Governance, Risk & Compliance (GRC) Analyst
$120k - $150kChaos Industries
Governance, Risk & Compliance (GRC) Analyst CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage—domain dominance. The company's products are powered by Coherent Distributed Networks (CDN™), empowering warfighters, commercial air operators, and border protection teams to act faster, adapt rapidly, and stay ahead of evolving threats. CHAOS Industries was founded in 2022 and has raised a total of $1 billion in funding from leading investors, including 8VC, Accel, and Valor Equity Partners. The company is headquartered in Los Angeles, with offices in Washington, D.C., San Francisco, San Diego, Seattle, and London. For more information, please visit . Role Overview: Own and mature the CHAOS Industries cybersecurity GRC program by establishing governance structure, policies, standards, expectations, and accountability across CHAOS businesses. You'll report to the IT/Cybersecurity Program Director and work daily with IT, Cybersecurity, Physical Security, and Manufacturing – teams with different priorities and vocabulary; therefore, you’ll spend real time translating broad requirements into controls people adopt. Build and manage cybersecurity risk processes, including risk registers, findings, vulnerabilities, remediation plans, ownership, escalation, and business acceptance. If you enjoy designing frameworks that fit the organization rather than forcing the organization to fit a template, and you want direct input into how a defense company governs risk, this is the seat. Responsibilities: Own risk assessments across several departments and maintain the centralized risk register. Design and maintain a unified, original control framework tailored to CHAOS Industries' operating environment, including a security-by-design approach to systems development and defined: Maximum Tolerable Downtime (MTD), Recovery Point Objective (RPO), and Recovery Time Objective (RTO) for critical systems. Write and maintain policy that goes beyond minimum mandatory compliance, building genuine security maturity rather than satisfying the floor of any one requirement. Manage GRC tooling and related workflows to support risk assessments, control monitoring, and reporting. Prepare for, coordinate, and help run third-party and certification audits, including evidence collection, gap assessments, and auditor liaison. Act as the connective tissue between different department to then develop security and compliance requirements for partner teams and drive them to execution. Report regularly to the Program Director and executive stakeholders on risk posture, audit status, and program maturity. Onsite presence required 4 days per week. Travel: up to 25%, primarily to support Manufacturing and Physical Security control validation across company sites. Physical demands: occasional access to manufacturing floor environments, including required PPE and periods of standing or walking during facility walkthroughs. Support customer, vendor, supplier, and subcontractor cybersecurity risk management, including questionnaires, contract reviews, security expectations, and customer-facing services. Coordinate cybersecurity audits, assessments, evidence requests, customer reviews, and remediation tracking in partnership with Legal, Compliance, commercial teams, IT, and business leaders. Bachelor’s degree or equivalent experience in computer science, cybersecurity, information security, Information Technology, Information Assurance, or a related field, or equivalent practical experience. Deep knowledge of NIST CSF, NIST RMF, the ISO/IEC 27000 series, UK Cyber Essentials, CMMC/NIST 800-171, NIST 800-53. Experience selecting, implementing, or administering GRC tooling and workflows. Exposure to widely recognized governance, risk, and compliance frameworks spanning security, privacy, and quality management domains. Familiarity with OT/ICS security concepts. Minimum of 5 years hands-on GRC or compliance experience combined with prior experience in a DoD environment or military service. Has directly supported a third-party or certification audit from evidence collection through closure. Can apply recognized governance, risk, and compliance frameworks well enough to design real, working controls tailored to a specific organization, not just describe them generically. Has performed or directly supported a formal risk assessment (identification, scoring, and treatment) using a defined methodology. Preferred Requirements: Experience supporting third-party audits in a cloud-centric environment. Has built or materially contributed to a risk register, control framework, or compliance program, not only operated within one already established elsewhere. Has written policy or procedure documentation that a non-security audience could follow and act on. Why CHAOS? Health Benefits: Medical, dental, and vision benefits 100% paid for by the company Additional benefits : 401k (+ 50% company match up to 6% of pay), FSA, HSA, life insurance, and more Our Perks: Free daily lunch, ‘No meeting Fridays’, unlimited PTO, casual dress code Compensation Components: Competitive base salaries, generous pre-IPO stock option grants, relocation assistance, and (coming soon!) annual bonuses Team Growth: 350 employees and counting across 5 global offices Base Salary Range: $120,000 - 150,000 The stated compensation range reflects only the targeted