56 cybersecurity grc jobs at 34 companies in Washington, DC

6d
Save
Mark Applied
Hide
Cybersecurity Principal Specialist - GRC #542
Washington, District of Columbia, United States
OnsiteFull Time
United States Senate
United States Senate: The upper chamber of the United States federal legislature.
7+ YOERequires 7–10 years of cybersecurity experience, cybersecurity domain expertise, leadership of project teams, strategic policy and framework development, high school diploma or GED, and eligibility for a Secret clearance as a U.S. citizen.
1mo
Save
Mark Applied
Hide
Enterprise Cybersecurity GRC Governance Analyst
McLean, Virginia, United States
$99k-$225k/yr HybridFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
8+ YOE8+ years in ISSO/SCA/ISSE/ISSM roles, experience configuring and automating GRC platforms (ServiceNow, Archer, Xacta, eMASS), knowledge of NIST frameworks and federal security standards, HS diploma/GED, U.S. citizenship required.
ServiceNow, Archer, Xacta, eMASS, RSA Archer, CSAM, Telos Xacta
1mo
Save
Mark Applied
Hide
Enterprise Cybersecurity GRC Governance Analyst
McLean or United States
$99k-$225k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
8+ YOE8+ years in ISSO/SCA/ISSE/ISSM roles; experience configuring and automating GRC platforms (ServiceNow, Archer, Xacta, eMASS); strong process/change management, policy-to-implementation translation, and knowledge of NIST RMF/FISMA/FedRAMP; U.S. citizenship required.
ServiceNow, Archer, RSA Archer, Xacta, Telos Xacta, eMASS, CSAM, API
4d
Save
Mark Applied
Hide
Cybersecurity Specialist
Rockville or McLean or United States or Washington
$98k-$163k/yr HybridFull Time
Guidehouse
Guidehouse: Provides management and technology consulting services to diverse organizations.
5+ YOEBachelor's degree or four additional years of experience, 5+ years in cybersecurity or related fields, federal security framework knowledge, ATO, POA&M, vulnerability management, incident response, and public trust eligibility.
FISMA, NIST 800-53, FedRAMP, Jira, Azure DevOps, Confluence, Microsoft SharePoint, Microsoft Teams, AWS, GRC, DevSecOps, ITIL, SAFe
3d
Save
Mark Applied
Hide
Cybersecurity Governance and Risk Management (GRC) Lead
Laurel, Maryland, United States
$165k-$210k/yr RemoteFull Time
ERP International
ERP International: Provider of healthcare and technology solutions for federal agencies.
7+ YOE3+ MgmtRequires 7+ years of cybersecurity or related experience, 3+ years leading governance or risk activities, a relevant bachelor's degree, and ability to obtain a government Public Trust clearance.
NIST Risk Management Framework, Enterprise Risk Management, FISMA, Zero Trust
2mo
Save
Mark Applied
Hide
Director, Cybersecurity Compliance
Arlington, Virginia, United States
OnsiteFull Time
VHC Health
VHC Health: Community health system providing comprehensive medical and hospital services.
10+ YOE5+ MgmtLeads healthcare organization's GRC program; 10+ years in IT security/risk/compliance; 5+ years in leadership in healthcare or regulated settings; HIPAA/HITECH, NIST/HITRUST/ISO knowledge; CISSP/CISM/CISA/CRISC and HCISPP/HITRUST CCSFP preferred.
GRC platforms, compliance tooling
2mo
Save
Mark Applied
Hide
EMERGING TECHNOLOGY / CYBERSECURITY ENGINEER
Arlington, Virginia, United States
RemoteFull Time
Zermount
Zermount: Provider of cybersecurity and IT solutions to government agencies.
5+ YOESenior cybersecurity engineer with 5+ years, federal compliance experience (RMF/ATO/NIST), cloud security, and vendor coordination; Bachelor's degree and one certification required.
AWS, Azure, GCP, DevSecOps, Tenable, Splunk, Sentinel, ServiceNow, Prisma Cloud, SIEM, SOAR, GRC
1mo
Save
Mark Applied
Hide
Senior Cybersecurity Project Manager
Washington, District of Columbia, United States
OnsiteFull Time
Tharros
Tharros: Provides specialized cybersecurity defense and vulnerability research services.
