23 crisc jobs at 17 companies in Washington, DC

3mo
Save
Mark Applied
Hide
Manager, Cyber Risk & Analysis
McLean or New York
$165k-$188k/yr OnsiteFull Time
Capital One
Capital OneNYSE: COF: Financial services offering credit cards, banking, and loans.
4+ YOE4+ years in cyber security domains; 4+ years in GRC/compliance; high school diploma or equivalent; preferred BS degree; CISSP/CISM/CRISC certifications.
NIST CSF, NIST 800-53, ISO 27000-1, PCI DSS, FFIEC
1mo
Save
Mark Applied
Hide
Information System Security Officer (ISSO) - Hybrid
Washington, District of Columbia, United States
HybridFull Time
Coalfire
Coalfire: Provides professional cybersecurity advisory, assessment, and engineering services.
5+ YOE5+ years ISSO experience performing security assessments, RMF A&A, security documentation (SSP,SIA,POA&M), continuous monitoring, and advising system owners; bachelor’s in IT, CRISC/CISM/CISSP preferred.
Risk Management Framework (RMF), NIST publications
3d
Save
Mark Applied
Hide
Senior Associate, Cyber Risk Specialist Identity & Access Management | Retail Bank
McLean or Richmond
$101k-$127k/yr OnsiteFull Time
Capital One
Capital OneNYSE: COF: Provides credit card, banking, and auto loan services.
3+ YOERequires 3+ years in cybersecurity, technology, consulting, audit, or risk management and 1+ year in identity and access management; preferred certifications include CISSP, CISA, CRISC, CISM, CIAM, CIMP, or AIGP.
Identity Governance & Administration, Privileged Access Management, Entitlement Management, Single Sign-On (SSO), Multi-Factor Authentication (MFA), Segregation of Duties (SOD)
1mo
Save
Mark Applied
Hide
Security Practice Lead -VA
Reston or Virginia or Maryland or Pittsburgh
OnsiteFull Time
Presidio
Presidio: Global provider of cloud, cybersecurity, and digital infrastructure solutions.
5+ YOE5+ years in IT security/managed security services, bachelor's degree or equivalent, working knowledge of security technologies and vendor products, professional security certifications highly desirable (CISSP, CISM, CRISC, CISA, GIAC).
Palo Alto, Cisco, Splunk, Crowdstrike, Zscaler, Cloudflare, GRC
1mo
Save
Mark Applied
Hide
Director, Cyber Governance, Risk & Compliance
Washington, District of Columbia, United States
OnsiteFull Time
Covington & Burling
Covington & Burling: Global law firm providing legal and regulatory counseling services.
15+ YOE10+ Mgmt15+ years cybersecurity experience with 10+ years running GRC functions; Bachelor's required; CISSP/CISM/CRISC/CISA preferred; experience with NIST, ISO 27001, GDPR, HIPAA, CMMC; strong communication and stakeholder leadership.
GRC, NIST CSF, ISO 27001, EU/UK GDPR, HIPAA, CMMC, ITAR/EAR
1mo
Save
Mark Applied
Hide
Vulnerability Management Lead
Washington or United States
RemoteFull Time
Valiant Solutions
Valiant Solutions: Provides cybersecurity and IT services to federal government agencies.
6+ YOEU.S. citizen with 6+ years cybersecurity experience, OS and networking knowledge, Tenable/AquaSec/CDM experience, GCIH/CISSP/CISM/CRISC certification, POA&M and dashboarding experience, and ability to coordinate across security and engineering teams.
Tenable ONE, Nessus, Tenable.io, AquaSec, CDM, ServiceNow, SIEM, AWS GovCloud
2mo
Save
Mark Applied
Hide
Risk Manager
Rockville, Maryland, United States
$155k-$165k/yr HybridFull Time
CVP
CVP: Provides technology and strategy consulting services to federal agencies.
