# Cybersecurity GRC Analyst Work in 2026: Evidence from 100 Current Vacancies

> A bounded study of 100 current vacancies maps how Cybersecurity GRC Analysts connect governance, risk, controls, evidence, assurance, third-party oversight and remediation.

- Canonical page: https://mtfinstitute.com/insights/cybersecurity-grc-analyst-work-100-vacancies-2026/
- Content type: Article
- Editorial category: Research &amp; Reports
- Publisher: MTF Institute of Management, Technology and Finance
- Author: MTF Institute Research Team- Published: 2026-08-22
- Updated: 2026-08-22
- Language: English
- Topics: Third-party risk, Labour Market Research, Cybersecurity GRC, Control Evidence, Governance Risk and Compliance

## Cybersecurity GRC Analyst Work in 2026: Evidence from 100 Current Vacancies

Author: MTF Institute Research Team  
Publication date: 22 August 2026  
Evidence cut-off: 22 August 2026  
Corpus: 100 current public first-party applicant-tracking-system vacancy records

The complete research archive — searchable PDF, evidence workbook and accepted-vacancy dataset — is openly available at [Zenodo DOI 10.5281/zenodo.22057757](https://doi.org/10.5281/zenodo.22057757).

## Executive abstract

This report examines what employers asked cybersecurity governance, risk and compliance professionals to do in 100 vacancies that were publicly accessible on 22 August 2026. The corpus was built from official Ashby, Greenhouse and Lever posting interfaces. It contains 100 distinct requisitions from 78 employers after live-status checks, scope screening, deduplication and an employer concentration cap of three records. The research is a point-in-time, purposive study of accessible English-language vacancy evidence. It is not a statistically representative census of employers, countries or cybersecurity jobs.

The strongest observed signal is breadth across a connected operating chain. Compliance operations appeared in 98 roles, governance and policy work in 94, control work in 91, and audit or assurance support in 84. Cyber risk work appeared in 74 roles, reporting in 70, third-party risk in 67, remediation or exception work in 66, and workflow tooling or automation in 66. Because each vacancy could receive several codes, these percentages overlap. They describe co-occurring responsibilities, not separate job populations. The average vacancy received 7.1 of the nine codes, and 70 roles received seven or more. This coding result suggests that employers frequently describe cybersecurity GRC as an evidence-to-decision workflow rather than as a narrow document-maintenance task.

The corpus also shows that the work is not confined to titles containing “GRC.” Forty-six titles contained that abbreviation, while other titles used combinations of security, cyber, compliance, risk, governance, assurance, programme or information-assurance language. Seniority was skewed away from entry-level roles: only three records were coded junior or associate, compared with 21 senior, 20 manager, 11 lead/principal/staff and nine director/executive records. Thirty-six were analyst, specialist or otherwise unspecified by seniority. This does not establish the overall labour-market mix; it shows the composition of this bounded sample.

The practical implication is a role profile centred on traceability: establish business and technology context; translate confirmed requirements into original internal control statements; coordinate accountable owners; request and assess time-bounded evidence; track exceptions and remediation; maintain third-party cyber-risk records; and prepare decision-focused reporting. The analyst supports decisions but does not replace security engineering, legal counsel, management risk owners or independent internal audit. Education for this role should therefore develop operating artefacts and professional judgement while preserving those authority boundaries.

## 1. Research purpose and questions

The study was designed to answer four bounded questions:

1. Which cybersecurity GRC operating responsibilities appeared most often in the accepted vacancy corpus?
2. How did those responsibilities combine within roles, and what does that combination imply for the work system?
3. What title, seniority, geography and source characteristics constrain interpretation of the findings?
4. What original professional-learning outcomes can be derived without reproducing protected framework expression, offering legal advice or claiming that a course leads to employment?

The unit of analysis is one current vacancy record, not one hire, one open headcount, one organization-wide capability or one worker. A record shows how an employer described a requisition at a specific time. It does not show whether the vacancy was filled, how the selected employee performed, how much work was actually allocated to each duty or whether a named practice was effective.

