Jobs › Cybersecurity & IT GRC
Cybersecurity Compliance and IT GRC Jobs
Open Cybersecurity & IT GRC jobs across governance, risk, and compliance, refreshed continuously.
Cybersecurity & IT GRC jobs are a core part of governance, risk, and compliance hiring.
Open Cybersecurity & IT GRC jobs (71)
Developmental- Associate Cybersecurity Specialist
Supervisory IT Specialist (Information Security)
IT CYBERSECURITY SPECIALIST (INFOSEC)
IT CYBERSECURITY SPECIALIST (CUSTSPT/INFOSEC)
IT Cybersecurity Specialist
CYBER ASSESSMENT SPECIALIST
IT Cybersecurity Specialist (INFOSEC)
Supervisory IT Cybersecurity Specialist (INFOSEC)
INFORMATION SECURITY SPECIALIST (Title 32)
INFORMATION TECHNOLOGY CYBER SECURITY SPECIALIST
LEAD INFORMATION TECHNOLOGY SPECIALIST (CYBERSECURITY/NETWORK)
IT CYBERSECURITY SPECIALIST (PLCYPLN/INFOSEC)
Cybersecurity Information Technology Specialist
T5 INFORMATION SECURITY SPECIALIST
Information System Security Officer (ISSO)
IT Cybersecurity Specialist (PLCYPN-INFOSEC)
IT CYBERSECURITY SPECIALIST (ENTARCH)
IT Cybersecurity Specialist (PLCYPLN-INFOSEC)
Information Technology Specialist (Cyber)
IT CYBERSECURITY SPECIALIST (INFOSEC)
Cybersecurity Requirements and Data Protection Lead
Information Security Manager (INFOSEC)
INFORMATION SECURITY SPECIALIST
Supervisory Information Technology Specialist (Information Security)
IT Cybersecurity Specialist (Infosec) - CES Recent Graduate
IT Specialist (Information Security)
Chief Architect for Cyber Services
IT Cybersecurity Specialist (Security)
Supvy IT Spec (SEC) 'Cyber Ops Branch Chief', GS-2210-15 FPL GS-15 (DH)
IT CYBERSECURITY SPECIALIST (PLCYPLN)
SUPV IT CYBERSECURITY SPECIALIST (APPSW)
Lead IT Cybersecurity Specialist
Chief Information Security Officer
IT CYBERSECURITY SPECIALIST (APPSW/INFOSEC)
Deputy Chief Information Security Officer
SUPV IT CYBERSECURITY SPECIALIST (PLCYPLN/INFOSEC)
IT Cybersecurity Specialist (INFOSEC)
IT CYBERSECURITY SPECIALIST (INFOSEC)
IT CYBERSECURITY SPECIALIST (NETWORK/INFOSEC)
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
IT Risk & Compliance Manager
Contractor Special/Program Security Officer (CPSO)
Cybersecurity & AI Engineer Automation
INFORMATION SECURITY SPECIALIST (TITLE 5)
IT CYBERSECURITY SPECIALIST (INFOSEC)
RISK MANAGEMENT & CYBERSECURITY SPECIALIST- ALTERNATE HIRING AUTHORITY
IT Cybersecurity Specialist (PLCYPLN) - CES Recent Graduate
Virtual CISO & Cybersecurity Practice Lead
Senior Director of Information Risk & Governance
Head of Security & AI Governance
Cybersecurity Consultant
Senior Research Lead, AI Security Portfolio
Senior Cybersecurity Engineer Specialist
Security, Risk and Compliance Consultant
Director, Information Security
Cyber Security Engineer III - Incident Response & Risk
Head of Government Cyber Integration
Staff Security Engineer - Identity Risk & Governance
Systems Security Engineer
Program analyst (Cyber Operations)
Program Analyst (Cyber Operations)
IT Specialist Cyber Security (Developmental)
IT CYBERSECURITY SPECIALIST (INFOSEC) TITLE 5
IT CYBERSECURITY SPECIALIST (INFOSEC)
Cybersecurity & IT GRC jobs: what the market looks like right now
A snapshot built from the 71 Cybersecurity & IT GRC roles currently on this page.
What these roles pay by level
| Level | Median midpoint | Postings |
|---|---|---|
| Mid-level | $126k | 44 |
| Senior / lead / manager | $179k | 5 |
| Executive / C-suite | $183k | 6 |
How these figures were calculated, and sources
Primary source: our own board. Every figure above is the median midpoint of the salary ranges published in the live postings on this page. Nothing is estimated, modelled, or carried over from a previous month. It is recalculated each time the board refreshes.
What is included. Only postings that publish a salary range. Hourly, weekly and monthly rates are annualised (2,080 hours, 52 weeks, 12 months). Ranges below $20,000 a year are excluded as data-entry placeholders. A seniority band is shown only when at least five postings support it.
What this is not. These are advertised ranges, not accepted offers. Advertised ranges tend to run wider than what is actually paid, and roles that do not publish a range are missing from the calculation entirely, which can bias the result upward.
