13 grc specialist jobs at 10 companies in Vienna, VA
3w
Save
Mark Applied
Hide
3w
Cyber GRC Specialist
Baltimore, Maryland, United States
$95k-$115k/yrOnsiteFull Time
Brown Advisory: Independent, privately held, colleague-owned investment management and strategic advisory firm serving private clients and institutions worldwide.
3+ YOE3–6 years in cyber GRC, information security, technology risk, IT audit, compliance, or control management preferred; knowledge of security frameworks and GRC platforms required.
Vanta, Archer, ServiceNow GRC, OneTrust, Drata, ISO 27001, SOC 2, NIST CSF, CIS Controls, Microsoft Excel
Second Front Systems: Public-benefit software helping governments and defense organizations securely deploy mission-critical SaaS.
5+ YOE5+ years in security compliance/GRC with FedRAMP experience; experience authoring SSPs/POA&Ms; knowledge of NIST 800-53/800-37 and FedRAMP; TS/SCI eligibility; CISSP/CISM/Security+; strong written communication.
Singapore or Australia or New Zealand or Sydney or New York City or Washington, D.C. or Vancouver or London or Galway or Budapest or Munich or Bengaluru
HybridFull Time
Diligent: Private GRC SaaS providing governance, risk, compliance, audit, and ESG software to boards and organizational leaders.
1+ YOERequires approximately 12+ months of relevant client-facing experience, English communication skills, collaboration ability, and GRC knowledge or willingness to learn. Degree and professional GRC accreditation are preferred.
AnaVation: Private federal IT contractor serving U.S. government agencies with intelligence, cloud, big-data, cybersecurity, and software-engineering services.
6+ YOE6+ years working with NIST, FISMA, RMF, and SA&A; FedRAMP and multi-cloud (Azure, AWS, OCI) experience; CISSP required; ability to obtain/maintain Public Trust; experience with GRC tools, vulnerability and endpoint tools, and presenting to leadership.
Azure, AWS, Oracle (OCI), Nessus, BigFix, SCCM, ePO, eMASS, JCAM, CSAM, Microsoft Excel, Microsoft Power BI
Singapore or Australia or New Zealand or New York City or Washington, D.C. or Vancouver or London or Galway or Budapest or Munich or Bengaluru or Singapore or Sydney
HybridFull Time
Diligent: Private GRC SaaS providing governance, risk, compliance, audit, and ESG software to boards and organizational leaders.
1+ YOE12+ months of consulting, professional services, SaaS implementation, customer success, or client-facing experience; English communication skills; willingness to learn GRC disciplines and Diligent products.
Vancouver or New York City or Washington or London or Galway or Budapest or Munich or Bengaluru or Singapore or Sydney
$56k-$70k/yrHybridFull Time
Diligent: Private GRC SaaS providing governance, risk, compliance, audit, and ESG software to boards and organizational leaders.
1+ YOERequires 12+ months of consulting, professional services, SaaS implementation, customer success, or client-facing experience; English communication skills; GRC knowledge or willingness to learn; collaboration and problem-solving abilities.
BDR Solutions: Service-disabled veteran-owned small IT services firm modernizing health, social-service, and disaster-relief systems for U.S. federal agencies.
5+ YOEActive MBI (required), U.S. citizenship, 5+ years in FedRAMP High or comparable AWS environments, CISSP/CCSP/Security+ (current), AWS Security experience, POA&M/GRC and ATO support, bachelor's degree in cybersecurity/IT.
Washington or Cleveland or California or Colorado or Hawaii or Illinois or Maine or Maryland or Massachusetts or Minnesota or New Jersey or New York or Vermont or Virginia or Washington or District of Columbia
$64k-$221k/yrHybridFull Time
Accenture Federal ServicesNew York Stock Exchange: ACN: Technology and management consulting for U.S. federal agencies.
2+ YOEManage full RMF lifecycle for federal/DoD systems; implement and assess NIST SP 800-53 controls; perform vulnerability scans, security control assessments, risk analysis, and maintain SSPs/POA&Ms. Requires 2+ years information security experience.
SOS International: Technology and services integrator for government and defense missions.
5+ YOEActive Top Secret/SCI clearance, Bachelor’s degree, 5+ years in risk management/internal controls or related DoD/IC experience; experience with DoD RMIC, FOCI, ServiceNow IRM/SPM, and Microsoft Office.
ServiceNow Integrated Risk Management (IRM), Strategic Portfolio Management (SPM), Microsoft Excel, Microsoft Word, Microsoft PowerPoint, GRC
General Dynamics Information TechnologyNew York Stock Exchange: GD: Provider of enterprise IT services and defense solutions.
5+ YOERequires 5+ years of related experience, US citizenship, active Secret clearance, RMF and ATO experience, Azure security expertise, GRC tool experience, and federal environment experience.
Microsoft Azure Security Stack, Microsoft Sentinel, Microsoft Defender, Risk Management Framework (RMF), Plan of Action and Milestones (POA&M), Security Content Automation Protocol (SCAP), CSAM, STIG, eMASS, Azure for Government, SIPRNET
Continuous Monitoring Specialist (SCA)? Level III (DC, Washington)
Washington, District of Columbia, United States
OnsiteFull Time
RiVidium: RiVidium is a privately held federal contractor providing cybersecurity, IT, human-capital, and intelligence services to government agencies.
7+ YOEActive TS/SCI clearance, 7+ years cybersecurity/continuous monitoring experience, expertise with NIST RMF and vulnerability management, experience with Nessus/ACAS/Tenable and GRC/SIEM platforms, bachelor's degree required.
General Dynamics Mission SystemsNew York Stock Exchange: GD: Defense electronics manufacturer and systems integrator for mission-critical solutions.
8+ YOEBachelor's degree plus 8+ years or master's degree plus 6+ years in AI governance, technology risk, cybersecurity GRC, responsible AI, or AI/ML compliance; U.S. citizenship required.
Microsoft Copilot, Microsoft Purview, OpenAI, Anthropic, Google, Palantir, Snowflake, Databricks, ServiceNow, NIST AI RMF, OWASP Top 10 for LLMs, MITRE ATLAS, EU AI Act, ISO 42001, NIST CSF, GDPR, MCP