Five new openings are worth reviewing today. Curana Health and Squarespace are the strongest traditional GRC roles. SNHU is strong for controls assurance. Treasure AI is a technical GRC stretch role. Robert Half has a solid contract option for candidates around the 3-year mark. 1) GRC Security Analyst | Curana Health - Location: Remote, US - Salary: Starting at $130,000 - Experience: 2-5 years in GRC, information security, risk, audit, compliance, cybersecurity, or a related function - Education: Related bachelor's degree or equivalent experience - Skills: HIPAA, SOC 2, NIST CSF, CIS Controls, HITRUST, and ISO 27001 - Skills: Risk assessments, control validation, audit evidence, and remediation tracking - Skills: Third-party risk and vendor security reviews - Skills: Risk registers, compliance metrics, and governance documentation - Skills: ServiceNow GRC, Archer, OneTrust, AuditBoard, or LogicGate preferred This is a strong early-career health-tech GRC role because candidates at the 2-3 year level can build experience across audits, risk, controls, TPRM, policies, and compliance operations. Apply: https://general-careers-curanahealth.icims.com/jobs/4229/grc-security-analyst/job 2) GRC Analyst | Squarespace - Location: New York, NY | Hybrid, 3 days per week in office - Salary: $130,000-$170,000 - Experience: 3+ years in GRC, IT audit, security compliance, or privacy compliance - Skills: SOX, SOC 1/2, PCI DSS, NIST, and ISO - Skills: Control testing, audit scoping, findings, and issue management - Skills: Third-party security and privacy assessments - Skills: Security questionnaires and customer assurance - Skills: GRC automation, continuous monitoring, and AI-enabled workflows This is one of the strongest roles today for someone around the 3-year mark because the work covers the full audit lifecycle plus TPRM, customer assurance, privacy, and compliance automation inside a technology company.