Find Jobs
Find Jobs Near You – Available Work in Your Location
Cybersecurity GRC Analyst I, II, or III
Career Insights for Vulnerability Analyst / Penetration Tester
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on California data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.
$125,034 / year median in California
+2% projected growth
Job Description
Overview Position:
Cybersecurity GRC Analyst I, II, or III (Depending on experience)Salary:
Starting at $90,000/year+ D.O.E- Actual compensation may vary from posting based on geographic location, work experience, education, and/or skill level.
Location:
On-Site Role -Santa Ana, California Position Summary :
The Cybersecurity AnalystI/II/III
supports the Third-Party Cyber Risk Management (TPCRM) program by identifying, assessing, monitoring, and helping reduce cybersecurity risk across NAF's third-party ecosystem. The role includes vendor cybersecurity assessments, continuous cyber monitoring, Security Architecture Reviews (SARs), AI risk assessments, emerging third-party threat analysis, remediation support, and development of meaningful risk reporting and metrics. This role partners with Third-Party Management (TPM), Legal, Privacy, Enterprise Technology, Procurement, and Business Unit stakeholders to provide practical, risk-based cybersecurity guidance and strengthen third-party cyber resilience. The position may be filled at the I, II, or III level based on the selected candidate's relevant experience, hands-on technical depth, demonstrated judgment, level of accountability, complexity and scale of prior vendor ecosystems, and experience operating in regulated environments. Candidates with more advanced experience are encouraged to apply; title, level, responsibilities, and compensation may be adjusted accordingly.Disclaimer :
Identity Verification checks are in place throughout the Candidate journey to prevent candidate fraud Responsibilities- Level of responsibility will scale with demonstrated capability, hands-on experience, independence, and complexity of prior responsibilities.
General differentiation by level includes:
- Analyst I - Executes defined vendor cyber risk assessments and monitoring activities with guidance; independently handles lower-to-moderate complexity vendors and escalates significant findings. Demonstrates foundational hands-on TPRM/security assessment experience and accountability for an assigned portfolio or assessment queue.
- Analyst II - Independently owns end-to-end assessments for moderate-to-high risk and critical vendors, leads vendor discussions and remediation, performs SAR and AI risk reviews, and makes risk-based recommendations with limited oversight. Demonstrates experience managing larger or more complex vendor populations and working across multiple business and technology stakeholders.
- Analyst III - Leads the most complex, critical, or strategically significant third-party assessments and incidents; provides independent challenge, mentors less-experienced analysts, influences risk decisions, and drives program/process improvements.
- Perform cybersecurity risk assessments for new and existing third-party vendors, review security questionnaires, SOC reports, penetration tests, certifications, policies, and other supporting evidence.
- Assessing vendor security controls across cloud security, identity and access management, AI, encryption, API security, vulnerability management, logging, incident response, and secure software development practices.
- Support or independently lead Security Architecture Reviews (SARs) based on role level and vendor risk. Analyst I supports defined reviews; Analyst II independently leads higher-risk reviews; Analyst III leads complex/critical reviews, challenges control design, and provides senior-level risk recommendations.
- Monitor and investigate emerging third-party cyber threats, including critical vulnerabilities, ransomware, software supply chain attacks, and vendor breaches. Increasing seniority requires greater independence in correlating events to NAF's vendor ecosystem, determining business impact, directing mitigation, and briefing senior stakeholders.
- Assess cybersecurity risks associated with vendor use of Artificial Intelligence (AI), including AI governance, model usage, data handling, AI-enabled services, and emerging AI-related threats.
- Evaluate fourth-party and Nth-party dependencies for concentration, cascading, and systemic supply chain risk.
- Track security findings through remediation and closure. Analyst I coordinates and documents remediation; Analyst II independently challenges vendor responses and validates corrective actions; Analyst III drives resolution of complex/high-risk findings, exceptions, and escalations involving critical vendors or material residual risk.
- Support third-party security incident triage and executive reporting. At higher levels, independently lead vendor cyber incident analysis, determine potential exposure and required actions, develop executive-ready risk briefings, and contribute to KPIs/KRIs and cyber risk quantification.
- Leverage TPRM, continuous monitoring, and generative AI capabilities to improve assessment efficiency, risk visibility, reporting, automation, and overall TPCRM program maturity.
- Partner effectively with TPM, Legal, Privacy, Procurement, Enterprise Technology, Business Units, and other stakeholders to support consistent third-party cyber risk decisions. Qualifications
- Experience performing third-party cybersecurity, technology risk, vendor risk, or related security assessments in an enterprise environment.
- Ability to interpret security documentation such as SOC reports, penetration test reports, vulnerability assessments, security questionnaires, policies, and cloud security documentation.
- Working knowledge of cybersecurity frameworks and standards such as
NIST CSF, NIST SP 800-53, CIS
Critical Security Controls, ISO 27001, and SOC 2.- Experience assessing SaaS, cloud, and/or AI-enabled vendors, with familiarity across Azure, AWS, or GCP environments.
- Experience with TPRM, GRC, or continuous monitoring platforms such as Lema.ai, Black Kite, or comparable enterprise risk solutions is preferred.
- Strong analytical, written, and verbal communication skills, with the ability to translate technical cybersecurity risk for both technical and non-technical stakeholders.
- Demonstrated judgment, ownership, and ability to operate with increasing independence.
- Vendor ecosystem scale: Experience should reflect increasing breadth and complexity rather than a fixed vendor count alone.
- Regulatory and industry complexity: Experience in financial services, banking, mortgage, insurance, healthcare, government, or similarly regulated environments is valued because these environments generally require deeper due diligence, evidence validation, audit readiness, regulatory awareness, and defensible risk decisions.
- Technical complexity: Seniority may also be demonstrated through hands-on assessment of cloud/SaaS platforms, APIs, IAM/SSO, sensitive or regulated data flows, AI-enabled services, critical infrastructure dependencies, security architecture, software supply chain risk, and complex remediation scenarios.
- Accountability and influence: Progression across levels is demonstrated by increasing ownership of risk decisions, independence in vendor challenge, responsibility for remediation and exceptions, ability to manage escalations/incidents, senior stakeholder engagement, mentoring, and contribution to TPCRM process and program maturity.