base compensation range and excludes additional earnings such as bonus, equity, and benefits. If your compensation requirements fall outside of the range, we still encourage you to apply. The salary range for this role is an estimate based on a range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. #LI-onsite Are you authorized to work for any employer in the United States? * Select... Are you a U.S. Person (i.e. a U.S. Citizen, a lawful permanent resident of the U.S., or a protected individual as defined by 8 U.S.C. 1324b(a)(3)) who can obtain and maintain a Security Clearance? * Select... Do you presently hold an active U.S. security clearance, or are you eligible to obtain and maintain a U.S. security clearance? * Select... Please note this position does not necessarily require eligibility to obtain and maintain a U.S. security clearance. Are you any of the following “protected individual(s)” as defined in the Immigration and Naturalization Act, 8 U.S.C. 1324b(a)(3)? * Select... EXPORT CONTROLS - This position may require access to information and technology that is subject to U.S. export controls. Your responses to the questions below will be used solely to determine your eligibility under U.S. law to receive information and materials subject to U.S. export controls. #J-18808-Ljbffr
- ...Third Party Governance, Risk and Compliance Analyst We are conducting a search for an experienced Third Party Governance, Risk and Compliance (GRC) Analyst with a minimum of three years' experience and a background in working with Big 4 consulting firms, financial institutions...Suggested
- ...Third Party Governance, Risk and Compliance (GRC) Analyst The Analyst will be a key player in overseeing third-party vendor risk, ensuring regulatory compliance, and supporting enterprise GRC initiatives. The ideal candidate brings hands-on experience with GRC processes...SuggestedContract work
$100k - $135k
Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to mature information security policies, drive employee security awareness, and pioneer our AI governance framework. You will partner across Technology, Legal, Internal Audit, Procurement, and People...Suggested- Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to join our Security team in Los Angeles. You will mature information security policies, drive employee training, and pioneer our AI governance framework across Legal, Tech, and Procurement. You will...SuggestedWork at office
- CHAOS Industries, headquartered in Los Angeles, seeks a Governance, Risk & Compliance Analyst to own and mature the GRC program across multiple business units. You will translate broad requirements into actionable controls and manage risk processes, audits, and policy development...Suggested
$100k - $120k
...Governance Risk & Compliance Engineer Polsinelli is hiring a Governance Risk & Compliance Engineer for any of our offices, with the option to work remotely. However, our preference is for this role to be based in Kansas City. CORE RESPONSIBILITIES Participate...Full timeTemporary workPart timeWork experience placementRemote workFlexible hoursShift work- Whatnot is seeking a Governance, Risk, & Compliance Analyst to strengthen security governance, risk management, and regulatory compliance across our platforms. You will define security requirements, coordinate with partner teams, and lead audit programs to demonstrate...Remote job
$80.05k - $165k
About the Role:Responsible for leading Cybersecurity and IT governance, risk, and compliance efforts, including the establishment and maintenance of IT... ..., assignment, remediation tracking, and closure of GRC-related issues in ServiceNow, ensuring timely resolution,...Full timeWork at office$100k - $135k
...need builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to join our expanding Security team. Reporting to the Senior Manager, GRC, you will mature information security...Temporary workWork at officeLocal area$100k - $135k
...and we need builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to join our expanding Security team. Reporting to the Senior Manager, GRC, you will mature information security...Contract workTemporary workFor contractorsFor subcontractorWork at officeLocal area$80k - $100k
...Union is looking for a Sr. GRC Analyst who will play a critical role... ...‑wide programs that enhance risk ownership, facilitate risk self... ...), policy and procedure governance, issue management, and initiatives... ...for risk, audit and compliance findings, ensuring strong root...Full timeWork at office- ...RevolutionBecome a Cybersecurity Engineering, Risk & Governance Senior Advisor at Southern California... ...infrastructure, application, OT/ICS, compliance, risk, audit, operations, and third-... ...security solution provider and analysts to enhance security solutions to reduce...Local areaRemote workRelocation
$80k - $100k
First Entertainment Credit Union seeks a Sr. GRC Analyst to support enterprise-wide GRC programs, drive risk identification, and advance control maturity. You will... ...role in Los Angeles focuses on RCSA, policy governance, issue management, and risk culture enhancement....Full time- Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to join our expanding Security team. Reporting to the Senior Manager, GRC, you will mature information security policies, drive employee security awareness, and pioneer our AI governance framework....