15+ YOEActive TS/SCI, 15+ years managing large cybersecurity/IT programs, PMP and CISSP or CISM, experience with cybersecurity program management, strong customer-facing and communication skills.
RMF, Assessment and Authorization (A&A), DevSecOps, Zero Trust, GRC, COMSEC
1mo
Save
Mark Applied
Hide
EMERGING TECHNOLOGY / CYBERSECURITY ENGINEER
Arlington or Alexandria
RemoteFull Time
Zermount
Zermount: Provides cybersecurity and IT consulting services to government agencies.
5+ YOE5+ years federal cybersecurity experience (RMF/ATO), expertise in cloud/SaaS/AI security, security architecture, assessments, POA&Ms, plus strong communication and stakeholder coordination skills; one listed security certification required.
NIST AI RMF, OWASP Top 10 for LLM/GenAI, MITRE ATLAS, AWS, Microsoft Azure, Google Cloud Platform, Splunk, Microsoft Sentinel, QRadar, Tenable, Security Hub, Microsoft Defender, Prisma Cloud, ServiceNow, Microsoft PyRIT, NVIDIA Garak, Promptfoo, DeepEval, OpenAI Evals, Azure AI Foundry Evaluation, Amazon Bedrock Guardrails, Google Vertex AI Evaluation, Lakera Guard, HiddenLayer, Protect AI ModelScan/Guardian, SIEM, SOAR, GRC
2mo
Save
Mark Applied
Hide
Cloud Cybersecurity Specialist - Senior
Herndon or United States
$100k-$130k/yr RemoteFull Time
BDR Solutions
BDR Solutions: Provider of IT, engineering, and consulting for federal agencies.
5+ YOEActive MBI (required), U.S. citizenship, 5+ years in FedRAMP High or comparable AWS environments, CISSP/CCSP/Security+ (current), AWS Security experience, POA&M/GRC and ATO support, bachelor's degree in cybersecurity/IT.
AWS, Security Hub, GuardDuty, CloudTrail, Config, IAM Access Analyzer, Splunk, ELK, eMASS, Archer, ServiceNow GRC, Tenable, Qualys, Inspector, Terraform, Git, Databricks, Lake Formation, OSCAL, Python
1w
Save
Mark Applied
Hide
Senior Cybersecurity Engineer / (SME) ? Level III (DC, Washington)
Washington, District of Columbia, United States
OnsiteFull Time
RiVidium
RiVidium: Provides cybersecurity software and IT services to federal agencies.
10+ YOETop Secret/SCI clearance, 10+ years cybersecurity engineering experience for federal/IC programs; expertise in cloud security, DevSecOps, Zero Trust, security automation, GRC/Risk frameworks; CISSP and AWS certs required.
ACAS, Nessus, SonarQube, GitLab, SCAP Compliance Checker, SCAP, Nmap, WebInspect, RSA Archer, Terraform, CloudFormation, Docker, Kubernetes, SOAR
2mo
Save
Mark Applied
Hide
Principal Cybersecurity Engineer
Reston, Virginia, United States
$185k-$277k/yr HybridFull Time
Workday
WorkdayNASDAQ: WDAY: Provides cloud-based software for financial and human capital management.
9+ YOE9+ years in building GRC platforms; proficient in Python/Go/Java; strong SDLC governance; architecture, data models, API design; leads technical roadmaps; experience automating risk data.
Python, Go, Java, Git, APIs, ETL, Data Modeling, NIST, FAIR
2mo
Save
Mark Applied
Hide
VP of Cybersecurity & Information Security
Nottingham, Maryland, United States
$160k-$225k/yr OnsiteFull Time
Mariner Finance
Mariner Finance: Provider of personal installment and auto loans.
12+ YOE3+ MgmtLead cybersecurity and information security; 12+ years IT with leadership; 3+ years management; CISSP/CISM; extensive security tech and regulatory experience.
SIEM, EDR, IAM, PAM, Vulnerability Management, Cloud Security, DevSecOps, Identity Security, Zero Trust, GRC
2mo
Save
Mark Applied
Hide
GRC Lead / Cyber Risk Manager (DC, Washington)
Washington, District of Columbia, United States
OnsiteFull Time
CyberLinx Solutions
CyberLinx Solutions: Provides specialized cybersecurity and IT services to federal agencies.
