Enter a job title or keyword

Governance, Risk & Compliance (GRC) Analyst

CHAOS Industries


Job Location:

El Segundo, CA - USA

Monthly Salary: $ 120000 - 150000
Posted: 29 August 2026 (8 days ago)
Application Deadline: 26 November 2026
Vacancies: 1 Vacancy

Job Summary

CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantagedomain dominance. The companys products are powered by Coherent Distributed Networks (CDN) empowering warfighters commercial air operators and border protection teams to act faster adapt rapidly and stay ahead of evolving threats.

CHAOS Industries was founded in 2022 and has raised a total of $1 billion in funding from leading investors including 8VC Accel and Valor Equity Partners. The company is headquartered in Los Angeles with offices in Washington D.C. San Francisco San Diego Seattle and London. For more information please visit .

Role Overview:

  • Own and mature the CHAOS Industries cybersecurity GRC program by establishing governance structure policies standards expectations and accountability across CHAOS businesses.
  • Youll report to the IT/Cybersecurity Program Director and work daily with IT Cybersecurity Physical Security and Manufacturing teams with different priorities and vocabulary; therefore youll spend real time translating broad requirements into controls people adopt.
  • Build and manage cybersecurity risk processes including risk registers findings vulnerabilities remediation plans ownership escalation and business acceptance.
  • If you enjoy designing frameworks that fit the organization rather than forcing the organization to fit a template and you want direct input into how a defense company governs risk this is the seat.

Responsibilities:

  • Own risk assessments across several departments and maintain the centralized risk register.
  • Design and maintain a unified original control framework tailored to CHAOS Industries operating environment including a security-by-design approach to systems development and defined: Maximum Tolerable Downtime (MTD) Recovery Point Objective (RPO) and Recovery Time Objective (RTO) for critical systems.
  • Write and maintain policy that goes beyond minimum mandatory compliance building genuine security maturity rather than satisfying the floor of any one requirement.
  • Manage GRC tooling and related workflows to support risk assessments control monitoring and reporting.
  • Prepare for coordinate and help run third-party and certification audits including evidence collection gap assessments and auditor liaison.
  • Act as the connective tissue between different department to then develop security and compliance requirements for partner teams and drive them to execution.
  • Report regularly to the Program Director and executive stakeholders on risk posture audit status and program maturity.
  • Onsite presence required 4 days per week.
  • Travel: up to 25% primarily to support Manufacturing and Physical Security control validation across company sites.
  • Physical demands: occasional access to manufacturing floor environments including required PPE and periods of standing or walking during facility walkthroughs.
  • Support customer vendor supplier and subcontractor cybersecurity risk management including questionnaires contract reviews security expectations and customer-facing services.
  • Coordinate cybersecurity audits assessments evidence requests customer reviews and remediation tracking in partnership with Legal Compliance commercial teams IT and business leaders.

Minimum Requirements:

  • Bachelors degree or equivalent experience in computer science cybersecurity information security Information Technology Information Assurance or a related field or equivalent practical experience.
  • Deep knowledge of NIST CSF NIST RMF the ISO/IEC 27000 series UK Cyber Essentials CMMC/NIST 800-171 NIST 800-53.
  • Experience selecting implementing or administering GRC tooling and workflows.
  • Exposure to widely recognized governance risk and compliance frameworks spanning security privacy and quality management domains.
  • Familiarity with OT/ICS security concepts.
  • Minimum of 5 years hands-on GRC or compliance experience combined with prior experience in a DoD environment or military service.
  • Has directly supported a third-party or certification audit from evidence collection through closure.
  • Can apply recognized governance risk and compliance frameworks well enough to design real working controls tailored to a specific organization not just describe them generically.
  • Has performed or directly supported a formal risk assessment (identification scoring and treatment) using a defined methodology.

Preferred Requirements:

  • Experience supporting third-party audits in a cloud-centric environment.
  • Has built or materially contributed to a risk register control framework or compliance program not only operated within one already established elsewhere.
  • Has written policy or procedure documentation that a non-security audience could follow and act on.

Why CHAOS

  • Health Benefits: Medical dental and vision benefits 100% paid for by the company
  • Additional benefits: 401k ( 50% company match up to 6% of pay) FSA HSA life insurance and more
  • Our Perks: Free daily lunch No meeting Fridays unlimited PTO casual dress code
  • Compensation Components: Competitive base salaries generous pre-IPO stock option grants relocation assistance and (coming soon!) annual bonuses
  • Team Growth: 350 employees and counting across 5 global offices
Base Salary Range: $120000 - 150000

The stated compensation range reflects only the targeted base compensation range and excludes additional earnings such as bonus equity and benefits. If your compensation requirements fall outside of the range we still encourage you to apply. The salary range for this role is an estimate based on a range of compensation factors inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience education and/or training critical skills and/or business considerations.

Recruiting Agencies: CHAOS Industries does not accept unsolicited resumes or outreach. Unsolicited submissions will not be reviewed or compensated.

#LI-onsite


Required Experience:

IC


About Company

Company Logo

CHAOS Industries builds omniscient defense systems powered by Coherent Distributed Networks (CDNTM), giving military, commercial, and border teams the ultimate advantage: time.

View Profile View Profile