Governance, Risk, and Compliance (GRC) Analyst (1042) - Department of Technology
$138.68k - $174.43kCity and County of San Francisco
Governance, Risk, and Compliance (GRC) Analyst (1042) - Department of Technology Apply through the City and County of San Francisco SmartRecruiters portal. Application deadline: 11:59 PM PST, Wednesday, October 29, 2025. About Department of Technology The Department of Technology (DT) is the centralized technology services provider for the City and County of San Francisco, supporting public safety, municipal broadband, cybersecurity, cloud solutions, and more. Benefits of Working for CCSF Competitive pay, benefits, and retirement options Career growth opportunities through training, internal mobility, and subsidized education Diverse work environment in a diverse city Hybrid work schedule Responsibilities Perform cyber risk assessments against City cybersecurity requirements. Conduct vendor risk assessments to evaluate security posture of vendors. Support the cyber awareness training and education program, including phishing simulations. Track and monitor risk mitigation plans. Develop routine reports in accordance with GRC metrics. Coordinate with technology and business groups to assess, implement, and monitor IT‑related security risks/hazards. Conduct technical research to aid in threat assessment or risk mitigation activities. Perform assessments of adherence to standards. Review policies and supporting procedures/processes. Stay up‑to‑date on industry changes related to security. Appointment Type Permanent Exempt (PEX), Full Time. This position is excluded by the Charter from the competitive civil service examination process and will serve at the discretion of the appointment officer. The anticipated duration is 36 months and will not result in an eligible list or permanent civil service hiring. Work Location Primary location: Department of Technology, 1 S Van Ness Ave, San Francisco, CA 94103. Occasional travel to other City sites may be required. Nature of Work Hybrid work schedule may be offered. Traveling within San Francisco may be required. How to Qualify Minimum Qualifications Associate degree in computer science, computer engineering, information systems, or a closely related field from an accredited college or university, OR equivalent in credit units. One (1) year of experience analyzing, installing, configuring, enhancing, and/or maintaining enterprise network components. Substitution: Each year of relevant experience may substitute for one year of academic training, up to a maximum of two (2) years. Completion of the 1010 Information Systems Trainee Program may substitute for the required degree. Desirable Qualifications 1–2 years working in a cyber GRC role. Experience with risk analytics within IT. Familiarity with cybersecurity frameworks (NIST CSF/RMF, NIST 800‑53, FedRAMP, etc.). Familiarity with security standards (e.g., HIPAA, PCI‑DSS, etc.). Familiarity with vendor risk management assessments (e.g., SOC 2, CAIQ, etc.). Comfortable discussing technical topics. Proficiency in Excel or similar. Ability to define and communicate risk in business‑relevant language. Excellent verbal and written communication skills. Experience communicating IT risk concepts to non‑technical people. Knowledge of quantitative risk management, including the Factor Analysis of Information Risk (FAIR). Familiarity with GRC platforms (e.g., SNOW, LogicGate, OneTrust, etc.). Security certifications (e.g., Security+, CISA, CISM, CRISC, etc.). Preferred skills in SharePoint and reporting services. Knowledge of privacy concepts. Verification Applicants may be required to submit verification of qualifying education and experience. Written verification must be on official letterhead, signed by the employer. Selection Procedures Evaluation of applications will consider minimum requirements and assess knowledge, skills, and abilities. Additional screening may be used. Interviews and written or performance exercises may be part of the process. Compensation $66.6750 – $83.8625 (hourly) | $138,684 – $174,434 (annually) EEO Statement The City and County of San Francisco encourages women, minorities, and persons with disabilities to apply. Applicants will be considered regardless of sex, race, age, religion, color, national origin, ancestry, physical or mental disability, medical condition, HIV/AIDS status, genetic information, marital status, sexual orientation, gender identity, gender expression, military and veteran status, or any other protected class. Additional Information Regarding Employment All information will be kept confidential according to EEO guidelines. #J-18808-Ljbffr City and County of San Francisco
$135k - $165k
