Updated by
Hi, I'm Jack, the owner of Cybersecurity Jobs List, and co-founder of Himalayas (himalayas.app) and Cavuno (cavuno.com). Across all my platforms, I work with application security daily: dependency vulnerability scanning, secure authentication, API security, and data protection across hundreds of thousands of users. My technical background is in computer science (UNSW), where he studied security engineering and computer networks, and worked as a research assistant on VR experiments that were published in the Journal of Experimental Psychology. I also work with cybersecurity hiring data every day, tracking which companies are posting, what certifications actually appear in listings, how salaries differ by sub-discipline and clearance level, and where the talent gaps are widest. That combination of security practice, engineering at scale, and daily immersion in the hiring data is what shapes the content on this site. I'm currently based in Sydney, Australia.

Hoxhunt, Coretelligent, Socure and XBOW have GRC or security assurance openings worth exploring. Their teams need different kinds of experience: one is hiring a junior colleague with support from senior teammates, while another asks an analyst to bring seven years of relevant work.
We checked the employer pages on 15 September 2026. Use the comparison below to choose where to look, then open the employer's posting before applying. These are selected opportunities, not a ranking of the best places to work, and availability can change.
Compare the GRC openings
Start with location and experience. A role you can do remotely may still require you to live in a particular country, and “analyst” doesn't consistently mean junior.
| Employer | Team focus | Location and arrangement | Experience to check |
|---|---|---|---|
| Hoxhunt | Customer trust and product security | Helsinki, Finland; hybrid, 2–3 office days | Junior; relevant degree in progress or completed; prior experience a bonus |
| Coretelligent | GRC services for clients | United States; remote | 3+ years in relevant GRC or IT work; prior managed-service-provider experience |
| Socure | Public-sector security assurance | Washington, DC hub; hybrid | 4+ years and hands-on continuous-monitoring experience; US eligibility restrictions |
| XBOW | Customer assurance and vendor risk | Remote UK/EU | 7+ years in relevant roles plus hands-on technical experience |
None of the descriptions we checked gave an explicit closing date. That doesn't mean the openings will remain available indefinitely. We also haven't treated silence about sponsorship as either an offer or a refusal.
Four GRC teams to explore
Hoxhunt: a junior role in customer trust
Hoxhunt's Junior Security Engineer, GRC works in Product Security. The posting describes customer security questionnaires, audit evidence and coordination of recurring security activities, with guidance from experienced teammates.
This is a useful example of why you should search beyond “GRC analyst.” Despite the engineer title, the work includes substantial writing and coordination. Previous compliance or audit experience is listed as a bonus. The qualifications include a relevant bachelor's or master's degree completed or in progress, although the employer encourages applicants whose skills are still developing.
The location matters: this is a Helsinki hybrid role with two or three office days each week. We'd put it on a junior candidate's research list if that arrangement is workable and they want customer-facing security work. Prepare to explain how you'd gather a reliable answer from technical colleagues when you don't know it yourself.
Coretelligent: GRC across client environments
The GRC Analyst opening at Coretelligent supports clients through security awareness, vendor risk assessments, controls documentation and audit coordination. You would work with client teams as well as Coretelligent staff.
Its requirements include three or more years in relevant GRC or cybersecurity-focused IT work, plus past experience at a managed service provider. That makes it a more plausible transition for someone already supporting business IT environments than for someone whose entire experience is a short introductory course.
The employer describes the position as remote in the United States. Its application asks about work authorization and sponsorship; the question itself doesn't establish a sponsorship policy.
For this kind of client-service role, we'd prepare an example of keeping several requests moving without mixing up evidence or commitments. An accurate handover and a well-managed deadline can be as useful to discuss as the name of the GRC platform you used.
Socure: hands-on public-sector assurance
Socure's GRC Analyst, Public Sector combines continuous monitoring, vulnerability remediation coordination and audit readiness. The description names FedRAMP and GovRAMP experience and expects practical execution, not just familiarity with the terms.
The employer asks for at least four years of relevant work, including demonstrated continuous-monitoring experience. It also states that applicants must be US citizens or permanent residents living in the United States and able to obtain what the posting calls a US OPM NACI clearance. Check the full requirements with the employer if your eligibility is uncertain.
The current location is a hybrid Washington, DC hub, even though a third-party listing we inspected labeled the role remote. Use the employer's version when planning your application.
We'd consider this a specialist option for someone who can explain an assessment or remediation process they've personally helped execute. A general interest in GRC alone isn't the experience this posting requests.
XBOW: an experienced analyst in a security startup
XBOW's Information Security Analyst, GRC supports customer security reviews, third-party risk and the company's wider trust function. The role works across technical and business teams.
The requirements include seven or more years in risk, compliance, security assurance or related work, plus experience in a hands-on technical role. This is a clear case where “analyst” describes the job without signaling entry level.
Its role-specific location is remote UK/EU. Broader language about working from anywhere elsewhere in the posting shouldn't be read as worldwide hiring permission.
For an experienced applicant, we'd prepare a customer-assurance example that shows technical judgment: how you checked a proposed answer, identified a limitation and communicated it accurately. Avoid presenting speed of questionnaire completion as the only measure of good work.
Choose the kind of GRC work you want
The same job title can put you in a different relationship with the people requesting your work. Read who you support and what you would own before choosing an employer.
Work on an internal security program can sit alongside customer-facing responsibilities. XBOW's description, for example, includes maintaining risk documentation and supporting remediation. Ask which decisions you would own and which stay with IT, legal or other business teams. You want to understand how a finding turns into a change.
A client-service team handles work for other organizations. Coretelligent illustrates that model. Ask how many clients you would support, who reviews deliverables and how deadlines are prioritized. Experience managing requests across different environments may matter more here than deep familiarity with one employer's internal system.
Customer assurance involves explaining security to prospective and existing customers. It appears in Hoxhunt and XBOW's roles, although their experience expectations differ sharply. Ask how the team verifies answers and handles a request the product can't satisfy. Writing clearly is useful; knowing when to seek a technical review matters too.
Public-sector assurance can require specific framework and operational experience. Socure's description gives a concrete example. Read those requirements individually instead of treating every compliance role as interchangeable.
These categories overlap. A single position may include audit preparation, customer questionnaires and vendor reviews. Ask what occupies most of a normal week and what the team expects you to do independently during your first few months.
Search beyond the GRC analyst title
Try “security compliance analyst,” “information security risk analyst,” “third-party security risk,” “security assurance” and “customer trust,” alongside “GRC analyst.” Add “junior,” “associate” or “graduate” when those levels match your experience, then read the responsibilities rather than relying on the label.
Check that the work is about cybersecurity. A compliance search can return credit risk, HR compliance, contract administration and financial reporting. Those may be worthwhile careers, but a matching word doesn't make them the security role you're seeking.
Look for concrete duties involving security controls, technology risk, audit evidence or assurance about systems and data. Our GRC analyst career guide explains the work and preparation in more detail. Use the GRC jobs collection to find further roles, checking the employer description for each one.
Build a shortlist you can use
Copy these prompts into your notes for each promising role:
- Employer and role: Save the title, application URL and date you checked it.
- Eligibility: Record country, office attendance, work authorization and any stated clearance requirement. Mark unanswered questions explicitly.
- Work: Describe the two duties that seem central to the position.
- Evidence: Name a piece of your own work that demonstrates a relevant requirement.
- Gap: Identify one requirement you cannot currently demonstrate, and whether it is essential or preferred.
- Next action: Apply, ask a specific eligibility question, prepare a work sample or remove the role from your current shortlist.
Consider a fictional candidate, Maya, who has three years in cybersecurity-focused IT support at a managed service provider. She has gathered client audit evidence and coordinated access reviews but hasn't run a federal continuous-monitoring program. Coretelligent's description gives her relevant experience to discuss, provided she meets the role's location and other requirements. Socure's specialist requirements identify a different gap. Applying to both with the same generic “passionate about compliance” paragraph would hide that distinction.
Maya could write a short, anonymized account of an access review: the question she needed answered, the evidence she gathered, the issue she escalated and the limits of her responsibility. She should only describe work she performed and must leave out confidential material. Our annotated GRC resume example shows how to present relevant experience without inventing a security job history.
Questions about applying for GRC jobs
Can beginners apply to these employers?
Hoxhunt's checked opening is explicitly junior. The other three postings request prior experience, with different requirements. An employer may advertise other levels later, so keep the company and the individual vacancy separate in your notes.
A beginner can also look for internships, graduate programs and junior security assurance roles. Check whether the employer provides supervision and what work you must already be able to do. A title alone won't answer either question.
Are remote GRC jobs available worldwide?
The remote examples here have geographic limits. Coretelligent lists the United States; XBOW specifies UK/EU. Don't infer worldwide eligibility from remote-working language, a company having international customers or an application form accepting a foreign phone number.
Should I get a certification before applying?
Read the specific vacancy first. A preferred certification is different from an essential requirement, and neither replaces experience an employer explicitly requests. If you meet the core requirements, don't automatically postpone an application to collect another credential. For credentials you do pursue, check the awarding body's current exam and experience rules.
What if a posting disappears?
Return to the employer's careers page and look for the same title or requisition. If you can't find it, remove it from your active application list until you can confirm availability. Keep the employer as a place to revisit if its work fits your interests.
Choose two plausible roles, complete the shortlist prompts and identify the evidence you'd use for each application. That gives you a focused next step from the opportunities available today.


