Grc Analyst Jobs in California
Grc Analyst jobs in California are among the most active in the country, concentrated in technology, financial services, healthcare, and defense contracting, with openings at every level from entry-level compliance associate through senior GRC manager. The heaviest hiring is in San Francisco, Los Angeles, and San Diego, where established employers like Google, Kaiser Permanente, and Northrop Grumman maintain large compliance and risk functions. The most in-demand specialties are IT risk management, SOC 2 and ISO 27001 compliance, and third-party vendor risk. Find a role that fits below and apply directly.
Find Grc Analyst JobsOverview
Showing 5 of 7+ Grc Analyst jobs











Join Aya Healthcare, winner of multiple Top Workplace awards!
We are seeking a Senior Governance, Risk & Compliance (GRC) Analyst to help operate and mature Aya's enterprise GRC program, with a strong emphasis on compliance automation, scalability, and operational excellence. In this role, you will own GRC projects and deliverables across the organization while serving as a subject-matter expert in compliance operations, risk management, and ServiceNow GRC / IRM.
This is a hands-on opportunity for someone energized by improving modern GRC capabilities and moving away from manual, point-in-time audit work toward automated, continuously operating compliance processes.
You will work cross-functionally across Information Security, IT, Legal, Privacy, Engineering, Finance, and Audit to translate regulatory and framework requirements into practical controls, improve evidence collection and reporting, and deliver clear, actionable insights to stakeholders and leadership.
You will work in the Security organization and report to the Manager, Governance, Risk & Compliance.
This role is remote and will work PST business hours.
Who We Are:
We're an $8+ billion, rapidly growing workforce solutions provider in the healthcare industry. We deliver tech-enabled services that help healthcare organizations meet and manage their contingent labor needs. We build and manage tech-enabled marketplaces for national and local healthcare talent and deliver contingent labor management solutions through our proprietary software platform.
At Aya, we're obsessed with creating exceptional experiences for our clients, clinicians, and employees. In fact, we put employee satisfaction above all else. Our team members are responsible for incomparable customer experience and we know that happy employees are critical to maintaining happy clients. We foster an entrepreneurial, high-energy, low-bureaucracy culture and value innovative thinking and creative problem-solving. We embrace diversity in thought and backgrounds unified by a commitment to high achievement. When you join Aya, you'll be surrounded by teammates who care about you as an individual and leaders who will help you grow both personally and professionally.
Responsibilities:
- Own assigned GRC projects, compliance deliverables, and process improvements from planning through completion.
- Support the day-to-day operation and continuous improvement of Aya's enterprise GRC program.
- Design and improve scalable workflows that translate regulatory and framework requirements into clear control activities and operational responsibilities.
- Support compliance efforts for SOC 2 and ISO/IEC 27001:2022, including readiness activities, audit preparation, evidence coordination, control testing, auditor support, and remediation tracking.
- Establish and maintain clear control ownership, traceability, documentation, and evidence requirements.
- Identify opportunities to replace manual or spreadsheet-driven compliance activities with automated, system-driven processes.
- Improve automated evidence collection, control testing, issue and remediation tracking, dashboards, and reporting.
- Conduct control reviews, risk assessments, evidence evaluations, and compliance gap analyses.
- Monitor remediation activities, follow up with control owners, identify delivery risks, and escalate issues when appropriate.
- Build and maintain dashboards, metrics, and reports that communicate compliance status, trends, exceptions, risks, and remediation progress.
- Partner with ServiceNow platform and engineering teams to ensure GRC solutions are scalable, supportable, and aligned with enterprise processes.
- Engage with customers to respond to compliance, security, privacy, and risk-related questions in RFPs, due diligence requests, contracts, and customer meetings.
- Collaborate with Security, IT, Engineering, Finance, Legal, Privacy, Internal Audit, and business stakeholders to resolve control and compliance issues.