## 2. Methodology

### 2.1 Discovery and live validation

The discovery process began with 1,204 title candidates obtained from a third-party daily index. That index was used only to identify possible requisitions; no indexed copy became final evidence. Screening reduced the pool to 303 candidates that could be associated with direct applicant-tracking-system records. The research process read 150 official employer boards and validated each retained requisition through a public, unauthenticated Ashby, Greenhouse or Lever interface.

After the initial ATS-availability and content/evidence screens, 132 preliminary records remained. A final manual role-boundary review removed 10 of those records before concentration controls. The final capped corpus contains 100 records from 78 employers. Every retained row has an HTTPS first-party ATS URL, employer, exact title, location label, provider requisition identifier, retrieval date, current-status evidence, source family, seniority classification, one short evidence excerpt, coded duties, a deduplication key and a limitations note. No credentials were used, and no access control, CAPTCHA or rate limit was bypassed.

### 2.2 Inclusion boundary

A vacancy was eligible when its exact requisition remained present in the official ATS response on 22 August 2026 and its title and described duties materially concerned cybersecurity governance, cyber or information-security risk, compliance operations, internal security controls, assurance evidence or third-party cyber risk. The record also had to contain enough public information to support at least two of the nine operating-duty codes used in the study.

The study excluded credit, anti-money-laundering, financial-crime, payment-only, generic operational-risk and non-cyber compliance roles. It also excluded GRC software sales, customer-success, product and technical-platform roles without practitioner operations scope; internships and student roles; unrelated data-governance roles; duplicate URLs or requisitions; and records above the three-vacancy employer cap. Ninety-four candidates were excluded because a requisition was absent from the current official response or the board could not be read. Seventy-seven failed the content or evidence boundary, and ten further records were removed in the final manual role-boundary review.

### 2.3 Deduplication and concentration control

The deduplication key combined normalized employer, exact title, location and ATS requisition identifier. Tracking query strings were removed from stored URLs. Duplicate canonical URLs and duplicate keys were rejected. Location-specific requisitions were retained only when the provider identifiers differed. The employer concentration cap was three records; no employer exceeded it in the final corpus. The resulting file has 100 unique source identifiers, 100 unique canonical URLs and 100 unique deduplication keys.

### 2.4 Coding method

Each role was coded for the presence of explicit duties in nine original study categories:

- **GRC-GOV — governance and policy operations:** governance forums, roles, policies, internal standards, decision rights or management-system coordination;
- **GRC-RISK — cyber-risk operations:** cyber or information-security risk assessment, risk registers, treatment, monitoring or posture;
- **GRC-COMP — compliance operations:** identifying, coordinating or tracking requirements and responses without making a legal determination;
- **GRC-CTRL — internal control operations:** original internal control design, implementation coordination, review or monitoring;
- **GRC-AUDIT — audit and assurance support:** evidence collection, assessor coordination, readiness support or response management, excluding ownership of an independent assurance opinion;
- **GRC-TPRM — third-party cyber-risk operations:** supplier or vendor cyber-risk evidence, due diligence, monitoring or issue escalation;
- **GRC-REMED — remediation and exception operations:** findings, corrective actions, exceptions, compensating measures or closure tracking;
- **GRC-REPORT — reporting operations:** metrics, dashboards, key indicators or leadership reporting; and
- **GRC-AUTO — workflow tooling and automation:** GRC platforms, evidence automation, policy/control workflow tooling or similar operational enablement.

Codes were non-exclusive: a vacancy could receive all applicable categories. Each record required at least two codes. The result is a descriptive coding of vacancy text, not a validated competency model, workload measurement or claim that every employee performs every coded duty.

### 2.5 Rights-preserving evidence storage

The stored corpus retains derived facts, public ATS URLs, classifications and one contiguous evidence excerpt of 8–20 words per vacancy. It does not retain bulk copies of job descriptions. External professional and public-authority sources are used only for attributed context and boundaries. This report does not reproduce protected standards, certification outlines, control catalogues, mappings, graphics or bodies of knowledge.

## 3. Corpus profile

### 3.1 Source platforms

| Official ATS platform | Vacancies | Share of corpus |
|---|---:|---:|
| Greenhouse | 51 | 51% |
| Ashby | 35 | 35% |
| Lever | 14 | 14% |
| **Total** | **100** | **100%** |

Platform distribution reflects where eligible public records could be discovered and validated. It does not estimate the global market share of ATS providers. Employers using private recruiting systems, other platforms, local-language sites or non-public hiring channels are outside the sample.

