Grc Analyst Jobs in California
Grc Analyst jobs in California are among the most active in the country, concentrated in technology, financial services, healthcare, and defense contracting, with openings at every level from entry-level compliance associate through senior GRC manager. The heaviest hiring is in San Francisco, Los Angeles, and San Diego, where established employers like Google, Kaiser Permanente, and Northrop Grumman maintain large compliance and risk functions. The most in-demand specialties are IT risk management, SOC 2 and ISO 27001 compliance, and third-party vendor risk. Find a role that fits below and apply directly.
Find Grc Analyst JobsOverview
Showing 5 of 8+ Grc Analyst jobs











Kura Sushi USA is a publicly traded U.S. company established in 2008 as a subsidiary of Kura Sushi, Inc. We are an innovative and tech interactive Japanese restaurant chain serving up the ultimate eater-tainment dining experience with a combination of premium ingredients, advanced technology, and affordable prices to create a one-of-a-kind revolving sushi dining experience.
Come join the Kura Krew! We have and exciting opportunity to join our growing team.
The GRC (Governance Risk & Compliance)-Senior Security Analyst will be responsible for safeguarding Kura’s IT (Information Technology) infrastructure by monitoring security systems, conducting vulnerability assessments, and responding to security incidents under the direction of the Integrated GRC Senior Manager. This includes but not limited to monitoring activity throughout the Kura Sushi USA (“Kura”) environments and responding to security alerts in real time; Analyzing system logs, intrusion detection alerts, and suspicious activity; conducting vulnerability assessments and penetration testing; providing guidance on firewall security configurations, Intrusion Prevention System (IPS)/Intrusion Detection System (IDS), and endpoint protection systems; Investigating and documenting security incidents, including root cause analysis; developing and enforcing security and data governance via policies, procedures, and compliance standards; collaborating with ACAS and IT teams to strengthen security controls; and provide cybersecurity training and awareness to staff.
DUTIES: Essential: Key responsibilities include but not limited to:
- Forensic Analysis: Conduct forensic analysis of Security Information Event Management (SIEM), environment telemetry or log events to identify security incidents and vulnerabilities.
- Security Solutions: Evaluate, recommend, and implement security solutions to enhance core security capabilities, including access management and network security.
- Incident Response: Monitor security networks for breaches, respond to incidents, and conduct thorough investigations to mitigate risks.
- Vulnerability Assessments: Perform periodic vulnerability assessments and threat hunting to identify and address potential security weaknesses.
- Collaboration: Work closely with IT teams to ensure secure system configurations and compliance with security policies.
- Reporting: Prepare regular security reports for management, detailing findings and recommendations for improvements.
- Training: Conduct security awareness training for staff to promote a culture of security within the organization.
- Other duties as directed by the Integrated GRC Senior Manager and/or the VP of Audit, Compliance and Advisory Services.
Security Regulatory Compliance:
1. Ensures the organization complies with all applicable security laws, regulations, and internal security policies. as it relates to security. This includes monitoring business operations and reporting any infractions.
2. Partners with other members of the GRC team, Head of Department (HOD) of IT and other members of management where/when applicable. 3. Policy Development: Create, modify, and implement enterprise-wide security policies and procedures.
4. Risk Management: Develop risk management strategies and conduct regular assessments to identify areas of potential non-compliance.
5. Training and Education: Design and deliver training programs for employees to ensure they understand compliance requirements and the importance of adhering to them.
6. Liaison with Regulatory Bodies: Act as the point of contact between the organization and regulatory agencies, handling inspections and assessments.
7. Incident Management: Perform assigned duties within the incident response plan. Investigate compliance breaches, conduct root cause analysis, and implement corrective actions to prevent recurrence.
8. Provides regular reports to the VP of ACAS and applicable senior management security posture.
9. Conducts annual security risk assessments
10. Reviews contracts containing Personal Identifiable Information (PII) and system components to ensure Data Processing Agreements (DPAs) are issued to 3rd party vendors.
11. Performs security assessments/reviews, monitors compliance deficiencies/remediation efforts, conducting/leading security investigations.