- Translate risk and compliance requirements into clear, business-relevant guidance that enables teams to take action.
- Lead working sessions, walkthroughs, and process discussions with control owners and subject-matter experts.
- Identify emerging risks, process dependencies, and long-term improvement opportunities within the GRC domain.
- Guide and support junior analysts and teammates through collaboration, knowledge sharing, and example.
- Review work products for accuracy, completeness, and alignment with established quality standards.
- Document process improvements, design decisions, procedures, and lessons learned.
Required Qualifications:
- 4+ years of experience in Governance, Risk, and Compliance, Information Security, IT Audit, or a related discipline.
- Hands-on experience operating or configuring GRC tools such as ServiceNow GRC / IRM, Drata, Vanta, or Hyperproof to automate and manage compliance workflows.
- Demonstrated experience owning GRC projects, compliance deliverables, or process-improvement initiatives from planning through completion.
- Strong working knowledge of SOC 2 or ISO/IEC 27001:2022. Familiarity with HIPAA and other healthcare-related compliance requirements is preferred.
- Experience with control design, evidence evaluation, risk assessments, audit support, remediation tracking, or compliance testing.
- Experience improving manual compliance processes through automation, workflow design, or system-based reporting.
- Strong written and verbal communication skills, with the ability to explain risk and compliance concepts to both technical and non-technical audiences.
- Demonstrated ability to work independently, manage competing priorities, anticipate next steps, and escalate risks early.
- Experience collaborating across Information Security, IT, Engineering, Legal, Privacy, Finance, Audit, and business teams.
- Bachelor's degree in IT / CS is preferred.
- CISA, CISSP (or CISSP Associate), CCSP, ISO 27001 credential, or another relevant security or compliance certification is preferred.
- Experience with additional security, compliance, AI governance, and privacy frameworks or regulatory requirements, such as ISO/IEC 42001, NIST AI RMF, NIST CSF, GDPR/UK GDPR, and CCPA/CPRA, is a plus.
- Experience with ServiceNow GRC / IRM implementation, administration, configuration, or integration is preferred.
- Experience developing GRC metrics, dashboards, key performance indicators, or leadership reporting is preferred.
- Experience supporting internal or external audits in a regulated or healthcare-related environment is preferred.
Core Role Criteria:
- GRC Subject-Matter Expertise: Demonstrates deep knowledge within GRC and understands how compliance activities affect related security, technology, privacy, legal, and business processes.
- Project and Outcome Ownership: Owns assigned outcomes end to end, delivers high-quality work, and holds self and project participants accountable for commitments.
- GRC Tool Capability: Experience with modern GRC tools such as ServiceNow, Drata, or Vanta. Experience with ServiceNow GRC / IRM beyond basic end-user activity is preferred.
- Compliance Automation Mindset: Identifies opportunities to reduce manual effort and validates automation or process improvements through measurable results.
- Analytical Judgment: Evaluates evidence, identifies control gaps and emerging risks, understands dependencies, and recommends practical solutions.
- Cross-Functional Collaboration: Builds effective working relationships and guides stakeholders through compliance requirements using clear, business-relevant language.
- Strategic Orientation: Understands emerging risks and long-term trends within GRC and connects day-to-day work to broader organizational objectives.
- Informal Leadership: Leads projects from start to completion and guides teammates through collaboration, knowledge sharing, and example without requiring formal management authority.
- Delivery and Initiative: Manages work independently, anticipates next steps, improves processes, and delivers projects on schedule.
What We Offer:
- Free premium medical, dental, life and vision insurance
- Generous 401(k) match
- Aya also offers other benefits to those that are eligible and where required by applicable law, including reimbursements and discretionary bonuses
- Aya provides paid sick leave in accordance with all applicable state, federal, and local laws. Aya's general sick leave policy is that employees accrue one hour of paid sick leave for every 30 hours worked. However, to the extent any provisions of the statement above conflict with any applicable paid sick leave laws, the applicable paid sick leave laws are controlling
- Celebrations! We hit our goals and reward ourselves.