### 3.2 Region labels

| Coded region | Vacancies | Share of corpus |
|---|---:|---:|
| North America | 51 | 51% |
| Europe | 12 | 12% |
| Asia-Pacific | 6 | 6% |
| Global remote | 5 | 5% |
| Latin America | 1 | 1% |
| Unspecified or ambiguous | 25 | 25% |
| **Total** | **100** | **100%** |

The region field is a classification of the vacancy’s published location label, not the employer’s headquarters, worker citizenship, permitted hiring territory or final work location. Twenty-five labels were too ambiguous for reliable regional assignment. The large North American share and the small Latin American count make geographic comparison particularly unsafe. The corpus should not be used to rank regional demand.

### 3.3 Seniority

| Seniority category | Vacancies | Share of corpus |
|---|---:|---:|
| Analyst, specialist or unspecified | 36 | 36% |
| Senior | 21 | 21% |
| Manager | 20 | 20% |
| Lead, principal or staff | 11 | 11% |
| Director or executive | 9 | 9% |
| Junior or associate | 3 | 3% |
| **Total** | **100** | **100%** |

Forty records were manager, lead/principal/staff or director/executive roles. A further 21 were senior. This composition signals that many accessible postings expected prior judgement, coordination or ownership experience. It does not prove that entry routes are absent: junior work may be advertised under different titles, filled internally, included within broader IT or compliance roles, or hosted outside the sampled ATS platforms.

### 3.4 Title variation

Forty-six titles included “GRC.” Forty-two included “compliance,” 40 included “risk,” 25 included “governance,” 41 included “security” or “cyber,” and 13 included “audit” or “assurance.” These keyword groups overlap and are not a taxonomy. Their main value is negative: title-only searches would omit many roles whose duties fit the operating scope. Conversely, a title containing “risk” or “compliance” is insufficient for inclusion unless the description supports cyber-specific operating work.

Examples in the corpus include Associate GRC Analyst, Senior GRC Specialist, Security Compliance Manager, Information Assurance Compliance Specialist, Senior GRC Engineer, Technical Program Manager for Security and GRC, and Director of Governance, Risk and Compliance. The variation supports using duties, decisions and artefacts to define the professional profile instead of treating one title string as authoritative.

## 4. Findings: evidence-coded operating responsibilities

### 4.1 Frequency of the nine operating categories

| Duty category | Roles coded | Share of 100 roles |
|---|---:|---:|
| Compliance operations | 98 | 98% |
| Governance and policy operations | 94 | 94% |
| Internal control operations | 91 | 91% |
| Audit and assurance support | 84 | 84% |
| Cyber-risk operations | 74 | 74% |
| Reporting operations | 70 | 70% |
| Third-party cyber-risk operations | 67 | 67% |
| Remediation and exception operations | 66 | 66% |
| Workflow tooling and automation | 66 | 66% |

The denominator is exactly 100, so each count is also the percentage of roles coded. Percentages must not be added: codes overlap. There were 710 code assignments across the corpus, an average of 7.1 per role. One role had two codes, two had three, five had four, nine had five, 13 had six, 27 had seven, 17 had eight and 26 had all nine. Seventy roles therefore received seven or more categories.

This breadth should be interpreted cautiously. Vacancy descriptions often aggregate responsibilities across a team, describe an aspirational scope or combine immediate work with future ownership. Coding detects the presence of a duty, not its proportion of working time or level of authority. Nevertheless, the repeated co-occurrence is strong evidence that the sampled roles were described as connected operating positions rather than isolated policy-writing jobs.

### 4.2 Governance, compliance and controls form the common core

Governance and compliance were coded together in 92 roles. Compliance and controls appeared together in 89, while controls and governance appeared together in 85. These were the three most common code pairs. The observation supports an original operating interpretation: requirements become manageable only when they are connected to accountable roles, internal control intent, current evidence and a decision process.

This is not a statement that a particular external framework was adopted. The coding does not identify whether employers used one standard, several sources or an entirely internal method. It also does not establish whether a listed requirement applied as law. A practitioner can maintain provenance, version, applicability owner and status for a candidate requirement; the legal or compliance authority remains responsible for applicability and interpretation.

### 4.3 Assurance support is operationally close to controls, but authority remains separate

Audit or assurance support appeared in 84 roles. It co-occurred with compliance in 83, governance in 80 and controls in 80. The job descriptions therefore frequently connected evidence requests, assessor coordination, response tracking and review preparation with ordinary GRC operations.

That proximity must not erase professional boundaries. A management-side analyst may assemble evidence, assess whether a file is attributable and current, record a gap, coordinate a response and follow remediation. Independent internal audit determines its own scope, methods, conclusions and reporting under the organization’s assurance arrangements. The Institute of Internal Auditors’ public position materials likewise distinguish management and risk/compliance responsibilities from independent assurance while encouraging coordination. This report treats the distinction as a design constraint, not as a claim about one universal organizational model.

### 4.4 Cyber risk is a scenario-and-decision process, not a label

Cyber-risk work appeared in 74 roles and was paired with compliance in 73, governance in 72 and controls in 68. The recurring combination indicates that risk work in the corpus was embedded within broader governance and evidence activity. An original, bounded workflow for education can therefore begin with a business service, technology dependency and plausible adverse scenario; record impact and uncertainty; connect the scenario to an accountable owner and an original internal control objective; and preserve the treatment or escalation decision.

The analyst does not become the executive risk owner, security architect or technical assessor. The analyst’s observable contribution is a traceable record: what context was used, which evidence was requested, which uncertainty remains, who owns the decision, when it must be reviewed and what event could reopen it.

### 4.5 Reporting is part of the operating loop

Reporting appeared in 70 roles. Its frequent pairing with compliance, governance and risk supports moving beyond a catalogue of activities. A useful decision view can distinguish material exposure, evidence confidence, overdue remediation, active exceptions, third-party dependencies, recent changes and requested management action. Thresholds and colour conventions must remain organization-specific; the study does not identify one universal dashboard.

Reporting also tests data quality. A count is not useful merely because it can be produced. A metric needs a definition, denominator, owner, source system, refresh rule, interpretation boundary and action link. The vacancy evidence does not prove which metrics are effective, so education should ask learners to state what a measure cannot show as well as what it can show.

### 4.6 Third-party cyber risk is not a one-time questionnaire

Third-party cyber-risk operations appeared in 67 roles. Public guidance from NIST, ENISA and the UK NCSC describes supply-chain risk as an organizational and lifecycle concern, while sector-specific EU law illustrates that responsibility and oversight can remain with the regulated organization. The 2026 Verizon Data Breach Investigations Report separately reported third-party involvement in 48% of the breaches in its contributor-based corpus. That figure is context, not a universal breach rate and not a causal result from this vacancy sample.

The educational implication is a lifecycle record rather than a generic questionnaire: establish criticality; request bounded cyber evidence; record ownership and unresolved questions; connect requirements through authorized commercial and legal channels; monitor material changes; escalate incidents or deficiencies; and retain closure or exit evidence. Cyber GRC does not own supplier selection, contract drafting, procurement negotiation or every dimension of supplier risk.

### 4.7 Remediation and exceptions are governed decisions

Remediation or exception operations appeared in 66 roles. The result supports teaching an exception as a time-bounded decision record rather than an informal waiver. An original record can contain the internal requirement or objective, affected scope, risk rationale, accountable approver, duration, compensating measures, remediation owner, due date, review trigger and closure evidence. The authorization threshold remains contextual and outside the analyst’s unilateral authority.

The same discipline applies to findings. A finding label without cause, affected scope, owner, target date, status evidence and closure criteria is difficult to manage. The analyst can maintain the workflow and challenge missing fields; technical owners validate implementation, authorized managers decide treatment, and independent assurance retains its own conclusion.

### 4.8 Tooling and automation are common, but consequential decisions need named review

Workflow tooling or automation appeared in 66 roles. The code covered GRC platforms, evidence automation, policy or control workflow tooling and related operational enablement. The vacancy records do not show that a particular product was required across the market, nor do they prove that automation improved outcomes.

Bounded AI assistance can be useful for classifying rights-cleared evidence, detecting duplicate requests, normalizing fields, extracting candidate obligations from authorized text, preparing a first-pass summary and prioritizing a review queue. It should preserve source provenance and uncertainty. A named human remains responsible for evidence sufficiency, legal interpretation, risk acceptance, regulatory communication, assurance conclusions and other consequential decisions. Real credentials, confidential architecture, personal data, privileged advice, restricted contracts and vulnerability details should not be placed into an unapproved AI tool.

## 5. What the evidence does and does not say about the role

### 5.1 Observed role proposition

Across the 100 records, the most defensible professional proposition is a business-facing operator who keeps cyber requirements, risk scenarios, internal control intent, accountable owners, evidence, exceptions, remediation, third parties and management reporting connected. The person must communicate across specialist boundaries and maintain records that another authorized reviewer can follow.

This proposition is an MTF synthesis of the coded corpus. It is not a named external role definition. ENISA’s public European Cybersecurity Skills Framework provides useful context by distinguishing cyber risk management from legal, policy and compliance responsibilities and by emphasizing role interdependencies. The current corpus shows that employers may combine parts of those territories in one vacancy, but that does not remove the need to state authority limits in actual organizations.

### 5.2 The title is broader than “analyst,” but the learning outcome can remain bounded

The sample includes substantial senior, manager and leadership representation. It would be misleading to imply that one course turns a learner into a director or supplies the experience expected in every posting. A bounded professional course can instead develop demonstrable operating artefacts: a mandate and decision-right map, cyber-risk criteria, a scenario register, an obligation handoff register, original internal control records, an evidence plan, an exception workflow, a remediation tracker, a third-party monitoring plan, a metrics specification and an executive brief.

Those artefacts can make reasoning visible in a fictional or sanitized case. They cannot establish job readiness for a particular employer, replace supervised experience or guarantee selection. The corpus contains only three junior or associate records, so any early-career positioning should be explicit about the experience gap rather than hiding it.

### 5.3 Communication and judgement remain central

Professional workforce studies provide a second, separate evidence family. ISC2 reported that its 2025 study included 16,029 practitioners and decision-makers and identified GRC, risk assessment, communication, problem-solving and collaboration among current skills signals. ISACA’s 2025 survey of more than 3,800 cybersecurity professionals also reported critical-thinking, communication and problem-solving gaps. These are self-reported professional studies, not employer census data, and they should not be combined numerically with the vacancy corpus.

Together with the observed breadth of vacancy duties, they support practice that asks learners to explain assumptions, ask for missing evidence, distinguish ownership from review, convert technical activity into a decision record and communicate uncertainty. Memorizing labels is insufficient when the work involves handoffs among business owners, security teams, legal or compliance specialists, suppliers, management and assurance functions.

## 6. Implications

### 6.1 For employers

First, employers should state the authority boundary of a GRC vacancy. A description that combines requirement tracking, technical control review, independent assurance, legal interpretation and risk acceptance without naming decision owners can create unrealistic expectations and conflicts of responsibility.

Second, hiring and operating models should distinguish essential workflow capability from a long list of product or credential keywords. The sample’s title variety and multi-code breadth indicate that the same work can be described in several ways. A practical selection exercise can ask a candidate to structure a fictional evidence gap, identify the decision owner, propose a bounded escalation and communicate limitations without requesting confidential data.

Third, employers should make evidence operations measurable. Useful process measures can include request age, evidence freshness, unresolved scope questions, overdue remediation, exception expiry, repeat finding patterns and third-party review triggers. Each measure needs a definition and action owner; no metric in this report is presented as universally suitable.

Fourth, organizations should preserve independence and specialist handoffs. GRC can coordinate management evidence and remediation while legal counsel determines legal meaning, security engineers validate technical implementation, authorized managers accept risk and internal audit forms independent conclusions.

### 6.2 For professionals

Professionals can develop a portable way of thinking without copying one organization’s system. Start with a clear business service and decision. Write a cyber-risk scenario in plain language. Identify what authority is needed and who holds it. Create original internal control intent from the organization’s confirmed requirement. Ask for evidence that is attributable, scoped, current and reviewable. Record uncertainty rather than filling gaps with assumptions. Track the next action, owner and review trigger.

The data also argues for breadth with limits. A professional should understand governance, risk, controls, evidence, exceptions, suppliers, remediation, reporting and tooling well enough to connect them. That does not require pretending to be a lawyer, independent auditor, penetration tester, incident commander or executive risk owner.

For early-career professionals, the seniority distribution is a warning against inflated positioning. A portfolio should show disciplined reasoning and traceable artefacts, not claim that a simulated case proves experience. Supervised practice, organizational context and specialist review remain necessary.

### 6.3 For education providers

Education should be organized around decisions and outputs rather than a protected control catalogue. A coherent sequence can move from mandate and business context to cyber-risk scenarios, confirmed requirements, original internal controls, evidence, policy and exception workflows, owner accountability, remediation, third-party monitoring, metrics, change intake, post-incident follow-up and executive reporting.

Assessment should check traceability and boundaries. Can another reviewer identify the source and date of a requirement? Is the applicability owner named? Does the evidence match the system and time period? Are missing facts visible? Is the exception time-bounded? Is the decision authority correct? Does the report distinguish observation from judgement? These questions measure the learner’s process without claiming external recognition.

AI practice should use fictional or sanitized inputs and require human review. It can help a learner compare fields, detect omissions and draft a concise summary. It should not ingest restricted standards, infer missing law, approve evidence, accept risk or generate an assurance conclusion.

## 7. Fictional synthesis: Northstar Digital

**The following case is entirely fictional and illustrates the report’s synthesis. It is not an observed employer, legal assessment or recommended control set.**

Northstar Digital provides a subscription workflow service to business customers in several countries. Its product team plans to move a document-processing component to a new cloud supplier. The change affects customer documents, identity access, service availability and incident communications. The organization has internal security requirements and customer commitments, but the case does not assert that any named law applies.

Maya Chen, a fictional Cybersecurity GRC Analyst, receives a request to “approve the supplier.” She first corrects the authority boundary: procurement owns supplier selection and commercial coordination; legal counsel interprets contract and legal requirements; security engineering validates technical design; the business service owner decides whether the residual risk is acceptable under Northstar’s authority model. Maya owns the traceable GRC workflow.

She creates a business-service and dependency context record, then writes two testable cyber-risk scenarios in original language. She links each scenario to an accountable owner and a confirmed internal requirement. For every requested item of evidence, she records source, system scope, period covered, owner, retrieval date, reviewer, known limitation and next review trigger. A policy document alone does not show current operation, so she asks the technical owner for time-bounded operational evidence appropriate to the internal objective.

One evidence item is incomplete. Maya does not mark the requirement satisfied and does not invent the missing detail. She opens a deficiency record with the affected scope, uncertainty, owner, target date and closure criteria. Because the supplier transition cannot meet the original date, the business owner requests a temporary exception. The record names the authorized approver, duration, compensating measures, remediation owner, due date and an event that will trigger early review.

Maya then prepares a concise management view. It separates observed facts from judgement, shows the unresolved exposure, identifies the decision required and lists the specialist reviews still outstanding. An AI assistant may help normalize the fictional evidence inventory and highlight missing fields, but Maya checks every source and no automated output determines sufficiency, legal meaning or risk acceptance.

The case demonstrates the operating chain found across the corpus: context, risk, confirmed requirement, original internal control intent, owner, evidence, gap, exception or remediation, decision and monitoring. It also preserves the boundaries that make the chain trustworthy.

## 8. Rights, legal and professional boundaries

This report is educational research and not legal, regulatory, security-engineering, audit or certification advice. References to NIS2 and DORA describe dated EU-level context only. NIS2 is a directive implemented through national law; entity classification, sector, size, service, national transposition, competent-authority guidance and exceptions affect actual obligations. DORA applies to defined financial-sector entities and relevant ICT third-party arrangements subject to its scope and later technical rules. No entity-level conclusion is made here.

NIST publications cited in the references are voluntary, versioned public guidance, not law or proof that an organization has met an obligation. ENISA and UK NCSC materials have stated audiences and limits. Their structures, indicators, mappings and examples are not reproduced as an MTF model.

No ISO publication text, COBIT material, ISC2 certification outline, CIS control content or protected crosswalk is used to construct this report. References to professional bodies identify public role or workforce context only. The report claims no endorsement, equivalence, conformity, credential preparation or external recognition.

For real work, qualified and authorized specialists must review legal applicability, regulatory notification, contractual interpretation, privilege, technical implementation, risk acceptance, independent assurance and certification matters. A GRC record can support those decisions; it cannot replace them.

## 9. Limitations

1. **Point-in-time status.** The 100 requisitions were present in official public ATS responses on 22 August 2026. Employers may change or close them later.
2. **Purposive rather than probabilistic sampling.** Discovery, public accessibility, English-language visibility, role filters and ATS coverage shaped the corpus. No sampling probability is available.
3. **Platform concentration.** Only Ashby, Greenhouse and Lever are represented, with Greenhouse accounting for 51 records. Other recruiting systems and private channels are absent.
4. **Geographic imbalance.** North America accounts for 51 records, Europe 12, Asia-Pacific six, Latin America one and global remote five; 25 location labels are ambiguous. Regional comparisons are not supported.
5. **Employer cap.** Limiting employers to three records reduces concentration but may understate employers with many relevant requisitions.
6. **Text is not work observation.** Vacancy descriptions can be aspirational, templated or team-wide. Coding does not show actual task frequency, authority, quality or effectiveness.
7. **Broad, overlapping codes.** The nine categories were deliberately operational and non-exclusive. A code records textual evidence of a duty, not mastery or workload. Co-occurrence may partly reflect long descriptions.
8. **Title and seniority judgement.** Normalized seniority and region classifications involve interpretation. Thirty-six roles had analyst, specialist or unspecified seniority, and 25 locations remained unspecified.
9. **No salary or outcome analysis.** The study did not compare compensation, time to hire, application volume, selection, retention, performance, course demand or course sales.
10. **No effectiveness inference.** A duty’s presence does not prove that a practice reduces incidents, improves assurance or causes better organizational results.
11. **External studies use different populations.** Workforce surveys, incident corpora and executive studies cited for context are not combined with the vacancy denominator and are subject to self-selection or contributor effects.
12. **Legal and rights scope remains bounded.** National NIS2 transposition, DORA secondary rules and organization-specific applicability are outside the study. Proprietary standards and certification materials remain excluded.

## 10. Conclusion

The 100-vacancy corpus supports a clear but bounded conclusion: cybersecurity GRC work was commonly described as an interconnected operating discipline. Governance, compliance and controls formed the broadest common core, while assurance support, risk, reporting, third-party work, remediation and tooling appeared across substantial majorities of the sample. The combination points to a professional who maintains the chain from business context and confirmed requirements to owned controls, current evidence, exceptions, remediation and decision-focused reporting.

The evidence does not support a universal job description, regional demand ranking or promise of employment. It does support a practical learning design centred on original artefacts, traceability, communication, uncertainty and authority boundaries. The strongest professional outcome is not memorization of a control catalogue. It is the ability to keep an evidence-to-decision system reviewable while technology, suppliers, obligations and organizational conditions change.

## References

### Public-authority, legal and professional context

1. US National Institute of Standards and Technology. “The NIST Cybersecurity Framework (CSF) 2.0,” 26 February 2024. https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20
2. US National Institute of Standards and Technology. “NIST SP 1305: CSF 2.0 Quick-Start Guide for Cybersecurity Supply Chain Risk Management,” 21 October 2024. https://csrc.nist.gov/pubs/sp/1305/final
3. European Union Agency for Cybersecurity. “NIS2 Technical Implementation Guidance,” version 1.0, 26 June 2025. https://www.enisa.europa.eu/publications/nis2-technical-implementation-guidance
4. European Union. “Directive (EU) 2022/2555 (NIS2),” Official Journal, 27 December 2022. https://eur-lex.europa.eu/eli/dir/2022/2555/oj?locale=en
5. European Union. “Regulation (EU) 2022/2554 on digital operational resilience for the financial sector,” Official Journal, 27 December 2022. https://eur-lex.europa.eu/eli/reg/2022/2554/oj?uri=CELEX%3A32022R2554
6. UK National Cyber Security Centre. “Cyber Assessment Framework,” version 4.0. https://www.ncsc.gov.uk/collection/cyber-assessment-framework
7. European Union Agency for Cybersecurity. “European Cybersecurity Skills Framework Role Profiles,” 19 September 2022. https://www.enisa.europa.eu/publications/european-cybersecurity-skills-framework-role-profiles
8. The Institute of Internal Auditors. “Statements of Position,” including the Three Lines position material. https://www.theiia.org/en/resources/statements-of-position
9. ISC2. “Aligning Skills, People and Hiring in Cybersecurity,” 17 April 2026, drawing on the 2025 Cybersecurity Workforce Study. https://www.isc2.org/insights/2026/04/aligning-skills-people-and-hiring-in-cybersecurity
10. ISACA. “State of Cybersecurity 2025: Global Update on Workforce, Resources and Operations,” 29 September 2025. https://www.isaca.org/about-us/newsroom/press-releases/2025/state-of-cybersecurity-2025-global-press-release
11. Verizon Business. “2026 Data Breach Investigations Report,” 19 May 2026. https://www.verizon.com/business/resources/reports/dbir/
12. World Economic Forum in collaboration with Accenture. “Global Cybersecurity Outlook 2026,” 12 January 2026. https://www.weforum.org/publications/global-cybersecurity-outlook-2026/

