×
Register Here to Apply for Jobs or Post Jobs. X

GRC Risk Management Analyst

Job in San Jose, Santa Clara County, California, 95112, USA
Listing for: Cynet Systems
Part Time position
Listed on 2026-08-13
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 68.97 - 72.8 USD Hourly USD 68.97 72.80 HOUR
Job Description & How to Apply Below

Job Title

Pay Range: $68.97hr - $72.8hr

Requirement/Must Have:
  • Education:

    Bachelor’s degree in Information Security, Risk Management, Business, Computer Science, or a related field.
  • Experience:

    1–4 years in enterprise risk, third-party risk, GRC, information security, or a related area.
  • Knowledge of inherent and residual risk, likelihood and impact, controls, treatment, acceptance, and monitoring.
  • Working technical knowledge of enterprise and cloud environments, including networking, operating systems, identity and access management, encryption, secure configuration, vulnerability management, logging and monitoring, application security, and incident response.
  • Ability to interpret technical evidence such as architecture and data-flow diagrams, access reviews, configuration outputs, vulnerability and penetration-test reports, security logs, and independent assurance reports, and to identify when deeper technical validation is required.
  • Ability to assess business impact, apply risk criteria, and communicate clear, defensible recommendations.
  • Strong analytical, organizational, stakeholder-management, and written and verbal communication skills.
  • Proficiency with Microsoft Office and familiarity with GRC, analytics, or automation tools.
  • Practical experience using generative AI, scripting, workflow automation, or low-code tools to improve repeatable business processes, with an understanding of prompt design, output validation, sensitive-data handling, access controls, model limitations, and responsible human oversight.
  • Must be able to commute to San Jose, CA or Austin, TX and work on-site at least 3 days per week.
Responsibilities:
  • Conduct end-to-end third-party risk assessments, including due diligence, inherent-risk tiering, control evaluation, residual-risk determination, periodic reassessment, and offboarding review.
  • Administer risk-based vendor questionnaires covering security governance, data protection, access control, vulnerability management, incident response, business continuity, cloud services, and subcontractor oversight; review responses and supporting evidence, clarify gaps with vendors, and translate findings into risk ratings and remediation actions.
  • Maintain enterprise and vendor risk registers with clear risk statements, ratings, owners, treatment plans, and status.
  • Analyze security, privacy, resilience, regulatory, concentration, and fourth-party risks based on business criticality and data sensitivity.
  • Perform technical risk analysis by reviewing system architecture, data flows, cloud and network configurations, identity and access models, encryption, logging, vulnerability results, penetration-test findings, software dependencies, and incident-response capabilities; distinguish design intent from operating effectiveness and document evidence-based conclusions.
  • Apply hands-on security knowledge to validate control implementation through practical review of technical artifacts, targeted demonstrations, sample-based testing, and collaboration with engineers and system owners; translate technical weaknesses and threat scenarios into clear likelihood, impact, residual-risk, and remediation recommendations.
  • Partner with Security, IT, Legal, Privacy, Procurement, and business owners to validate findings and drive proportionate mitigation.
  • Track remediation, escalate material risks and exceptions, and prepare concise leadership reporting, including KRIs, trends, and heat maps.
  • Support policy governance, control testing, issue management, compliance monitoring, and alignment with NIST, ISO 27001, CMMC, and applicable requirements.
  • Design and use analytics, automation, and AI-assisted workflows to improve questionnaire triage, evidence extraction, control mapping, risk-statement drafting, issue classification, continuous monitoring, and reporting; measure process gains and maintain human approval, secure handling of sensitive data, output validation, auditability, and compliance with organizational AI governance requirements.
Nice to Have:
  • Relevant certification or active pursuit, such as Security+ or an AI fundamentals credential.
  • Experience with GRC platforms, vendor monitoring tools, audit support, or control evidence collection.
  • Familiarity with NIST CSF, ISO 27001, CMMC, SOC 2, GDPR, CCPA, or similar requirements.
  • Experience creating clear procedures, SOPs, or workflow documentation in a technology or regulated environment.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary