Governance, Risk & Compliance (GRC) Analyst

CHAOS Industries

Los Angeles (CA)

On-site

USD 120,000 - 150,000

Full time

12 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health benefits
401k match
FSA/HSA
Life insurance
Free daily lunch
No meeting Fridays
Unlimited PTO
Casual dress code

Job summary

CHAOS Industries, headquartered in Los Angeles, seeks a Governance, Risk & Compliance Analyst to own and mature the GRC program across multiple business units. You will translate broad requirements into actionable controls and manage risk processes, audits, and policy development.

Ideal candidates have 5+ years in GRC/compliance, DoD experience, and strong knowledge of NIST, ISO/IEC 27000, and related frameworks. Onsite presence is required four days weekly with up to 25% travel.

Qualifications

  • Bachelor's degree or equivalent in computer science, cybersecurity, information security, IT, information assurance, or related field.
  • Deep knowledge of NIST CSF, NIST RMF, ISO/IEC 27000 series, UK Cyber Essentials, CMMC/NIST 800-171, NIST 800-53.
  • Experience selecting, implementing, or administering GRC tooling and workflows.

Responsibilities

  • Own risk assessments across multiple departments and maintain the centralized risk register.
  • Design and maintain a unified control framework tailored to CHAOS Industries’ environment with MTDRPO/MTD, RPO, and RTO definitions.
  • Write and maintain policy beyond minimum compliance to mature security posture.
  • Manage GRC tooling and workflows for risk assessments, control monitoring, and reporting.
  • Coordinate audits, gather evidence, perform gap assessments, and liaise with auditors.
  • Translate cross‑functional requirements into security and compliance controls and drive execution.
  • Report risk posture and program maturity to the Program Director and executives.
  • Onsite presence required 4 days per week; travel up to 25%.

Skills

GRC
Risk Assessments
Policy Development
Audit Coordination
NIST CSF/RMF
ISO/IEC 27000
DoD experience
GRC tooling
Vendor security

Education

Bachelor’s degree in CS/IS

Tools

GRC tooling

Job description

Governance, Risk & Compliance (GRC) Analyst

CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage—domain dominance. The company's products are powered by Coherent Distributed Networks (CDN™), empowering warfighters, commercial air operators, and border protection teams to act faster, adapt rapidly, and stay ahead of evolving threats.

CHAOS Industries was founded in 2022 and has raised a total of $1 billion in funding from leading investors, including 8VC, Accel, and Valor Equity Partners. The company is headquartered in Los Angeles, with offices in Washington, D.C., San Francisco, San Diego, Seattle, and London. For more information, please visit www.chaosinc.com .

Role Overview:

  • Own and mature the CHAOS Industries cybersecurity GRC program by establishing governance structure, policies, standards, expectations, and accountability across CHAOS businesses.
  • You'll report to the IT/Cybersecurity Program Director and work daily with IT, Cybersecurity, Physical Security, and Manufacturing – teams with different priorities and vocabulary; therefore, you’ll spend real time translating broad requirements into controls people adopt.
  • Build and manage cybersecurity risk processes, including risk registers, findings, vulnerabilities, remediation plans, ownership, escalation, and business acceptance.
  • If you enjoy designing frameworks that fit the organization rather than forcing the organization to fit a template, and you want direct input into how a defense company governs risk, this is the seat.

Responsibilities:

  • Own risk assessments across several departments and maintain the centralized risk register.
  • Design and maintain a unified, original control framework tailored to CHAOS Industries' operating environment, including a security-by-design approach to systems development and defined: Maximum Tolerable Downtime (MTD), Recovery Point Objective (RPO), and Recovery Time Objective (RTO) for critical systems.
  • Write and maintain policy that goes beyond minimum mandatory compliance, building genuine security maturity rather than satisfying the floor of any one requirement.
  • Manage GRC tooling and related workflows to support risk assessments, control monitoring, and reporting.
  • Prepare for, coordinate, and help run third-party and certification audits, including evidence collection, gap assessments, and auditor liaison.
  • Act as the connective tissue between different department to then develop security and compliance requirements for partner teams and drive them to execution.
  • Report regularly to the Program Director and executive stakeholders on risk posture, audit status, and program maturity.
  • Onsite presence required 4 days per week.
  • Travel: up to 25%, primarily to support Manufacturing and Physical Security control validation across company sites.
  • Physical demands: occasional access to manufacturing floor environments, including required PPE and periods of standing or walking during facility walkthroughs.
  • Support customer, vendor, supplier, and subcontractor cybersecurity risk management, including questionnaires, contract reviews, security expectations, and customer-facing services.
  • Coordinate cybersecurity audits, assessments, evidence requests, customer reviews, and remediation tracking in partnership with Legal, Compliance, commercial teams, IT, and business leaders.
  • Bachelor’s degree or equivalent experience in computer science, cybersecurity, information security, Information Technology, Information Assurance, or a related field, or equivalent practical experience.
  • Deep knowledge of NIST CSF, NIST RMF, the ISO/IEC 27000 series, UK Cyber Essentials, CMMC/NIST 800-171, NIST 800-53.
  • Experience selecting, implementing, or administering GRC tooling and workflows.
  • Exposure to widely recognized governance, risk, and compliance frameworks spanning security, privacy, and quality management domains.
  • Familiarity with OT/ICS security concepts.
  • Minimum of 5 years hands-on GRC or compliance experience combined with prior experience in a DoD environment or military service.
  • Has directly supported a third-party or certification audit from evidence collection through closure.
  • Can apply recognized governance, risk, and compliance frameworks well enough to design real, working controls tailored to a specific organization, not just describe them generically.
  • Has performed or directly supported a formal risk assessment (identification, scoring, and treatment) using a defined methodology.