### Illustrative vacancy records from the preserved 100-role corpus

The following public links illustrate title, seniority, geography and ATS variation. They are not a statistically selected subsample, and their continued availability may change. The complete 100-record URL inventory is preserved in the research corpus.

13. Kayak. “Associate GRC Analyst.” Ashby requisition `8ee1a151-4fbf-4ad1-a6ba-6ee5546c0aed`, accessed 22 August 2026. https://jobs.ashbyhq.com/kayak/8ee1a151-4fbf-4ad1-a6ba-6ee5546c0aed
14. Alan. “Security Engineer - GRC.” Ashby requisition `f2c66b32-b173-4f0f-b3e6-8e25026cc4e5`, accessed 22 August 2026. https://jobs.ashbyhq.com/alan/f2c66b32-b173-4f0f-b3e6-8e25026cc4e5
15. Aisle. “Senior Security Compliance (GRC) Manager.” Ashby requisition `97a09433-9034-4266-acd3-1361219b4bce`, accessed 22 August 2026. https://jobs.ashbyhq.com/aisle/97a09433-9034-4266-acd3-1361219b4bce
16. Astera Labs. “Governance, Risk Management and Compliance, Senior Director.” Greenhouse requisition `4719162005`, accessed 22 August 2026. https://job-boards.greenhouse.io/asteralabs/jobs/4719162005
17. Arlo Solutions LLC. “(627) Information Assurance Compliance Specialist II.” Greenhouse requisition `5012860007`, accessed 22 August 2026. https://job-boards.greenhouse.io/arlosolutionsllc/jobs/5012860007
18. Aircall. “Senior GRC Engineer.” Lever requisition `ea2a9614-6bbe-4e17-b280-3340423d75d1`, accessed 22 August 2026. https://jobs.lever.co/aircall/ea2a9614-6bbe-4e17-b280-3340423d75d1
19. Arsiem. “Junior Information Assurance (IA) Specialist.” Lever requisition `1fff3521-c8ae-4db9-8fce-f685ff990dda`, accessed 22 August 2026. https://jobs.lever.co/arsiem/1fff3521-c8ae-4db9-8fce-f685ff990dda
20. Coupa. “Technical Program Manager, Security &amp; GRC - 11745.” Lever requisition `f5b09f5e-9940-44fd-9628-700e4af0743d`, accessed 22 August 2026. https://jobs.lever.co/coupa/f5b09f5e-9940-44fd-9628-700e4af0743d

## Appendix A. Reproducibility record

- Final corpus file: `accepted-vacancies-2026-08-22.tsv`
- Corpus SHA-256: `1D01E07456440302B88EC6478234524929F851F8F1ADDB6E771DD186F5FB0E94`
- Corpus size: 82,713 bytes
- Rows: 100
- Columns: 16
- First source identifier: `CYGRC-VAC-0001`
- Last source identifier: `CYGRC-VAC-0100`
- Retrieval date: 22 August 2026, Europe/Lisbon
- Accepted employers: 78
- Employer concentration maximum: three records
- Current-status source: public official ATS response
- Provider mutation performed: no


## Citation

When citing or summarizing this material, link to the canonical HTML page: https://mtfinstitute.com/insights/cybersecurity-grc-analyst-work-100-vacancies-2026/
