> Markdown version of [/jobs/ext/2572186-cybersecurity-grc-analyst-consultant](https://www.wearedevelopers.com/jobs/ext/2572186-cybersecurity-grc-analyst-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity GRC Analyst / Consultant - **Company:** TechNix LLC - **Location:** Sacramento, CA, United States - **Contract:** Temporary contract - **Skills:** Cyber Security, RSA Archer Platform - **Published:** August 28, 2026 - **Apply:** https://www.dice.com/job-detail/8b0fb75b-893e-4be8-992c-46264da80ace ## About the Role * Experience in information security, GRC, risk management, or incident response. * Strong knowledge of security policies, procedures, standards, and controls. * Experience with enterprise GRC platforms. * Experience performing security risk assessments and third-party risk assessments. * Knowledge of NIST SP 800-53 and security-control frameworks. * Experience developing incident-response plans and playbooks. * Experience supporting investigations, evidence handling, and post-incident activities. * Strong documentation and communication skills. * Experience in regulated public-sector, healthcare, health-exchange, or similar environments is preferred. ## Description Can attend the Sacramento office for two consecutive days each month, generally the first Wednesday and Thursday., The GRC & Incident Response Security Professional will support the client's information-security governance, risk, compliance, third-party risk, and incident-response functions. The role will work closely with the Information Security Office and provide risk advisory, compliance, incident management, and remediation support., * Governance, Risk & Compliance * Develop, update, and maintain security policies, procedures, standards, and documentation. * Administer and support enterprise GRC platforms. * Perform security risk assessments and compliance reviews. * Provide risk advisory services aligned with: * CMS ARC-AMPE * NIST SP 800-53 Revision 5 * IRS Publication 1075 * Applicable laws, regulations, and internal security requirements. * Conduct third-party/vendor security due diligence. * Perform vendor risk assessments and contract/control reviews. * Support continuous monitoring and risk reporting. * Develop corrective-action plans and track remediation. * Incident Response * Develop and maintain incident-response plans and playbooks. * Support security investigations and incident-management activities. * Assist with evidence handling and documentation. * Coordinate incident communications and reporting. * Support post-incident reviews. * Serve as backup security incident manager. * Provide incident status and escalation reporting to the CISO when required. * Participate in after-hours/on-call incident-response activities when necessary. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Building Security Champions](https://www.wearedevelopers.com/videos/193-building-security-champions) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions)