1

It Security Grc Analyst Jobs (NOW HIRING)

GRC Analyst

Los Angeles, CA · On-site

$100K - $135K/yr

Who you are Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to join our ... of experience in information security GRC, cybersecurity training, or technology compliance

GRC Analyst

Cleveland, OH · On-site

$99K - $120K/yr

QUALIFICATIONS The GRC Analyst requires a bachelor's degree in Information Security, Cybersecurity, Information Technology, Business, or a related field, or equivalent professional experience. A ...

$80K - $165K/yr

Develop new andanalyze existing internal technology and security controls, to ensure compliance ... Maintain cybersecurity gap analysis documents; gather necessary information from technology and ...

GRC Analyst

Los Angeles, CA · On-site

$100K - $135K/yr

Who you are Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to join our ... of experience in information security GRC, cybersecurity training, or technology compliance

QUALIFICATIONS The GRC Analyst requires a bachelor's degree in Information Security, Cybersecurity, Information Technology, Business, or a related field, or equivalent professional experience. A ...

... IT security, and they are seeking an IT Security Manager (GRC) to oversee the security risk ... risk analysis and risk management processes to identify acceptable levels of residual risk. • ...

Information Security / Risk & Compliance Reports To: Director, Global Information Security Job ... IT, Internal and External auditors. The analyst administers Varonis to classify, monitor, and ...

NY · On-site

Description Position Overview The IT GRC Analyst (CMMC Control Specialist) is responsible for the ... Security Plan (SSP). * Partner with System Administrators and IT Operations to convert POA&M ...

GRC Analyst

Chicago, IL · On-site

$109K - $131K/yr

QUALIFICATIONS The GRC Analyst requires a bachelor's degree in Information Security, Cybersecurity, Information Technology, Business, or a related field, or equivalent professional experience. A ...

... technology. Its goal is to scale and enhance the high-performance computing (HPC) and cloud ... THE POSITION NMC² is hiring a GRC Analyst to join the Information Security team, reporting to the ...

$41.75 - $55.75/hr

... security posture through robust frameworks and controls. We're seeking candidates with strong ... The IT GRC Analyst plays a critical role in ensuring that the organization's IT governance is ...

Information Security analyst with Healthcare experience Involvement with security platforms on ... Archer GRC Disaster Recovery Risk Assessment Security Awareness Pen Testing Vulnerability IT Audit ...

GRC Analyst

Boston, MA · On-site

$82K - $105K/yr

The Team The Analyst Governance, Risk, and Compliance, a member of the Information Security ... technologies * Knowledge of Information Security Standards (ISO 27001/27002, ITIL, etc.

Showing results 41-60

It Security Grc Analyst information

See salary details

$40.5K

$108K

$186K

How much do it security grc analyst jobs pay per year?

As of Sep 11, 2026, the average yearly pay for it security grc analyst in the United States is $108,050.00, according to ZipRecruiter salary data. Most workers in this role earn between $60,000.00 and $148,000.00 per year, depending on experience, location, and employer.

What does an IT Security GRC Analyst do?

An IT Security GRC (Governance, Risk, and Compliance) Analyst is responsible for ensuring that an organization follows industry regulations and security standards related to information technology. They assess security risks, develop and enforce policies, and monitor compliance with laws such as GDPR, HIPAA, or SOX. Their role often includes conducting audits, managing risk assessments, and collaborating with different departments to ensure security best practices are followed. By doing so, they help protect sensitive data and reduce the risk of security breaches.

What are the key skills and qualifications needed to thrive as an IT Security GRC Analyst?

To thrive as an IT Security GRC Analyst, you need strong knowledge of risk management, compliance frameworks (such as ISO 27001, NIST, or GDPR), and security best practices, often backed by a degree in information security or a related field. Familiarity with GRC tools (like RSA Archer or ServiceNow), audit software, and relevant certifications (such as CISSP, CISA, or CRISC) is highly valuable. Excellent analytical thinking, attention to detail, and strong communication skills help you interpret regulations and collaborate effectively across teams. These skills ensure that organizations stay compliant, manage risks proactively, and maintain a robust security posture.

What are some common challenges IT Security GRC Analysts face when implementing new compliance frameworks within an organization?

IT Security GRC Analysts often encounter challenges such as navigating complex regulatory requirements, aligning different departments on risk management goals, and ensuring consistent documentation across the organization. Balancing business objectives with stringent security controls can also be difficult, especially when introducing new frameworks like ISO 27001 or NIST. Effective communication, cross-functional collaboration, and ongoing training are essential to overcome these obstacles and ensure successful compliance implementation.

What is the difference between It Security Grc Analyst vs Cybersecurity Analyst?

