Brown Advisory: Provides investment management and financial advisory services to global clients.
3+ YOE3–6 years in cyber GRC, information security, technology risk, IT audit, compliance, or control management preferred; knowledge of security frameworks and GRC platforms required.
Vanta, Archer, ServiceNow GRC, OneTrust, Drata, ISO 27001, SOC 2, NIST CSF, CIS Controls, Microsoft Excel
New York City or Maryland or Massachusetts or Virginia or Georgia or New York
$97k-$184k/yrOnsiteFull Time
Chainalysis: Blockchain data platform for cryptocurrency investigation and compliance.
Experience implementing and operating security and compliance controls in cloud/SaaS environments; built evidence collection, control testing, or remediation workflows; supported SOC 2/ISO 27001 or similar; strong written/verbal communication; US citizenship required.
Digital Global Connectors: Provides cybersecurity, engineering, and compliance services to federal agencies.
5+ YOEBachelor's degree, 5+ years performing RMF/GRC security control assessments using NIST SP 800-53, experience supporting ATO and continuous monitoring, strong technical writing and analytical skills, U.S. citizenship and ability to obtain Tier 2 Public Trust.
TransamericaNYSE: AEG: Provides insurance, retirement solutions, and investment products to customers.
10+ YOE10+ years operational/enterprise risk experience, experience managing enterprise GRC platforms and risk data frameworks, strong ERM and operational risk knowledge, stakeholder influence and communication skills.
United States or Illinois or Colorado or Hawaii or District of Columbia or Maryland or Minnesota or New York or Washington or New Jersey or Vermont or Massachusetts or California or Kansas
$97k-$227k/yrRemoteFull Time
ComcastNASDAQ: CMCSA: Provides global telecommunications, media content, and entertainment services.
5+ YOE5+ years enterprise sales engineering experience in B2B SaaS, GRC/cyber risk expertise, data fluency including SQL, strong PoV/demo/communication skills, ability to travel and influence product direction.
DataBee, SQL, Business Intelligence (BI) Reporting Tools
Cybersecurity Governance and Risk Management (GRC) Lead
Laurel, Maryland, United States
$165k-$210k/yrRemoteFull Time
ERP International: Provider of healthcare and technology solutions for federal agencies.
7+ YOE3+ MgmtRequires 7+ years of cybersecurity or related experience, 3+ years leading governance or risk activities, a relevant bachelor's degree, and ability to obtain a government Public Trust clearance.
NIST Risk Management Framework, Enterprise Risk Management, FISMA, Zero Trust
SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead
Silver Spring, Maryland, United States
HybridFull Time
For Your Information, Inc.: Provides HR and IT services to federal government agencies.
8+ YOE8+ years in cybersecurity/GRC/IT audit with direct SOC 2 Type 2 audit experience, GRC platform experience (Drata preferred), SaaS/cloud expertise, evidence review, strong written communication, and stakeholder coordination skills.
Bethesda or New York City or Chicago or Chevy Chase or New York
$130k-$212k/yrHybridFull Time
GEICO: Provides vehicle and property insurance services to consumers.
5+ YOERequires PCIP, 5+ years in auditing, control assessment, and PCI DSS, 6+ years in GRC, cybersecurity expertise, security technology experience, and a relevant bachelor's degree.
Cybersecurity Information System Security Officer (ISSO)
Aberdeen Proving Ground, Maryland, United States
$96k-$140k/yrOnsiteFull Time
Nakupuna: Provides professional services and technical solutions for federal agencies.
2+ YOEUS citizen with active Secret clearance, 2+ years ISSO experience in DoD, eMASS/RMF proficiency, cloud and GRC experience, risk assessments, and executive reporting skills.
Enterprise Mission Assurance Support Service (eMASS), SIPRNet
Chicago or Denver or Phoenix or Chandler or Arizona or Colorado or District of Columbia or Illinois or Maryland or Texas or Virginia or California or Florida or Massachusetts or New York or Oregon or Washington or Wisconsin or United States
$171k-$214k/yrHybridFull Time
Caribou: Connects car owners with lenders to refinance auto loans.
Owner of security and IT programs with proven SOC 2 Type II delivery, SIEM/EDR incident response, GRC controls, SaaS and identity management, vendor management, and people leadership.
K2United: Provides cybersecurity advisory and online workforce safety training.
4+ YOE4+ years RMF/continuous monitoring experience, POA&M and control assessment expertise, GRC platform experience, bachelor’s degree or equivalent, ability to meet federal background investigation.
McCormickNYSE: MKC: Produces and sells spices, seasonings, condiments, and flavors.
10+ YOE4+ MgmtBachelor's in Information Systems, CISA/CISM/CISSP required, 10+ years technology audit/IT risk experience with 4+ years leadership, GRC platform proficiency, digital transformation and analytics experience.
California or Maryland or Massachusetts or Illinois or Oregon or Washington or Colorado or Texas or Florida or Pennsylvania or Louisiana or Missouri or District of Columbia or New South Wales or Tasmania
RemoteFull Time
UpGuard: AI-powered platform for managing cyber risk and security.
5+ YOE5+ years B2B SaaS implementation/professional services experience, experience with large organisations (5,000+ employees), PSA tools, API/webhook integrations, consultative stakeholder skills; GRC experience desirable.
ManTech: Provides technology solutions for defense and intelligence agencies.
12+ YOERequires US citizenship and active TS/SCI with Polygraph; minimum 12 years relevant SE experience (bachelor's+), ServiceNow implementation experience, systems engineering leadership, GRC/IRM experience, and reporting/dashboard development.
DigiFlight: Provides cybersecurity, aerospace, and systems engineering for government agencies.
4+ YOE3–5 years in cybersecurity, IT audit/compliance, and GRC; knowledge of CMMC Level 1/2, NIST 800-171, CAP, FedRAMP, SOC 2; experience with security assessments and DoD/CUI environments; strong communication.
CVP: Provides technology and strategy consulting services to federal agencies.
6+ YOE6+ years cybersecurity experience, FISMA/FedRAMP A&A background, experience with risk assessments, security controls, POA&Ms, and team leadership; one of CISSP/CISA/CISM/CRISC required; familiarity with ITIL, GRC, and continuous monitoring tools.
Mariner Finance: Provider of personal installment and auto loans.
12+ YOE3+ MgmtLead cybersecurity and information security; 12+ years IT with leadership; 3+ years management; CISSP/CISM; extensive security tech and regulatory experience.
Rockville or McLean or United States or Washington
$98k-$163k/yrHybridFull Time
Guidehouse: Provides management and technology consulting services to diverse organizations.
5+ YOEBachelor's degree or four additional years of experience, 5+ years in cybersecurity or related fields, federal security framework knowledge, ATO, POA&M, vulnerability management, incident response, and public trust eligibility.
FISMA, NIST 800-53, FedRAMP, Jira, Azure DevOps, Confluence, Microsoft SharePoint, Microsoft Teams, AWS, GRC, DevSecOps, ITIL, SAFe
United States or Colorado or Hawaii or Illinois or Maryland or Massachusetts or Minnesota or Vermont or District of Columbia or New York or New Jersey or Washington or California or Connecticut or Pennsylvania
$129k-$189k/yrRemoteFull Time
TwilioNYSE: TWLO: Cloud communications platform for building customer engagement applications.
5+ YOE5+ years security-focused risk management experience with industry risk frameworks, quantitative and qualitative risk analysis, automation and AI tooling, cross-functional collaboration, and strong communication skills.