- ...owned technology and services integrators in the defense and government services industry. We deliver tailored solutions, tested... ...contingent upon award of contract SOSi is seeking a Risk and Compliance Analyst to support mission requirements for a structured approach...Full timeContract workFor contractorsRemote workWorldwide
- The City of Los Angeles is seeking a Cyber Security Analyst to lead cybersecurity activities across governance, risk, and compliance, including audit and privacy initiatives. The role requires a four-year degree in a related field and several years of security-focused...
- ...Risk Compliance Analyst The Risk Compliance Analyst investigates basic to moderate level of claims, including Worker's Compensation and other product lines. This position conducts presentations on general risk issues to Operations and conducts store site inspections...Permanent employmentFull timeLocal area
- ...California Edison (SCE) seeks a Cybersecurity Engineering, Risk & Governance Senior Advisor to lead high-impact initiatives and embed cyber... ...segmentation, logging, vulnerability management, and compliance readiness, while translating complex risk into actionable plans...
- Cybersecurity Engineering, Risk & Governance Senior Advisor Become a Cybersecurity Engineering, Risk & Governance Senior Advisor at Southern... ...across cybersecurity, infrastructure, application, OT/ICS, compliance, risk, audit, operations, and third‑party teams to ensure...Local areaRemote workRelocation
$162k - $310k
GRC Program Manager, US Government Compliance Security - Washington, DC This role is based in Washington, DC. We use a hybrid work model of 3 days in the... ...assistance to new employees. About the Team Governance, Risk, and Compliance (GRC) is foundational to Security...Work at officeRelocation package- Panda Restaurant Group, Inc. is seeking a Risk Compliance Analyst to investigate claims related to workers' compensation and other products, while supporting CO safety and hazardous-material compliance across store locations. The role includes presenting on risk issues...
$164k - $200k
...serve as its Senior Vice President, Chief Compliance Officer (CCO) . This executive will lead the design, implementation, governance, and continuous enhancement of the Bank’s enterprise... ...primary leader for regulatory compliance risk. The CCO is accountable for ensuring the...Full timeLocal areaFlexible hours$50 - $60 per hour
Compliance and Risk Analyst III (Reg W / 23A project) Location: Tempe, AZ or Irving, TX (hybrid 3-4 days on-site) Duration: 6-month contract with... ...Solutions complies with applicable state and local laws governing nondiscrimination in employment in every location in which...Contract workWork at officeLocal areaFlexible hours- Latham & Watkins in Los Angeles is seeking a Vendor Risk Management Analyst to assess, monitor, and mitigate risks in vendor relationships. Located in our Global Services Office with a hybrid schedule, this role focuses on due diligence, risk profiling, and continuous improvement...Work at office
- Jobtailor seeks a seasoned vendor risk management professional to assess and mitigate risks across vendor relationships in a dynamic environment. The role requires 4+ years in vendor risk or related fields, with strong analytical and communication skills and experience...
- Panda Restaurant Group, Inc. is seeking a Risk Compliance Analyst to support CO₂ safety, hazardous-material compliance, and environmental health across store locations. You will investigate incidents, gather evidence, conduct inspections, and assist in safety program development...
- Panda Restaurant Group is seeking a Risk Compliance Analyst in Rosemead, CA to support safety, Workers' Compensation and regulatory compliance across store locations. You will investigate claims, conduct site inspections, and develop risk management programs in partnership...
$95k - $125k
UCLA Outpatient Clinics is seeking a Compliance Analyst to support their comprehensive compliance program. You will conduct and support compliance investigations, review documents to identify risks, and provide guidance on regulatory matters. This role includes preparing...- ABM Industries is seeking an HR Compliance Specialist to coordinate sensitive legal requests, manage HR compliance data, and support investigations across our organization. This role combines policy management, data analytics, and process improvement to ensure timely,...
- University of California - Los Angeles Health is seeking a Compliance Analyst for the Office of Compliance Services. The role supports investigations, reviews, audits, training, and risk mitigation to protect organizational integrity and patient trust. Responsibilities...Work at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Governance, Risk & Compliance (GRC) Analyst. Be the first to apply!
- third party risk analyst Los Angeles, CA
- operational risk specialist Los Angeles, CA
- risk officer Los Angeles, CA
- senior quantitative risk analyst Los Angeles, CA
- transaction risk analyst Los Angeles, CA
- risk analyst Los Angeles, CA
- risk consultant Los Angeles, CA
- it risk analyst Los Angeles, CA
- risk compliance officer Los Angeles, CA
- governance risk & compliance analyst Los Angeles, CA

