164K/yr
The Information Security GRC Analyst III managed day to day, short and long term information security risks and ensures activities are within risk tolerance and in compliance with approved risk ...
Security GRC Analyst
San Francisco, CA · On-site
Security GRC Analyst Location: San Francisco , CA - Hybrid Duration: 6 months CTH Qualifications ... Certified Information Systems Auditor (CISA) certification preferred * Ability to work with minimal ...
Security GRC Analyst
San Francisco, CA · On-site
Security GRC Analyst Location: San Francisco , CA - Hybrid Duration: 6 months CTH Qualifications ... Certified Information Systems Auditor (CISA) certification preferred * Ability to work with minimal ...
Information Security GRC Analyst III - CISSP preferred
Dayton, OH · On-site +1
$94K - $164K/yr
The Information Security GRC Analyst III managed day to day, short and long term information security risks and ensures activities are within risk tolerance and in compliance with approved risk ...
Information Security GRC Analyst III - CISSP preferred
Dayton, OH · On-site +1
$94K - $164K/yr
The Information Security GRC Analyst III managed day to day, short and long term information security risks and ensures activities are within risk tolerance and in compliance with approved risk ...
Head of Information Security
Belgrade, MT · On-site
$120 - $180/hr
Lead the GRC function and manage the Information Security team. * Drive information security governance across the organization. * Lead and support international audits, including ISO 27001, PCI DSS ...
Head of Information Security
Belgrade, MT · On-site
$120 - $180/hr
Lead the GRC function and manage the Information Security team. * Drive information security governance across the organization. * Lead and support international audits, including ISO 27001, PCI DSS ...
Serve as an Information Security subject matter expert, advising technical and non-technical ... GRC Platform Administration: Support and optimize Governance, Risk, and Compliance (GRC) technology ...
Serve as an Information Security subject matter expert, advising technical and non-technical ... GRC Platform Administration: Support and optimize Governance, Risk, and Compliance (GRC) technology ...
Manager SAP Security & GRC
Salisbury, NC · On-site
$110 - $140/hr
Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field. * 10+ years of experience in SAP Security and SAP GRC Access Control. * 3-5+ years leading security or ...
Manager SAP Security & GRC
Salisbury, NC · On-site
$110 - $140/hr
Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field. * 10+ years of experience in SAP Security and SAP GRC Access Control. * 3-5+ years leading security or ...
Collaborate with the Information Security GRC team to align risk assessments, risk and control libraries, and Risk and Control Self-Assessments (RCSAs), while leveraging outputs from Internal Audit ...
Collaborate with the Information Security GRC team to align risk assessments, risk and control libraries, and Risk and Control Self-Assessments (RCSAs), while leveraging outputs from Internal Audit ...
What We're Looking For * 5+ years of IT experience, with at least 3 years in Cybersecurity/IT Security (GRC preferred). * Strong background in Risk Management (monitoring, reporting, quantification)
Quick apply
What We're Looking For * 5+ years of IT experience, with at least 3 years in Cybersecurity/IT Security (GRC preferred). * Strong background in Risk Management (monitoring, reporting, quantification)
Serve as an Information Security subject matter expert, advising technical and non-technical ... GRC Platform Administration: Support and optimize Governance, Risk, and Compliance (GRC) technology ...
Serve as an Information Security subject matter expert, advising technical and non-technical ... GRC Platform Administration: Support and optimize Governance, Risk, and Compliance (GRC) technology ...
Senior Security GRC Lead
Manhattan, NY · On-site
Senior Security GRC Lead Austin | Chicago | New York City | Salt Lake City | San Francisco Gong ... For more information, visit gong.io. At Gong, you will join a company built on innovative products ...
Senior Security GRC Lead
Manhattan, NY · On-site
Senior Security GRC Lead Austin | Chicago | New York City | Salt Lake City | San Francisco Gong ... For more information, visit gong.io. At Gong, you will join a company built on innovative products ...
AVP, IT Ops Risk
Coral Gables, FL · On-site
$120 - $180/hr
Collaborate with the Information Security GRC team to align risk assessments, risk and control libraries, and Risk and Control Self-Assessments (RCSAs), while leveraging outputs from Internal Audit ...
AVP, IT Ops Risk
Coral Gables, FL · On-site
$120 - $180/hr
Collaborate with the Information Security GRC team to align risk assessments, risk and control libraries, and Risk and Control Self-Assessments (RCSAs), while leveraging outputs from Internal Audit ...
Information Security Grc information
See salary details
$68K - $79.2K
5% of jobs
$79.2K - $90.5K
6% of jobs
$90.5K - $101.7K
11% of jobs
$103.9K is the 25th percentile. Wages below this are outliers.
$101.7K - $112.9K
15% of jobs
The median wage is $121.2K / yr.
$112.9K - $124.1K
18% of jobs
$124.1K - $135.4K
16% of jobs
$140.1K is the 75th percentile. Wages above this are outliers.
$135.4K - $146.6K
11% of jobs
$146.6K - $157.8K
8% of jobs
$157.8K - $169K
5% of jobs
$169K - $180.3K
4% of jobs
$180.3K - $191.5K
1% of jobs
$68K
$126.8K
$191.5K
How much do information security grc jobs pay per year?
What is an information security GRC?