1. Provides guidance to other members of ACAS Information Technology management in building a strong IT/Security compliant environment including guiding and mentoring direct and indirect team members.
2. Providing guidance and facilitating coordination with cross-functional members in implementing processes such as Security and IT governance, risk, and compliance activities to automate and facilitate continuous monitoring of information security controls, exceptions, risks, and testing.
3. Contributes to the development and implementation of the Data Governance program, as directed by the Integrated GRC Senior Manager.
4. Liaise with GRC/Internal Audit and IT members to ensure appropriate controls over IT/Security design while working with the IT management and cross-functional members to facilitate operational efficiencies and effectiveness relating to:
- Systems Development Life Cycle (SDLC)-New and existing systems
- Cyber Security, Data Security management
- Artificial Intelligence (AI)
- Identity & Access Management (IAM) e.g., privileged access, User Access Reviews (UARs)
- Security System configurations, e.g., provisioning and deprovisioning
- System and Organizational Controls (SOC) Evaluations
- Other security activities
6. Builds and enhances the organization’s cybersecurity strategy to proactively identify/address relevant security gaps, ensure compliance with internal policies and external regulatory requirements, and improving Kura’s overall security posture and program.
7. Collaborates with cross-functional business and the information technology team to ensure security strategies and initiatives align with business objectives.
8. Provides guidance to the other members of ACAS and the IT team in developing the system-wide information security compliance program, ensuring IT activities, processes, and procedures meet defined requirements, security policies, and regulations.
9. Train and mentors other ACAS GRC members, who will at a minimum, facilitate and monitor compliance related to the security and change management processes.
10. Facilitation and the coordination, development and implementation of security awareness compliance programs and education while partnering with the IT Team.
11. Facilitates, guides coordinates, and partners with other ACAS-GRC members during the systems development life cycle activities and new processes to ensure security components are properly implemented.
12. Evaluates IT control/process deficiencies issued by the Internal Audit team and provides remediation plans to the Internal Audit Team for recommended design improvements while partnering with the GRC and IT team on remediation plan.
13. Facilitates and provides guidance to the IT HOD in the development of IT policies and procedures and ensures alignment with company goals and security regulatory requirements.
14. Presents issues of IT Security and data security non-compliance to the Integrated GRC Senior Manager and the VP of ACAS
15. Attends continuing professional education to keep abreast of security and technology regulations, emerging risks and strategies.
16. Presents progress and initiatives on a monthly basis based on annual plan to the Integrated GRC Senior Manager and the VP of ACAS
17. Perform other projects assigned by the Integrated GRC Senior Manager and VP of ACAS
Non-Essential:
1. Seeks on-going improvement or more cost- efficient and effective solutions in work processes of the department.
2. Researches and develops resources that create timely and efficient workflow.
3. Performs special projects and other miscellaneous duties as assigned by the Integrated GRC Senior Manager or VP of ACAS.
4. Follows up to complete any assigned work.
5. Maintains high ethical standards in the workplace.
6. Reports all irregular issues and problems to supervisor.
7. Maintains good communication with all Kura team members and outside parties.
8. Complies and maintains confidentiality of all company policies and procedures.
9. Maintains a clean and safe working area.
SKILLS AND QUALIFICATIONS: To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Education/Experience:
1. A bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field
2. Possess relevant certifications such as CISSP or CISM, GIAC or CEH
3. At least 5 years of experience in cybersecurity or IT security role, with a strong understanding of security frameworks and standards such as (NIST, ISO 27001, CIS)
4. Governance, risk and compliance experience from Big 4 consulting firm or fortune 500 company.
5. Hands-on experience in incident response and forensic analysis
6. Knowledge of cloud security (Amazon Web Services (AWS), Azure, or Google Cloud Platform (GCP) environments)
7. Familiarity with threat intelligence platforms and malware analysis
8. Experience with regulatory compliance (CCPA, PCI DSS, SOX, GDPR)
9. Proficient with Optro (formerly AuditBoard)-Cross Comply and various security tools.
10. Proficiency with SIEM tools such as Splunk, Google Security Operations, QRadar, or ArcSight
11. Knowledge of firewalls, intrusion detection/prevention systems, and endpoint security
12. Knowledge of cloud/data security platforms such as Netskope, CheckPoint, Zscaler
13. Knowledge of data security posture management (DSPM) platforms such as BigID and MS Purview
14. Ability to conduct vulnerability assessments and penetration testing
15. Basic scripting skills in Python, PowerShell, or Bash
16. Strong technical background.
17. Excellent leadership and people management skills.
18. Skills in documenting security, risk, and regulatory compliance activities
19. Familiarity with security/technology auditing processes
20. Familiar with dashboard creation
21. Ability to critically think about issues, research, and develop solutions/options that can be shared with stakeholders.