Preferred Requirements:

  • Experience supporting third-party audits in a cloud-centric environment.
  • Has built or materially contributed to a risk register, control framework, or compliance program, not only operated within one already established elsewhere.
  • Has written policy or procedure documentation that a non-security audience could follow and act on.

Why CHAOS?

  • Health Benefits: Medical, dental, and vision benefits 100% paid for by the company
  • Additional benefits: 401k (+ 50% company match up to 6% of pay), FSA, HSA, life insurance, and more
  • Our Perks: Free daily lunch, ‘No meeting Fridays’, unlimited PTO, casual dress code
  • Compensation Components: Competitive base salaries, generous pre-IPO stock option grants, relocation assistance, and (coming soon!) annual bonuses
  • Team Growth: 350 employees and counting across 5 global offices

Base Salary Range: $120,000 - 150,000

The stated compensation range reflects only the targeted base compensation range and excludes additional earnings such as bonus, equity, and benefits. If your compensation requirements fall outside of the range, we still encourage you to apply. The salary range for this role is an estimate based on a range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations.

#LI-onsite

Are you authorized to work for any employer in the United States? * Select...

Are you a U.S. Person (i.e. a U.S. Citizen, a lawful permanent resident of the U.S., or a protected individual as defined by 8 U.S.C. 1324b(a)(3)) who can obtain and maintain a Security Clearance? * Select...

Do you presently hold an active U.S. security clearance, or are you eligible to obtain and maintain a U.S. security clearance? * Select...

Please note this position does not necessarily require eligibility to obtain and maintain a U.S. security clearance.

Are you any of the following “protected individual(s)” as defined in the Immigration and Naturalization Act, 8 U.S.C. 1324b(a)(3)? * Select...

EXPORT CONTROLS - This position may require access to information and technology that is subject to U.S. export controls. Your responses to the questions below will be used solely to determine your eligibility under U.S. law to receive information and materials subject to U.S. export controls.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Chaos, Inc. • El Segundo (CA)

Hybrid
USD 120,000 - 150,000
Health benefits
401k with company match
Free daily lunch
+2
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

CHAOS Industries • El Segundo (CA)

On-site
USD 120,000 - 150,000
Health benefits
401k with company match
Free daily lunch
+4
People Program Manager
People Program Manager

Chaos, Inc. • El Segundo (CA)

On-site
USD 150,000 - 200,000
Health benefits
401k match
Free daily lunch
+2
DevSecOps Engineer
DevSecOps Engineer

CHAOS Industries • El Segundo (CA)

On-site
USD 110,000 - 160,000
Health benefits 100% paid
Free daily lunch
Unlimited PTO
Staff Solutions Architect – Enterprise Systems
Staff Solutions Architect – Enterprise Systems

CHAOS Industries • El Segundo (CA)

On-site
USD 160,000 - 220,000
Health Benefits
401k
FSA/HSA
+4
Hardware Systems Engineer
Hardware Systems Engineer

CHAOS Industries • El Segundo (CA)

On-site
USD 190,000 - 270,000
Health benefits
401k match
Free daily lunch
+2
Senior Cybersecurity Engineer, Product Security
Senior Cybersecurity Engineer, Product Security

CHAOS Industries • Washington

On-site
USD 110,000 - 190,000
Health benefits
401k matching
Relocation assistance
+1
Network Data Loss Prevention (DLP) Administrator
Network Data Loss Prevention (DLP) Administrator

CHAOS Industries • El Segundo (CA)

On-site
USD 120,000 - 180,000
Health benefits fully covered by the company
401k with 50% company match
Free daily lunch
+1
Senior Cybersecurity Engineer, Product Security
Senior Cybersecurity Engineer, Product Security

CHAOS Industries • Los Angeles (CA)

On-site
USD 110,000 - 190,000
Health benefits
401k + company match
Free daily lunch
+2
Senior Cybersecurity Engineer, Product Security
Senior Cybersecurity Engineer, Product Security

CHAOS Industries • El Segundo (CA)

On-site
USD 114,000 - 190,000
Free daily lunch
No meeting Fridays
401k match
+2