An Information Security GRC (Governance, Risk, and Compliance) job focuses on ensuring that an organization's security policies, risk management strategies, and regulatory compliance align with industry standards and legal requirements. Professionals in this role assess security risks, implement controls, and develop frameworks to maintain data protection and regulatory adherence. They collaborate with different teams to enforce compliance, conduct audits, and manage security governance. This role is critical in preventing security breaches, ensuring legal compliance, and maintaining customer trust.
What does an information security GRC do?
As an Information Security GRC professional, your daily responsibilities often include conducting risk assessments, monitoring compliance with internal policies and external regulations, and supporting audits. You may review and update governance documentation, communicate risks or compliance issues to stakeholders, and collaborate with IT, legal, and business teams to ensure information security best practices are followed. Additionally, you'll stay current with changes in laws and regulations to maintain the organization's overall security posture. The work is both analytical and collaborative, requiring you to balance technical tasks with effective communication and project management.
What are the key skills and qualifications needed to thrive in the information security GRC position?
To thrive as an Information Security GRC professional, you need a strong understanding of information security principles, risk management frameworks, compliance regulations, and policy development, often supported by a degree in information security or a related field. Familiarity with tools such as GRC platforms (e.g., Archer, ServiceNow), risk assessment software, and certifications like CISSP, CISA, or CRISC is highly valuable. Exceptional analytical thinking, attention to detail, and strong communication skills are important soft skills in this role. These competencies enable you to navigate complex regulatory landscapes, collaborate across teams, and effectively protect an organization's information assets.
Is information security GRC a good career?
Is information security GRC an entry level job?
What cities are hiring for Information Security Grc jobs?
Cities with the most Information Security Grc job openings:
What states have the most Information Security Grc jobs?
States with the most job openings for Information Security Grc jobs include:
What job categories do people searching Information Security Grc jobs look for?
The top searched job categories for Information Security Grc jobs are:

Manager, Information Security GRC
Columbus, OH • On-site
Full-time
Posted 10 days ago
Job description
The Information Security Governance, Risk, and Compliance (GRC) Manager is responsible for leading the development, implementation, and ongoing management of the organization's security governance framework. Responsible for the oversight of risk management activities, ensures compliance with applicable regulations and standards, and drives continuous improvement in the security program. The GRC Manager partners closely with technology, legal, audit, and business stakeholders to embed security into operations and support strategic objectives.
Qualifications:
Education: Bachelor's Degree in Information Technology, Computer Science, Cybersecurity, or related field. Master's Degree preferred.
Licenses/Certifications: Valid Driver's License, CISSP, CISA or CRISC.
Preferred: Relevant certifications such as CompTIA Security+, Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC) or similar credentials.
Experience: Seven or more years of combined experience in information security, IT or risk management, preferably in a financial institution. Experience leading a team. Or equivalent combination of education and experience.
Essential Functions:
A: Job Specific:
- Designs and executes end-to-end risk assessments that include internal, third party and fourth party vendors, identifying high-impact vulnerabilities, threats, and business risk across the enterprise.
- Oversees compliance with security policies, industry standards, and regulations (e.g., NIST CSF, HIPAA, NIST 800-53, PCI-DSS, GDPR, GLBA or ISO 27001).
- Develops and updates security policies, standards, and procedures to address evolving risk and regulatory requirements.
- Leads audit preparation and response efforts, managing interactions with external auditors and ensuring timely resolution of findings.
- Leads investigations into security incidents, performing detailed root cause analysis and impact assessments.
- Designs and implements advanced security metrics and key risk indicators (KRIs) to measure and communicate risk posture.
- Acts as a trusted advisor to senior management, providing insights on risk trends, mitigation strategies, and security investments.
- Collaborates with business units, IT, legal and compliance teams to embed risk management into strategic initiatives and projects.
- Leads and mentor junior analysts, providing guidance on technical skills, risk methodologies, and professional development.
- Partners with HR to manage staff performance issues/concerns, develop/identify training needs, recruitment processes.
Knowledge/Skills/Abilities:
- Excellent verbal and written communications at both business and deep technical levels.
- Strong understanding of and experience with process improvement and process mapping.
- Strong leadership skills, dependable, curious, matrix-oriented, a visionary, solution oriented, delivers exemplary customer service and quality focused.
- Excellent interpersonal skills.
- Self-directed and motivated.
- The ability to manage multiple tasks.
- Ability to read and comprehend instructions, correspondence, technical manuals and memos.
- Ability to respond to common inquiries or complaints from employees, vendors and management staff.
- Ability to effectively present information to individuals one-on-one or a small group setting.
- Ability to articulate technical concepts to end-users.
- Advanced knowledge of TPRM platforms and ability to optimize.
- Proactive Mindset: Staying ahead of emerging threats and taking initiative in risk mitigation.
- Strong analytical and problem-solving skills.
- Attention to Detail: Ability to identify subtle security vulnerabilities and ensure accurate documentation.
- Adaptability: Capacity to learn and adapt to rapidly evolving security threats and technologies.
- Teamwork: Willingness to collaborate with other team members for effective risk mitigation.
- Time Management: Skill in prioritizing tasks and managing workload in a fast-paced environment.
Sutton Bank is an All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, sexual orientation, gender identity, pregnancy, disability or protected veteran status.
About Sutton Bank
Sourced by ZipRecruiter
Industry
Commercial banking
Company size
51 - 200 Employees
Headquarters location
Attica, OH, US
Year founded
1878