...Ivo? Ivo is an AI-powered contract review and legal technology company transforming how organizations review, negotiate... ...to scale, we are looking for a highly motivated Governance, Risk & Compliance (GRC) Analyst to support and mature Ivo's security compliance and risk...SuggestedContract workFlexible hours- City and County of San Francisco seeks a Governance, Risk, and Compliance Analyst for the Department of Technology. This position focuses on conducting cyber risk assessments and vendor evaluations while supporting security training and education programs. The ideal candidate...SuggestedFull time
- Spectraforce Technologies is seeking a Database Analyst III in San Francisco, CA. This hands-on role focuses on automating compliance workflows, data governance, and AI-driven automation. Key responsibilities include designing GRC workflows, building dashboards, and supporting...Suggested
$135k - $165k
Ivo AI, Inc. is looking for a Governance, Risk & Compliance (GRC) Analyst based in San Francisco. This role involves supporting compliance programs, conducting risk assessments, and maintaining security policies. The ideal candidate has 3-5 years of related experience and...SuggestedFlexible hours- Ivo Inc. is seeking a GRC Analyst to support compliance and risk management initiatives in their San Francisco office. This is a crucial role designed... ...successful candidate will have 3-5 years of experience in Governance, Risk & Compliance, and be skilled in audits and...SuggestedWork at office
$88k - $124k
IG Compliance & Security Analyst Cooley is seeking an IG Compliance... ...the Information Governance & Data Privacy... ...members of the department are expected to... ...periodic risk assessments and... ...and compliance (GRC) processes, solutions... ...in Information Technology or Computer Information...Full timeTemporary workWork experience placementFlexible hoursWeekend work$159k
...Windsor; Winters; Woodland; Yuba City Department Overview: The Electric Risk & Compliance organization provides governance, oversight, and strategic direction on risk... ...training, guidance, and instruction to regulatory analysts in a work environment that fosters teamwork...Contract workWork experience placementWork at officeFlexible hours2 days per week3 days per week$102.74k - $154.22k
...Information Security Risk & Governance Specialist, Senior The Technology and Data Trust Assurance Services team drives BSC technology and information security... ..., coordinated SOC 2 and PCI-DSS audit and compliance support, information security oversight including NIST...Full timePart timeWork at officeLocal areaWork from homeHome office2 days per week$105k
Requisition ID # 172624 Job Category: Compliance / Risk / Quality Assurance Job Level: Individual Contributor... ...; Windsor; Winters; Woodland; Yuba City Department Overview: The Electric Risk & Compliance organization provides governance, oversight, and strategic direction on...Flexible hours2 days per week3 days per week$122k
Requisition ID # 172621 Job Category: Compliance / Risk / Quality Assurance Job Level: Individual Contributor... ...; Windsor; Winters; Woodland; Yuba City Department Overview: The Electric Risk & Compliance organization provides governance, oversight, and strategic direction on...Flexible hours2 days per week3 days per week- ...management consultancy is seeking a Consultant specializing in technology and fintech to join their San Francisco office. In this... ...will lead engagements that deliver impactful solutions across risk, compliance, and operations. The ideal candidate will have 1-4 years of...Work at office
$95k - $130k
Overview Security GRC Analyst job at LiveRamp. San Francisco... ...of rapidly evolving compliance and privacy... ...is designed to reduce risk in alignment with business... ...of Global Security Governance, Risk and Compliance... ...techniques, and security technologies by attending...Work at officeRemote workWork from homeFlexible hoursNight shift$130k - $150k
...believes in each other, come build with us at Crusoe. About This Role We’re seeking a GRC Analyst to support the day-to-day execution of our Governance, Risk, and Compliance program. Reporting to the Head of GRC, this role focuses on operational compliance...Temporary work$65 - $85 per hour
...Description Job Description Senior GRC Analyst - Security & Compliance LHH Recruitment Solutions is partnering... ...to take ownership of a growing governance, risk, and compliance program within an innovative technology environment. The organization is building...Hourly payContract workTemporary workWork at officeLocal area$150k
...Crusoe Energy Systems LLC is looking for a GRC Analyst in San Francisco, CA to support their Governance, Risk, and Compliance program. The role includes managing user access reviews, supporting audits, and leveraging AI tools for process improvements. Ideal candidates...- ...Title: GRC Analyst Location: San Francisco, CA (4 days onsite) Duration: 6+ months Key Responsibilities: • Conduct technical vendor risk assessments (security, privacy, architecture, data handling) for new and existing third parties • Review security...