6+ YOE6+ years cybersecurity experience, FISMA/FedRAMP A&A background, experience with risk assessments, security controls, POA&Ms, and team leadership; one of CISSP/CISA/CISM/CRISC required; familiarity with ITIL, GRC, and continuous monitoring tools.
CSAM, Tenable Nessus, DBProtect, Wireshark, WebInspect, ITIL
2mo
Save
Mark Applied
Hide
DHS Information Systems Security Engineer
Washington or District of Columbia
OnsiteFull Time
OneZero Solutions
OneZero Solutions: Provides cybersecurity and IT services to federal government agencies.
12+ YOETS/SCI clearance and 12+ years ISSE experience supporting DoD/Federal environments. Expertise in RMF/FISMA, DoD STIG, NIST CSF, IDS/IPS, SIEM, penetration testing; CRISC/GISP/CASP/CISSP or equivalent experience.
OpenRMF, DoD STIG, NIST Cybersecurity Framework, FISMA, RMF, IDS/IPS, SIEM, VPN
1mo
Save
Mark Applied
Hide
Information Security Engineer III
Washington, District of Columbia, United States
HybridFull Time
GAMA-1 Technologies
GAMA-1 Technologies: Provides IT, cloud, and security services to federal agencies.
5+ YOEBachelor's degree, 5+ years AWS cloud security experience, hands-on with CloudFormation/IaC, Splunk/Nessus/Tenable, AWS security services, and must hold one of CISA/CRISC/CISM/CGEIT/CISSP/CAP; able to obtain security clearance.
AWS, CloudFormation, Splunk, Nessus, Tenable, Palo Alto, Imperva, Fortinet, API Gateway, Lambda, CloudFront
2mo
Save
Mark Applied
Hide
Director, Cybersecurity Compliance
Arlington, Virginia, United States
OnsiteFull Time
VHC Health
VHC Health: Community health system providing comprehensive medical and hospital services.
10+ YOE5+ MgmtLeads healthcare organization's GRC program; 10+ years in IT security/risk/compliance; 5+ years in leadership in healthcare or regulated settings; HIPAA/HITECH, NIST/HITRUST/ISO knowledge; CISSP/CISM/CISA/CRISC and HCISPP/HITRUST CCSFP preferred.
GRC platforms, compliance tooling
1mo
Save
Mark Applied
Hide
Manager, OT Cybersecurity
Manassas, Virginia, United States
OnsiteFull Time
Northern Virginia Electric Cooperative
Northern Virginia Electric Cooperative: Provides electric distribution and utility services in Northern Virginia.
7+ YOEBachelor's in CS/IT required; 7+ years cybersecurity experience with 3+ years in OT/ICS; experience managing technical teams; knowledge of NERC CIP/NIST, ITIL, SCADA, SIEM, and OT security tools; CISSP/CISM/CRISC/CSSA/SCADA preferred.
Tableau, Power BI, SIEM, SCADA, ITIL
1mo
Save
Mark Applied
Hide
AI Governance Analyst
Washington, District of Columbia, United States
$110k-$135k/yr OnsiteFull Time
Koniag Government Services
Koniag Government Services: Providing technical and professional services to federal agencies.
5+ YOEBachelor's degree, 5+ years in AI governance/technology policy or risk management, knowledge of federal AI policies and NIST AI RMF, ability to obtain Public Trust, and relevant certifications (CISSP,CIPP/G,PMP,CRISC or NIST AI RMF credentials).
TensorFlow, PyTorch, Scikit-learn, AWS SageMaker, Azure Machine Learning, Google Vertex AI, SHAP, LIME, NIST AI RMF
1mo
Save
Mark Applied
Hide
Lead Technical Advisor - Clearance Required
Fort Belvoir, Virginia, United States
$134k-$195k/yr OnsiteFull Time
LMI
LMI: Provides management consulting and digital solutions to federal government agencies.
