{"schemaVersion":"jobsearcher.job.v1","id":"f925a94ec12d2d9e2183ca99","url":"https://jobsearcher.com/jobs/f925a94ec12d2d9e2183ca99","canonicalUrl":"https://jobsearcher.com/jobs/f925a94ec12d2d9e2183ca99","title":"Security GRC Analyst","description":"Job Title: Security GRC Analyst\r\nOverview\r\nAre you a dedicated security professional passionate about shaping enterprise risk management? We are seeking a dynamic Security GRC (Governance, Risk, and Compliance) Analyst to join a leading organization's security team. In this critical role, you'll influence how the company manages security risks, ensures regulatory compliance, and strengthens its security posture. If you thrive in a fast-paced environment and are eager to make a tangible impact in information security, this opportunity is perfect for you!\r\nRequired Skills\r\n4+ years experience in governance, risk, compliance, or information security\r\n2+ years experience conducting 3rd party and supply chain risk assessments\r\nStrong understanding of CISSP security domains and industry best practices\r\nKnowledge of security regulatory requirements such as SOX and GDPR\r\nFamiliarity with ISMS frameworks (ISO 27001, NIST, CAIQ)\r\nExperience with security certifications (ISO 27001, SOC 1, SOC 2, WebTrust)\r\nAbility to communicate complex risk concepts to diverse audiences\r\nProficiency in controls development, implementation, and assessment\r\nStrong project management, organizational, and interpersonal skills\r\nSelf-motivated with the ability to manage multiple stakeholders across time zones\r\nNice to Have Skills\r\nAutomation experience related to security metrics and reporting\r\nExperience with enterprise security risk management tools and methodologies\r\nKnowledge of security incident response processes\r\nFamiliarity with security awareness training programs\r\nPreferred Education and Experience\r\nBachelor's degree in information security, computer science, or related field (Master's preferred)\r\nProfessional certifications such as CISSP, CISA, CISM, or equivalent are highly desirable\r\nPrior experience working with compliance standards like ISO27001, GDPR, or NIST frameworks\r\nOther Requirements\r\nLocation: San Jose, CA (Hybrid work model: 2 days per week onsite)\r\nDuration: 6+ months with the possibility of extension\r\nStart Date: ASAP\r\nWork Arrangement: Open to W2 and C2C candidates\r\nAdditional: Ability to engage in automation initiatives and support remediation efforts\r\nEqual Opportunity Employment\r\nDeWinter Group and Maris Consulting is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. We post pay scales which are based on our client pay ranges. DeWinter, Maris, and our clients have the right to modify the requirements of the role which can impact the pay ranges posted.\r\nJ-18808-Ljbffr","company":"DeWinter Group","rawCompany":"dewinter group","city":"San Jose","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-07-16T01:35:59.931Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541618","title":"Other Management Consulting Services","slug":"other-management-consulting-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security GRC Analyst","description":"Job Title: Security GRC Analyst\r\nOverview\r\nAre you a dedicated security professional passionate about shaping enterprise risk management? We are seeking a dynamic Security GRC (Governance, Risk, and Compliance) Analyst to join a leading organization's security team. In this critical role, you'll influence how the company manages security risks, ensures regulatory compliance, and strengthens its security posture. If you thrive in a fast-paced environment and are eager to make a tangible impact in information security, this opportunity is perfect for you!\r\nRequired Skills\r\n4+ years experience in governance, risk, compliance, or information security\r\n2+ years experience conducting 3rd party and supply chain risk assessments\r\nStrong understanding of CISSP security domains and industry best practices\r\nKnowledge of security regulatory requirements such as SOX and GDPR\r\nFamiliarity with ISMS frameworks (ISO 27001, NIST, CAIQ)\r\nExperience with security certifications (ISO 27001, SOC 1, SOC 2, WebTrust)\r\nAbility to communicate complex risk concepts to diverse audiences\r\nProficiency in controls development, implementation, and assessment\r\nStrong project management, organizational, and interpersonal skills\r\nSelf-motivated with the ability to manage multiple stakeholders across time zones\r\nNice to Have Skills\r\nAutomation experience related to security metrics and reporting\r\nExperience with enterprise security risk management tools and methodologies\r\nKnowledge of security incident response processes\r\nFamiliarity with security awareness training programs\r\nPreferred Education and Experience\r\nBachelor's degree in information security, computer science, or related field (Master's preferred)\r\nProfessional certifications such as CISSP, CISA, CISM, or equivalent are highly desirable\r\nPrior experience working with compliance standards like ISO27001, GDPR, or NIST frameworks\r\nOther Requirements\r\nLocation: San Jose, CA (Hybrid work model: 2 days per week onsite)\r\nDuration: 6+ months with the possibility of extension\r\nStart Date: ASAP\r\nWork Arrangement: Open to W2 and C2C candidates\r\nAdditional: Ability to engage in automation initiatives and support remediation efforts\r\nEqual Opportunity Employment\r\nDeWinter Group and Maris Consulting is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. We post pay scales which are based on our client pay ranges. DeWinter, Maris, and our clients have the right to modify the requirements of the role which can impact the pay ranges posted.\r\nJ-18808-Ljbffr","datePosted":"2026-07-16T01:35:59.931Z","dateModified":"2026-07-16T01:35:59.931Z","hiringOrganization":{"@type":"Organization","name":"DeWinter Group","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Jose","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"f925a94ec12d2d9e2183ca99"},"url":"https://jobsearcher.com/jobs/f925a94ec12d2d9e2183ca99"}}