111 grc jobs at 61 companies in Virginia

1w
Save
Mark Applied
Hide
GRC Analyst – Rockville, MD
Rockville or Falls Church
OnsiteContract
Creative Information Technology
Creative Information Technology: Provides IT solutions and software for government and healthcare sectors.
1+ YOE1 year information security/IT/GRC experience preferred; bachelor\u0002s degree in related field preferred; experience with ServiceNow and Office 365; knowledge of NIST, risk scoring, HIPAA; certifications earn points.
ServiceNow, Office 365
1w
Save
Mark Applied
Hide
GRC Engineer III
Fairfax or Lafayette or Knoxville
$144k-$311k/yr HybridFull Time
CGI
CGINYSE: GIB: Provides information technology and business consulting services.
9+ YOEBachelor's in cyber field, 9+ years relevant experience, experience with ServiceNow/Archer/eMASS, RMF automation, FAIR, AI governance familiarity, strong communication and executive engagement skills.
ServiceNow, Archer, eMASS
1mo
Save
Mark Applied
Hide
Senior vCISO / GRC Consulting Manager
Richmond, Virginia, United States
$125k/yr OnsiteFull Time
Agency
Agency: Automates cybersecurity compliance and managed security operations for startups.
6+ YOE4+ Mgmt6+ years GRC/cybersecurity experience with 4+ years managing teams; experience with SOC 2, ISO 27001, NIST frameworks, audit readiness, client advisory, and project delivery; strong communication and project management skills; in-person from Richmond, VA.
NIST 800-171, NIST 800-53, CMMC, SOC 2, ISO 27001, Vanta, Drata, Secureframe, Hyperproof, AuditBoard, OneTrust, HIPAA, HITRUST, NIST CSF, PCI DSS, GDPR, CIS Controls, AWS, Azure, Google Cloud
3w
Save
Mark Applied
Hide
Senior GRC Engineer, Trust
New York City or Maryland or Massachusetts or Virginia or Georgia or New York
$97k-$184k/yr OnsiteFull Time
Chainalysis
Chainalysis: Blockchain data platform for cryptocurrency investigation and compliance.
Experience implementing and operating security and compliance controls in cloud/SaaS environments; built evidence collection, control testing, or remediation workflows; supported SOC 2/ISO 27001 or similar; strong written/verbal communication; US citizenship required.
AWS, Terraform, Vanta, Jira, Okta
3mo
Save
Mark Applied
Hide
Governance Risk Compliance (GRC) Manager
Vienna, Virginia, United States
OnsiteFull Time
Antithesis
Antithesis: Autonomous software testing platform for deterministic bug detection.
3+ YOE3–5 years GRC/compliance/IT audit; hands-on SOC 2 audits; deep tech understanding; AWS/GCP IaC; strong written comms; fast-paced environment.
AWS, GCP, Terraform
1w
Save
Mark Applied
Hide
Associate GRC Analyst
Richmond, Virginia, United States
$75k-$101k/yr HybridFull Time
CoStar Group
CoStar GroupNASDAQ: CSGP: Global provider of commercial and residential real estate data.
1+ YOEBachelor's degree,1+ year experience in IT/audit/compliance or related role; knowledge of core security concepts, strong written communication, organizational skills, and curiosity about cybersecurity.
Python, PowerShell, Power Automate
1w
Save
Mark Applied
Hide
Associate GRC Analyst
Richmond, Virginia, United States
$75k-$101k/yr HybridFull Time
CoStar Group
CoStar GroupNASDAQ: CSGP: Provides global real estate information, analytics, and online marketplaces.
1+ YOEBachelor's degree,1+ year experience in IT/audit/compliance/info security,knowledge of core security concepts,excellent written communication,organizational skills,curiosity about cybersecurity.
Python, PowerShell, Power Automate
3w
Save
Mark Applied
Hide
GRC Team Lead
Richmond, Virginia, United States
$90k-$150k/yr HybridFull Time
CapTech
CapTech: Provides technology and management consulting services to large enterprises.
6+ YOE6+ years in information security/GRC/IT audit with experience owning SOC 2, NIST 800-53, or NIST AI RMF; CRISC or CISM (or to be attained); strong executive communication and automation experience.
Python, PowerShell, APIs, Microsoft Office
6d
Save
Mark Applied
Hide
Security Assessor (RMF / GRC)
Bethesda or McLean
HybridFull Time
Digital Global Connectors
Digital Global Connectors: Provides cybersecurity, engineering, and compliance services to federal agencies.
5+ YOEBachelor's degree, 5+ years performing RMF/GRC security control assessments using NIST SP 800-53, experience supporting ATO and continuous monitoring, strong technical writing and analytical skills, U.S. citizenship and ability to obtain Tier 2 Public Trust.
NIST SP 800-53, NIST SP 800-37, FISMA, Risk Management Framework (RMF), Microsoft Office Suite, ServiceNow, Jira
1mo
Save
Mark Applied
Hide
Risk Consulting - Risk Technology - Oracle GRC - Manager (New York, NY, US, 10001-8604)
New York or Atlanta or Boston or Chicago or Cleveland or Dallas or Detroit or Pittsburgh or Hoboken or Houston or Los Angeles or McLean or Miami or Minneapolis or North Carolina or Philadelphia or Portland or San Francisco or Seattle or Tampa
$150k-$260k/yr HybridFull Time
EY
EY: Global firm providing audit, tax, and professional consulting services.
5+ YOEBachelor's or master's degree with ~5 years related experience; Oracle security/controls and controls testing experience; strong project management, client service, leadership, communication, analytical skills; valid US driver’s license and passport; willing to travel.
Oracle, Oracle Cloud, Workday
1mo
Save
Mark Applied
Hide
Enterprise Cybersecurity GRC Governance Analyst
McLean, Virginia, United States
$99k-$225k/yr HybridFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
8+ YOE8+ years in ISSO/SCA/ISSE/ISSM roles, experience configuring and automating GRC platforms (ServiceNow, Archer, Xacta, eMASS), knowledge of NIST frameworks and federal security standards, HS diploma/GED, U.S. citizenship required.
ServiceNow, Archer, Xacta, eMASS, RSA Archer, CSAM, Telos Xacta
1mo
Save
Mark Applied
Hide
Enterprise Cybersecurity GRC Governance Analyst
McLean or United States
$99k-$225k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
8+ YOE8+ years in ISSO/SCA/ISSE/ISSM roles; experience configuring and automating GRC platforms (ServiceNow, Archer, Xacta, eMASS); strong process/change management, policy-to-implementation translation, and knowledge of NIST RMF/FISMA/FedRAMP; U.S. citizenship required.
ServiceNow, Archer, RSA Archer, Xacta, Telos Xacta, eMASS, CSAM, API
6d
Save
Mark Applied
Hide
Senior ESM Consultant - ServiceNow SME - GRC & IRM
Mclean or Vienna
$70k-$170k/yr RemoteFull Time
Capgemini
CapgeminiEuronext Paris: CAP: Provides global IT consulting and digital transformation services.
7+ YOE7+ years ServiceNow development, 3+ years ServiceNow GRC/IRM expertise, ServiceNow scripting (JavaScript, Glide), Flow Designer, IntegrationHub, risk framework mapping, technical leadership and mentoring experience.
ServiceNow, JavaScript, Glide, Flow Designer, IntegrationHub, ServiceNow CSDM, Azure AD, BitSight
2w
Save
Mark Applied
Hide
COMPLIANCE DATA ARCHITECT / GRC RECONILIATION ENGINEER
Arlington or Alexandria
$145k-$180k/yr HybridFull Time
Zermount
Zermount: Provider of cybersecurity and IT solutions to government agencies.
15+ YOE15+ years in database/data architecture across cloud and on-prem, strong data modeling, ETL and reconciliation, hands-on NIST SP 800-53 and POA&M/ATO experience, T-SQL and PowerShell skills, attention to detail.
Liquibase, AWS Glue, AWS DMS, Azure Data Factory, Splunk, Azure Log Analytics, T-SQL, PowerShell, OSCAL, KQL, AWS RDS, Azure SQL
2mo
Save
Mark Applied
Hide
Cybersecurity Consultant
McLean or Bethesda
$85k-$141k/yr OnsiteFull Time
Guidehouse
Guidehouse: Provides management and technology consulting services to diverse organizations.
3+ YOE3+ years in cybersecurity or IT risk management; Bachelor's degree; ability to obtain Public Trust; experience with GRC, NIST SP 800-53, FISMA; strong communication and analytical skills.
GRC platforms, NIST SP 800-53, FISMA, 800-37
2mo
Save
Mark Applied
Hide
Senior Information Systems Security Officer
Rosslyn, Virginia, United States
$150k/yr OnsiteFull Time
AptNexus
AptNexus: A provider of information technology and security services.
7+ YOESenior ISSO with 7-10 years in federal or federal contractor environment; proficient in RMF/NIST controls; SA&A packaging; GRC tools; cloud security; active Secret clearance.
GRC platform, Xacta 360, SIEM, EDR, CrowdStrike, Qualys, NIST RMF, NIST SP 800-53
1mo
Save
Mark Applied
Hide
Risk and Control Manager - IT SOX, GFRC
Austin or Arlington or Seattle or Portland
$121k-$164k/yr OnsiteFull Time
Amazon
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
5+ YOE5+ years compliance, audit, or risk management experience; Bachelor’s degree or equivalent required; deep knowledge of COSO 2013, SEC/PCAOB, ITGCs, SOX scoping, control design, testing, remediation, and GRC platforms.
GRC platforms, audit management tools, ERP systems, databases
1mo
Save
Mark Applied
Hide
Sr. Director, Cyber Risk and Trust
Sterling, Virginia, United States
OnsiteFull Time
Asurion: Provides insurance and repair services for consumer electronics.
15+ YOE12+ MgmtMaster's preferred; 15+ years cybersecurity/technology risk experience and 12+ years leading teams; deep governance, GRC/TPRM, third-party risk, audit, and security awareness expertise; strong executive communication.
NIST CSF, NIST SP 800, ISO/IEC 27001, SOC 2, CIS Controls, PCI DSS, GDPR, CCPA/CPRA, LGPD, PIPA, APPI, PDPA, GRC, TPRM, ERM
3d
Save
Mark Applied
Hide
Cloud Information Assurance Engineer
Tysons, Virginia, United States
$135k-$155k/yr OnsiteFull Time
Telos
TelosNASDAQ: TLS: Provides cyber, cloud, and enterprise security solutions for government and commercial clients.
5+ YOEActive TS/SCI clearance and US citizenship, 5+ years IT experience (degree may be substituted), DOD 8140 eligibility, cloud provider experience (AWS/Azure/GCP), RMF/GRC and audit experience, strong analytical and communication skills.
AWS, Azure, GCP, GRC, Risk Management Framework (RMF)
2mo
Save
Mark Applied
Hide
Director, Cybersecurity Compliance
Arlington, Virginia, United States
OnsiteFull Time
VHC Health
VHC Health: Community health system providing comprehensive medical and hospital services.
10+ YOE5+ MgmtLeads healthcare organization's GRC program; 10+ years in IT security/risk/compliance; 5+ years in leadership in healthcare or regulated settings; HIPAA/HITECH, NIST/HITRUST/ISO knowledge; CISSP/CISM/CISA/CRISC and HCISPP/HITRUST CCSFP preferred.
GRC platforms, compliance tooling