For an independent benchmark, compare against the U.S. Bureau of Labor Statistics Occupational Employment and Wage Statistics for SOC 15-1212 — Information Security Analysts, published annually at bls.gov/oes. BLS reports actual wages across all employers rather than advertised ranges, so its medians normally sit below job-board figures.
Where the work is
- Work mode: 3 remote, 2 hybrid, 66 on-site or unstated.
- Seniority mix: mid (54), executive (8), senior (7), director (2)
- Employers hiring more than one: SEI (9), Defense Information Systems Agency (8), U.S. Coast Guard (5), Air National Guard Units (4), Defense Finance and Accounting Service (4), Patent and Trademark Office (3)
Skills these postings ask for
- security control mapping (SOC 2, ISO 27001, NIST CSF)
- evidence automation and continuous monitoring
- vendor security review
- vulnerability and patch governance
- incident response coordination
How to get a cybersecurity GRC job — the full career guide for this field: entry routes, transferable backgrounds, certifications and salary by level.
Certifications that come up most
None of these are universally required, but they appear often enough in Cybersecurity & IT GRC postings to be worth knowing: CISSP, CISM, CISA, CRISC, Security+. The certification academy covers what each one actually tests and who it is for.
Cybersecurity & IT GRC jobs: tools, skills and workflows
What tools do cybersecurity compliance jobs use?
The security GRC stack sits on top of the security stack rather than replacing it. A control library mapped to SOC 2, ISO 27001, NIST CSF and PCI DSS at once, so one test can satisfy four frameworks. An evidence pipeline pulling screenshots, configs and logs out of cloud consoles and ticketing on a schedule instead of by hand every audit. A vendor and third-party risk register. A findings tracker wired to the same ticketing engineering already uses, because a finding nobody can see is a finding nobody fixes. Increasingly a compliance-automation platform doing continuous evidence collection. Our GRC tools and automation skills guide covers how to configure that layer.
What skills do cybersecurity compliance jobs require?
Enough technical depth to argue with an engineer about whether a control is really operating, and enough writing to make an auditor accept the answer. Control mapping across overlapping frameworks. Cloud fundamentals, since most evidence now lives in AWS, Azure or GCP consoles. Scripting or API work to pull evidence automatically. Risk assessment and third-party review. And the workflow design skill to build an evidence process that runs itself rather than turning into a fire drill every audit cycle.
What does the security compliance workflow look like?
Scope the framework, map its requirements to controls that already exist, identify the gaps, assign the gaps as engineering work. Then the operating loop: controls get tested on a cadence, evidence is collected and timestamped, exceptions are documented with compensating controls, findings are tracked to closure, and the whole thing is packaged for the auditor. The difference between a good and bad program is whether evidence is collected continuously or reconstructed in a panic three weeks before fieldwork.
How do I move from security engineering into IT GRC?
You already have the half most people lack. Take one framework, map it against a system you actually operate, and write the control descriptions and test procedures for it. That artifact plus your engineering background is a stronger case than a certificate alone. The cybersecurity and IT GRC career guides map the jobs, and the CISA certification jobs hub shows what the credential is worth in postings right now.
Related cybersecurity and IT GRC roles
Security compliance sits between the engineers who build controls and the auditors who test them:
- IT security compliance manager jobs — mapping security controls to SOC 2, ISO 27001, PCI DSS and NIST, then evidencing they operate.
- CISA certification jobs and IT audit jobs — the independent assurance line over information security.
- Third-party risk jobs — vendor security reviews and supply chain assurance.
- Data privacy jobs — the data-protection half of the same programme.
- AI governance jobs — where security teams are being handed ISO/IEC 42001 and the NIST AI RMF.
Hiring for one of these instead? The GRC and AI governance hiring toolkit has ready-to-edit job description templates, and the career guides map each path.
What an independent source says about cybersecurity pay
Our figures above come from the postings on this page. It is worth setting them beside a source that measures the whole occupation rather than one board. OnlineCybersecurity.org’s cybersecurity salary guide (updated 16 August 2026) compiles federal wage data with certification and clearance premiums:
- $124,910 — national median for information security analysts, per the Bureau of Labor Statistics, across roughly 179,430 people employed.
- 33% projected growth for the occupation, one of the fastest rates BLS publishes.
- CISA adds $10,000 to $20,000 (10–20%), which they attribute to demand in compliance-heavy sectors — the GRC end of security specifically.
- CISSP and CISM each add $15,000 to $25,000, with CISSP holders averaging near $147,000.
- Entry level runs $55,000 to $75,000 before certifications.
Two cautions. Their page quotes the BLS median as both $124,910 and $120,360 in different sections, so treat it as roughly $120–125k rather than a precise figure. And BLS measures information security analysts as a whole, which is broader than the GRC and compliance roles listed on this page — useful as a floor, not a like-for-like comparison.
Their guide also breaks pay down by state and metro area, which our board does not attempt. If you are weighing a relocation, it is the better reference. For a certification-by-certification view of the GRC side, see our certification academy and CISA jobs.
Hiring for Cybersecurity & IT GRC?
We have 71 open Cybersecurity & IT GRC roles on the board right now. Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
Cybersecurity & GRC career guides · All GRC jobs · Job alerts