56 cybersecurity grc jobs at 34 companies in Washington, DC
6d
Save
Mark Applied
Hide
6d
Cybersecurity Principal Specialist - GRC #542
Washington, District of Columbia, United States
OnsiteFull Time
United States Senate: The upper chamber of the United States federal legislature.
7+ YOERequires 7–10 years of cybersecurity experience, cybersecurity domain expertise, leadership of project teams, strategic policy and framework development, high school diploma or GED, and eligibility for a Secret clearance as a U.S. citizen.
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
8+ YOE8+ years in ISSO/SCA/ISSE/ISSM roles, experience configuring and automating GRC platforms (ServiceNow, Archer, Xacta, eMASS), knowledge of NIST frameworks and federal security standards, HS diploma/GED, U.S. citizenship required.
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
8+ YOE8+ years in ISSO/SCA/ISSE/ISSM roles; experience configuring and automating GRC platforms (ServiceNow, Archer, Xacta, eMASS); strong process/change management, policy-to-implementation translation, and knowledge of NIST RMF/FISMA/FedRAMP; U.S. citizenship required.
ServiceNow, Archer, RSA Archer, Xacta, Telos Xacta, eMASS, CSAM, API
Rockville or McLean or United States or Washington
$98k-$163k/yrHybridFull Time
Guidehouse: Provides management and technology consulting services to diverse organizations.
5+ YOEBachelor's degree or four additional years of experience, 5+ years in cybersecurity or related fields, federal security framework knowledge, ATO, POA&M, vulnerability management, incident response, and public trust eligibility.
FISMA, NIST 800-53, FedRAMP, Jira, Azure DevOps, Confluence, Microsoft SharePoint, Microsoft Teams, AWS, GRC, DevSecOps, ITIL, SAFe
Cybersecurity Governance and Risk Management (GRC) Lead
Laurel, Maryland, United States
$165k-$210k/yrRemoteFull Time
ERP International: Provider of healthcare and technology solutions for federal agencies.
7+ YOE3+ MgmtRequires 7+ years of cybersecurity or related experience, 3+ years leading governance or risk activities, a relevant bachelor's degree, and ability to obtain a government Public Trust clearance.
NIST Risk Management Framework, Enterprise Risk Management, FISMA, Zero Trust
VHC Health: Community health system providing comprehensive medical and hospital services.
10+ YOE5+ MgmtLeads healthcare organization's GRC program; 10+ years in IT security/risk/compliance; 5+ years in leadership in healthcare or regulated settings; HIPAA/HITECH, NIST/HITRUST/ISO knowledge; CISSP/CISM/CISA/CRISC and HCISPP/HITRUST CCSFP preferred.
Zermount: Provider of cybersecurity and IT solutions to government agencies.
5+ YOESenior cybersecurity engineer with 5+ years, federal compliance experience (RMF/ATO/NIST), cloud security, and vendor coordination; Bachelor's degree and one certification required.
Tharros: Provides specialized cybersecurity defense and vulnerability research services.
15+ YOEActive TS/SCI, 15+ years managing large cybersecurity/IT programs, PMP and CISSP or CISM, experience with cybersecurity program management, strong customer-facing and communication skills.
RMF, Assessment and Authorization (A&A), DevSecOps, Zero Trust, GRC, COMSEC
Zermount: Provides cybersecurity and IT consulting services to government agencies.
5+ YOE5+ years federal cybersecurity experience (RMF/ATO), expertise in cloud/SaaS/AI security, security architecture, assessments, POA&Ms, plus strong communication and stakeholder coordination skills; one listed security certification required.
NIST AI RMF, OWASP Top 10 for LLM/GenAI, MITRE ATLAS, AWS, Microsoft Azure, Google Cloud Platform, Splunk, Microsoft Sentinel, QRadar, Tenable, Security Hub, Microsoft Defender, Prisma Cloud, ServiceNow, Microsoft PyRIT, NVIDIA Garak, Promptfoo, DeepEval, OpenAI Evals, Azure AI Foundry Evaluation, Amazon Bedrock Guardrails, Google Vertex AI Evaluation, Lakera Guard, HiddenLayer, Protect AI ModelScan/Guardian, SIEM, SOAR, GRC
BDR Solutions: Provider of IT, engineering, and consulting for federal agencies.
5+ YOEActive MBI (required), U.S. citizenship, 5+ years in FedRAMP High or comparable AWS environments, CISSP/CCSP/Security+ (current), AWS Security experience, POA&M/GRC and ATO support, bachelor's degree in cybersecurity/IT.
WorkdayNASDAQ: WDAY: Provides cloud-based software for financial and human capital management.
9+ YOE9+ years in building GRC platforms; proficient in Python/Go/Java; strong SDLC governance; architecture, data models, API design; leads technical roadmaps; experience automating risk data.
Python, Go, Java, Git, APIs, ETL, Data Modeling, NIST, FAIR
Mariner Finance: Provider of personal installment and auto loans.
12+ YOE3+ MgmtLead cybersecurity and information security; 12+ years IT with leadership; 3+ years management; CISSP/CISM; extensive security tech and regulatory experience.
CyberLinx Solutions: Provides specialized cybersecurity and IT services to federal agencies.
8+ YOE3+ MgmtBachelor's in a related field, 8+ years in cybersecurity with 3+ years of GRC leadership, strong knowledge of NIST CSF/RMF and NIST SP 800-53/800-171, audit/compliance experience, and executive communication skills.
General Counsel, Government Contracts & Cybersecurity
Charlotte or Washington
$242k-$302k/yrHybridFull Time
HoneywellNASDAQ: HON: Manufactures aerospace products, building technologies, and industrial control systems.
10+ YOEJ.D. or equivalent, U.S. bar admission, and 10+ years of legal experience advising on government contracts and cybersecurity, including FAR, DFARS, CMMC, NIST, and related compliance.
Covington & Burling: Global law firm providing legal and regulatory counseling services.
15+ YOE10+ Mgmt15+ years cybersecurity experience with 10+ years running GRC functions; Bachelor's required; CISSP/CISM/CRISC/CISA preferred; experience with NIST, ISO 27001, GDPR, HIPAA, CMMC; strong communication and stakeholder leadership.
GRC, NIST CSF, ISO 27001, EU/UK GDPR, HIPAA, CMMC, ITAR/EAR
Asurion: Provides insurance and repair services for consumer electronics.
10+ YOE5+ Mgmt10+ years in cybersecurity/IT risk or GRC with 5+ years leading managers; bachelor’s or equivalent; deep knowledge of NIST CSF 2.0 and ISO 27001/27005; GRC platform and risk-quantification experience; strong executive communication.
SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead
Silver Spring, Maryland, United States
HybridFull Time
For Your Information, Inc.: Provides HR and IT services to federal government agencies.
8+ YOE8+ years in cybersecurity/GRC/IT audit with direct SOC 2 Type 2 audit experience, GRC platform experience (Drata preferred), SaaS/cloud expertise, evidence review, strong written communication, and stakeholder coordination skills.
Bethesda or New York City or Chicago or Chevy Chase or New York
$130k-$212k/yrHybridFull Time
GEICO: Provides vehicle and property insurance services to consumers.
5+ YOERequires PCIP, 5+ years in auditing, control assessment, and PCI DSS, 6+ years in GRC, cybersecurity expertise, security technology experience, and a relevant bachelor's degree.