22. Communicates confidently with executive management, corporate support personnel, cross-functional peers, and product/services providers at appropriate technical levels for each and liaises with Internal Audit to ensure appropriate IT General Controls (ITGCs). Demonstrates ability to articulate business cases for identified technology solutions.
23. Excellent analytical and troubleshooting skills.
24. Ability to work under pressure.
PAY RANGE: $90,000 - $95,000/yr. DOE
INDHEADOFFICE
See All 8 Grc Analyst Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find Grc Analyst JobsGrc Analyst Jobs by City in California
Where California roles are concentrated, by current openings.
Grc Analyst Job Market in California
A snapshot from current California openings, updated as new roles post.
Who's Hiring



Top Industries Hiring
- Technology & Software
What California Employers Look For
The qualifications that appear most often in grc analyst jobs across California.
- Bachelor's degree in information security, business, or a related field
- Hands-on experience with GRC platforms such as ServiceNow, Archer, or OneTrust
- Relevant certification such as CRISC, CISA, CISSP, or CISM
- Working knowledge of frameworks including NIST CSF, ISO 27001, and SOC 2
- Experience conducting risk assessments, control testing, and audit support
- Strong written communication skills for policy documentation and executive reporting
Grc Analyst Jobs in California: Frequently Asked Questions
How do you become a grc analyst in California?
Most grc analyst roles in California require a bachelor's degree in information security, computer science, business administration, or a related discipline. California does not issue a state-specific license for this role, but employers consistently favor candidates who hold recognized certifications such as CRISC, CISA, or CISSP. Starting in an IT audit, compliance coordinator, or information security associate role at a California technology company, financial institution, or health system is the most direct entry path.
How much do grc analysts make in California?
Grc analysts in California earn a median of about $96,980 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $57,530 for the lowest 10% to over $158,280 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire grc analysts in California?
Employers hiring grc analysts in California right now include Kura Sushi, ivo, and Adobe, based on current listings on Migrate Mate as of August 2026. California's concentration of large technology firms, regulated financial institutions, and major health systems means demand is consistent and spread across multiple industries statewide.
Which California cities have the most grc analyst jobs?
Irvine, San Francisco, and Carlsbad have the most grc analyst openings in California. San Francisco leads because of its density of enterprise technology companies and fintech firms, Los Angeles draws demand from entertainment, aerospace, and financial services, and San Diego's strong defense contracting and biotech sectors drive consistent hiring for risk and compliance professionals there.
Are there remote grc analyst jobs in California?
Yes, and more than most fields. About 60% of grc analyst openings tied to California are remote or hybrid as of August 2026, reflecting the desk-based and documentation-heavy nature of the work. Policy development, risk assessments, and control monitoring are the parts of the role most commonly performed remotely, while on-site presence is more often required for audit facilitation and stakeholder meetings.
How can I get hired as a grc analyst in California with little or no experience?
The most realistic entry path is moving from an IT support, internal audit, or IT helpdesk role into a junior GRC or compliance associate position. Large California technology companies and health systems like Salesforce and Kaiser Permanente regularly hire for entry-level compliance analyst and IT audit associate roles that do not require prior GRC experience. Earning a CompTIA Security+ or completing a NIST framework course strengthens any application, and building a small portfolio of sample risk assessments or policy documents gives hiring managers a concrete reason to call.
Where can I find and apply to grc analyst jobs in California?
You can find and apply to grc analyst jobs in California on Migrate Mate, which lists current openings from employers actively hiring across the state. Find the roles that fit your experience and apply directly to each one.
See All 8 Grc Analyst Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find Grc Analyst Jobs