AspectIt Security Grc AnalystCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CEH, CompTIA Security+
Work EnvironmentPolicy, compliance, risk management teamsTechnical security operations and incident response
Employer & Industry UsageFinancial, healthcare, government sectors focusing on governanceTech companies, security firms, and organizations with active threat monitoring

While both roles focus on security, the It Security Grc Analyst emphasizes governance, risk, and compliance, ensuring policies align with standards. The Cybersecurity Analyst is more technical, focusing on threat detection and incident response. Understanding these differences helps organizations assign the right responsibilities and professionals to their security needs.

What cities are hiring for It Security Grc Analyst jobs?

Cities with the most It Security Grc Analyst job openings:

What states have the most It Security Grc Analyst jobs?

States with the most job openings for It Security Grc Analyst jobs include:

What are popular job titles related to It Security Grc Analyst jobs?

For It Security Grc Analyst jobs, the most frequently searched job titles are:

GRC Analyst

Los Angeles, CA • On-site

$100K - $135K/yr

Full-time

Medical, Life, Retirement

Re-posted 12 days ago


Job description

Who we are

The real world is the next frontier, and at Metropolis, we are creating the artificial intelligence to make it responsive. We are pioneering the Recognition Economy — a future where mundane repetition disappears and being known unlocks access, comfort and belonging everywhere you go. From transforming parking into a seamless drive-in, drive-out experience for millions of Members to expanding our intelligence layer across retail and hospitality, we are building a world that feels instinctive and magical. The future isn't coming; it's here, and we need builders, innovators and problem solvers to help us create it.

Who you are

Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to join our expanding Security team. Reporting to the Senior Manager, GRC, you will mature information security policies, drive employee security awareness, and pioneer our AI governance framework. You will partner across Technology, Legal, Internal Audit, Procurement, and People Operations to safeguard customer trust and support operational excellence. 

What you'll do
  • Author, update, and enforce corporate security policies to guarantee cross-departmental compliance
  • Deploy and manage required information security training campaigns as the platform owner
  • Transform static policies into interactive modules with comprehension quizzes for mandatory sign-offs
  • Establish and enforce an internal AI governance framework with Data, Legal, and Tech teams
  • Conduct structured risk assessments on emerging tools and internal AI models to maintain behavioral guardrails
  • Report training metrics, policy exceptions, and risk postures directly to senior management
  • Review vendor security profiles and software pipelines to mitigate security risk
What we're looking for
  • 3+ years of experience in information security GRC, cybersecurity training, or technology compliance
  • Proven track record of managing required security awareness programs and driving cross-functional accountability
  • Experience with modern training orchestration platforms and understanding of AI and machine learning data security
  • Working knowledge of standard industry frameworks, specifically SOC 2 and PCI-DSS
  • Communication skills with the ability to explain complex regulatory needs to non-technical employees
  • Bachelor's degree in Cybersecurity, Information Systems, or an equivalent technical discipline 
While not required, these are a plus:
  • GRC certifications such as CISA or CRISC

4 Days in Office: Metropolis values in-person collaboration to drive innovation, strengthen culture, and enhance the Member experience. Our corporate team members hold to our office-first model, which requires employees to be on-site at least four days a week, fostering organic interactions that spark creativity and connection

When you join Metropolis, you'll join a team of world-class product leaders and engineers, building an ecosystem of technologies at the intersection of parking, mobility, and real estate. Our goal is to build an inclusive culture where everyone has a voice and the best idea wins. You will play a key role in building and maintaining this culture as our organization grows. The anticipated base salary for this position is $100,000.00 USD to $135,000.00 USD annually. The actual base salary offered is determined by a number of variables, including, as appropriate, the applicant's qualifications for the position, years of relevant experience, distinctive skills, level of education attained, certifications or other professional licenses held, and the location of residence and/or place of employment. Base salary is one component of Metropolis's total compensation package, which may also include access to or eligibility for healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, basic life insurance, a lucrative stock option plan, bonus plans and more. #LI-CM1 #LI-Onsite

Metropolis may utilize an automated employment decision tool (AEDT) to assess or evaluate your candidacy for employment or promotion. AEDTs are used to assist in assessing a candidate's application relative to the required job qualifications and responsibilities listed in the job posting.

As part of this process, Metropolis retains data relevant to your candidacy, including personal information, for a period that is reasonably necessary for the use of the tool. If you are hired for the position, your data may become part of your employee records.

Metropolis Technologies is an equal opportunity employer. We make all hiring decisions based on merit, qualifications, and business needs, without regard to race, color, religion, sex (including gender identity, sexual orientation, or pregnancy), national origin, disability, veteran status, or any other protected characteristic under federal, state, or local law.