- ...A prominent AI research firm based in San Francisco is seeking an AI Emerging Risks Analyst to analyze and mitigate potential risks related to AI technologies. The successful candidate will leverage a strong background in trust and safety to develop actionable intelligence...
$122.9k - $213.4k
...consulting firm is seeking a Senior Consultant for its Risk Technology practice. The role involves assessing and implementing... ...background, excellent communication skills, and experience in governance, risk, and compliance. This position offers a competitive salary range of $12...$193.8k - $228k
...Senior GRC Analyst II job at Carta. San Francisco, CA. The Problems You'll Solve As a Senior GRC Analyst... ...and accordingly establish and maintain governance and risk frameworks. You will build and run security compliance programs to measure and reduce risk, report compliance...Full time$132k - $178k
...Enterprise Risk Analyst Denver, CO or Long Beach, CA... ...ambition to build the technology that secures it. True... ...engineering, security, legal, compliance, and operations teams... ..., enterprise GRC platforms, and MS Project... ...interactions, and government partner reviews....Permanent employmentContract workWork at office- Ivo is looking for a detail-oriented Governance, Risk & Compliance (GRC) Analyst in San Francisco. The ideal candidate will support compliance programs such as SOC 2 Type II and ISO 27001 while managing audits and risk assessments. This onsite role offers a competitive...
- ...Team The Financial Crime Compliance (FCC) team at Airwallex... ...program, sanctions framework, risk assessment methodology, and governance infrastructure across... ..., NYDFS, state banking departments, and FINTRAC). Oversee... ...Governance and Risk Committee (GRC). Provide strategic...Local areaWorldwideShift work
- ...resources in four specialty Information Technology (IT), Clinical Research, Rehabilitation Therapy and Nursing. Job Description The Risk Management Coordinator works independently... ...job alert for this search Risk Management Analyst • San Francisco, CA, United States #J-188...
$159k
...Operations / Strategy; Compliance / Risk / Quality Assurance... ...Woodland; Yuba City Department Summary: The... ...organization provides governance, oversight, and strategic... ...platforms (e.g., GRC, SAP, Power BI) to support... ...to regulatory analysts in a work environment...Work experience placementWork at officeFlexible hours- Payfuture Technologies is looking for a skilled Fraud Analyst to join our team in San Francisco, California. You will play a vital role in detecting and mitigating fraudulent activity related to a fintech credit card product. The ideal candidate has 3-5 years of experience...Contract work
$140k
Requisition ID # 172735 Job Category: Compliance / Risk / Quality Assurance; Accounting / Finance;... ...Windsor; Winters; Woodland; Yuba City Department Overview: The Electric Risk & Compliance organization provides governance, oversight, and strategic direction on risk...Full timeWork at officeFlexible hours- Join RSM US LLP as a Technology Risk Consulting Senior Associate in San Francisco, California. In this role, you will assist with planning engagements, conducting audits, and ensuring compliance with industry standards. You'll work on risk assessments and collaborate with...Flexible hours
- ...Ernst & Young Advisory Services Sdn Bhd is seeking a Senior Consultant based in San Francisco to support risk, compliance, and control activities in modern technology ecosystems. This role emphasizes cloud-native architectures and AI-enabled environments. The ideal...Flexible hours
- A technology services provider is seeking a Fraud Analyst in San Francisco or Portland. The role involves analyzing fraud risks, optimizing alerting strategies, and collaborating with various business units. Applicants should have over 5 years of experience in risk analysis...
$93.8k - $116.3k
...transform themselves to maintain their advantage. The Sia Technology Business Unit supports clients through digital, operations... ...strategize and scale leveraging deep expertise and solutions in compliance and risk management, strategic technology partnerships, data science...H1bWork at officeWorldwideVisa sponsorshipWork visaFlexible hoursShift work3 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Governance, Risk, and Compliance (GRC) Analyst (1042) - Department of Technology. Be the first to apply!
- it risk analyst San Francisco, CA
- governance risk & compliance analyst San Francisco, CA
- risk analyst San Francisco, CA
- senior quantitative risk analyst San Francisco, CA
- operational risk consultant San Francisco, CA
- transaction risk analyst San Francisco, CA
- risk officer San Francisco, CA
- operational risk specialist San Francisco, CA
- risk compliance officer San Francisco, CA
- third party risk analyst San Francisco, CA