10+ YOEBachelor's in CS/IT required (Master's preferred); 10+ years in solution architecture, cloud, cybersecurity, and data infrastructure supporting large-scale Army/DoD environments; Active Secret clearance preferred; relevant certifications (CISSP, CISM, CRISC, Security+, Cloud+, CySA+, etc.).
AWS, Azure, TAK, Cross-Domain Solution (CDS)
3w
Save
Mark Applied
Hide
IT Risk Consulting Manager
Washington, District of Columbia, United States
$77k-$125k/yr FieldFull Time
Kearney & Company
Kearney & Company: Provides financial, accounting, and consulting services to federal agencies.
4+ YOEBachelor's degree, 4+ years in IT risk/technology advisory/internal IT audit, experience with ITGCs and control assessments, client-facing consulting skills, ability to obtain US security clearance, and at least one professional certification (CISA/CISSP/CRISC/CGEIT/Security+/CPA).
Oracle, Oracle Cloud ERP, Oracle Federal Financials, AWS, Azure, Oracle Cloud Infrastructure (OCI), Google Cloud Platform, ServiceNow GRC, Diligent HighBond, Archer, ERP
1w
Save
Mark Applied
Hide
Manager - Information Security Compliance
Reston, Virginia, United States
$136k-$184k/yr HybridFull Time
Verisign
VerisignNASDAQ: VRSN: Provides internet domain name registry and DNS infrastructure services.
8+ YOE2+ Mgmt8+ years in information security governance, risk, or compliance; 4+ years security control assessment; 2+ years managing staff; bachelor\u0002s in related field or equivalent; expertise with CIS, SOC 2/3, NIST frameworks; CISSP/CISA/CISM/CRISC preferred.
CIS Controls, SOC 2, SOC 3, NIST Cybersecurity Framework, NIST SP800-53
6d
Save
Mark Applied
Hide
Cybersecurity Compliance Analyst (2 Positions Available)
Washington, District of Columbia, United States
$95k-$137k/yr OnsiteFull Time
Metropolitan Washington Airports Authority
Metropolitan Washington Airports Authority: Operates major airports and transportation infrastructure in Washington, D.C.
5+ YOEFive years in cybersecurity compliance, governance, risk management, information security, internal audit, or regulatory compliance; bachelor's degree preferred or equivalent experience; driver's license required.
National Institute of Standards and Technology (NIST), Payment Card Industry Data Security Standard (PCI DSS), ISO 27001, CJIS, Health Insurance Portability and Accountability Act (HIPAA), Certified Information Systems Auditor (CISA), CRISC, CISM, CISSP
1d
Save
Mark Applied
Hide
26-27 Youth@Work Internship
Prince George's County, Maryland, United States
$18/hr OnsiteMultiple Commitments Available
Prince George's County Government
Prince George's County Government: Local government providing administrative and public services to residents.
Prince George's County resident, age 18–24 by October 1, 2026, GPA of 2.5 or higher, prior SYEP participation, interview, and possible assessment, background check, or driver's license by discipline.
Microsoft Excel, Microsoft Office Suite, Microsoft 365 Fundamentals, CISM, CRISC, CCNA, CCT, CSM, CompTIA A+
2d
Save
Mark Applied
Hide
Manager, Enterprise Identity and Data Protection
Suwanee or Ashburn or Irving or Overland Park
OnsiteFull Time
QTS Data Centers
QTS Data Centers: Operates and provides large-scale data center colocation and infrastructure.
7+ YOE3+ MgmtBachelor’s degree or equivalent experience; 7+ years in enterprise technology, governance, or risk and controls; 3+ years leading technical teams; IAM, DLP, audited environments, vendors, budgets, and process improvement experience.
SailPoint, Saviynt, Okta, Microsoft Entra ID Governance, Veza, Microsoft Purview, Zscaler, Netskope, Microsoft Entra, Intune, ServiceNow, PMP, Lean Six Sigma, ITIL 4, CRISC, CGEIT, Five Whys