8+ YOE3+ MgmtBachelor's in a related field, 8+ years in cybersecurity with 3+ years of GRC leadership, strong knowledge of NIST CSF/RMF and NIST SP 800-53/800-171, audit/compliance experience, and executive communication skills.
NIST Cybersecurity Framework (CSF), NIST Risk Management Framework (RMF), NIST SP 800-53, NIST SP 800-171, ISO 27001
1w
Save
Mark Applied
Hide
General Counsel, Government Contracts & Cybersecurity
Charlotte or Washington
$242k-$302k/yr HybridFull Time
Honeywell
HoneywellNASDAQ: HON: Manufactures aerospace products, building technologies, and industrial control systems.
10+ YOEJ.D. or equivalent, U.S. bar admission, and 10+ years of legal experience advising on government contracts and cybersecurity, including FAR, DFARS, CMMC, NIST, and related compliance.
SAM.gov, CAGE, KPI, KRI, GRC, NIST SP 800-171/800-53, CMMC, DFARS 252.204-7012
1mo
Save
Mark Applied
Hide
ITDI Cyber Engineering Lead #830
Washington, District of Columbia, United States
OnsiteFull Time
Allen Integrated Solutions
Allen Integrated Solutions: Provides technical and engineering services for national security missions.
Bachelor's degree, experience maintaining SIEM/XDR/DLP/GRC, implementing automation for cybersecurity operations, and providing expert guidance; Public Trust clearance required.
SIEM, XDR, DLP, GRC, Microsoft Excel
1mo
Save
Mark Applied
Hide
Director, Cyber Governance, Risk & Compliance
Washington, District of Columbia, United States
OnsiteFull Time
Covington & Burling
Covington & Burling: Global law firm providing legal and regulatory counseling services.
15+ YOE10+ Mgmt15+ years cybersecurity experience with 10+ years running GRC functions; Bachelor's required; CISSP/CISM/CRISC/CISA preferred; experience with NIST, ISO 27001, GDPR, HIPAA, CMMC; strong communication and stakeholder leadership.
GRC, NIST CSF, ISO 27001, EU/UK GDPR, HIPAA, CMMC, ITAR/EAR
1mo
Save
Mark Applied
Hide
Director, Cyber Risk
Sterling or United States
OnsiteFull Time
Asurion: Provides insurance and repair services for consumer electronics.
10+ YOE5+ Mgmt10+ years in cybersecurity/IT risk or GRC with 5+ years leading managers; bachelor’s or equivalent; deep knowledge of NIST CSF 2.0 and ISO 27001/27005; GRC platform and risk-quantification experience; strong executive communication.
ServiceNow IRM, Archer, OneTrust
1mo
Save
Mark Applied
Hide
SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead
Silver Spring, Maryland, United States
HybridFull Time
For Your Information, Inc.
For Your Information, Inc.: Provides HR and IT services to federal government agencies.
8+ YOE8+ years in cybersecurity/GRC/IT audit with direct SOC 2 Type 2 audit experience, GRC platform experience (Drata preferred), SaaS/cloud expertise, evidence review, strong written communication, and stakeholder coordination skills.
Drata, Vanta, SecureFrame, Hyperproof, Jira, Confluence, AWS, Azure, GCP, CI/CD, SAST, DAST, SCA, IAM, MFA, vulnerability management, PCI DSS
3d
Save
Mark Applied
Hide
PCI DSS Internal Controls, Senior Manager
Bethesda or New York City or Chicago or Chevy Chase or New York
$130k-$212k/yr HybridFull Time
GEICO
GEICO: Provides vehicle and property insurance services to consumers.
5+ YOERequires PCIP, 5+ years in auditing, control assessment, and PCI DSS, 6+ years in GRC, cybersecurity expertise, security technology experience, and a relevant bachelor's degree.
PCI DSS, NIST 800-53, GLBA, FFIEC, ITIL, NIST, MITRE, COBIT, COSO, HITRUST, SOC, CSF, ISO, GDPR, firewalls, intrusion detection and prevention systems, encryption technologies