- Company-sponsored virtual events, happy hours and team-building activities are always on the horizon — plus, you get a special treat on your birthday!
- Unlimited DTO — we believe in time off!
- Virtual yoga, meditation or boot camp classes offered daily
Compensation: Aya reasonably anticipates the pay scale for this position to be an annual salary of $105,000 to $135,000.
The pay scale for this position may vary if applicant possesses experience outside of what Aya reasonably anticipates for this position. Bonuses are subject to the role and your manager's discretion.
Aya is an Equal Opportunity Employer (EEO), including Disability / Vets, and welcomes all to apply. Please click here for our EEO policy
See All 7 Grc Analyst Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find Grc Analyst JobsGrc Analyst Jobs by City in California
Where California roles are concentrated, by current openings.
Grc Analyst Job Market in California
A snapshot from current California openings, updated as new roles post.
Who's Hiring



Top Industries Hiring
- Technology & Software
What California Employers Look For
The qualifications that appear most often in grc analyst jobs across California.
- Bachelor's degree in information security, business, or a related field
- Hands-on experience with GRC platforms such as ServiceNow, Archer, or OneTrust
- Relevant certification such as CRISC, CISA, CISSP, or CISM
- Working knowledge of frameworks including NIST CSF, ISO 27001, and SOC 2
- Experience conducting risk assessments, control testing, and audit support
- Strong written communication skills for policy documentation and executive reporting
Grc Analyst Jobs in California: Frequently Asked Questions
How do you become a grc analyst in California?
Most grc analyst roles in California require a bachelor's degree in information security, computer science, business administration, or a related discipline. California does not issue a state-specific license for this role, but employers consistently favor candidates who hold recognized certifications such as CRISC, CISA, or CISSP. Starting in an IT audit, compliance coordinator, or information security associate role at a California technology company, financial institution, or health system is the most direct entry path.
How much do grc analysts make in California?
Grc analysts in California earn a median of about $96,980 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $57,530 for the lowest 10% to over $158,280 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire grc analysts in California?
Employers hiring grc analysts in California right now include ivo, Gusto, and Atomus, based on current listings on Migrate Mate as of October 2026. California's concentration of large technology firms, regulated financial institutions, and major health systems means demand is consistent and spread across multiple industries statewide.
Which California cities have the most grc analyst jobs?
San Francisco, San Diego, and Irvine have the most grc analyst openings in California. San Francisco leads because of its density of enterprise technology companies and fintech firms, Los Angeles draws demand from entertainment, aerospace, and financial services, and San Diego's strong defense contracting and biotech sectors drive consistent hiring for risk and compliance professionals there.
Are there remote grc analyst jobs in California?
Yes, and more than most fields. About 25% of grc analyst openings tied to California are remote or hybrid as of October 2026, reflecting the desk-based and documentation-heavy nature of the work. Policy development, risk assessments, and control monitoring are the parts of the role most commonly performed remotely, while on-site presence is more often required for audit facilitation and stakeholder meetings.
How can I get hired as a grc analyst in California with little or no experience?
The most realistic entry path is moving from an IT support, internal audit, or IT helpdesk role into a junior GRC or compliance associate position. Large California technology companies and health systems like Salesforce and Kaiser Permanente regularly hire for entry-level compliance analyst and IT audit associate roles that do not require prior GRC experience. Earning a CompTIA Security+ or completing a NIST framework course strengthens any application, and building a small portfolio of sample risk assessments or policy documents gives hiring managers a concrete reason to call.
Where can I find and apply to grc analyst jobs in California?
You can find and apply to grc analyst jobs in California on Migrate Mate, which lists current openings from employers actively hiring across the state. Find the roles that fit your experience and apply directly to each one.
See All 7 Grc Analyst Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find Grc Analyst Jobs