GRC Analyst
$75k - $95kNextgenID
Location: Onsite - Fairfax, VA · U.S. Citizen Required (FedRAMP / Federal Customer) Type: Full Time NextgenID is hiring a GRC Analyst to do the hands‑on work that keeps our compliance program running. We verify and credential identity at the highest assurance level (IAL3) for federal agencies and enterprises, so evidence, documentation, and audit support are constant, real work. You maintain our control documentation and evidence, run the operational side of our FedRAMP, Kantara, and UK digital‑identity efforts, keep the POA&M and vulnerability tracking current, and complete the security questionnaires our customers send. You report to the GRC Lead. Salary Range: $75,000-$95,000 Role Fit & Non‑Negotiables Onsite at our Fairfax, VA headquarters. This role is hands‑on and evidence‑heavy. U.S. citizen, required for FedRAMP and federal‑customer obligations. Two or more years in GRC, security compliance, audit support, or a closely related role. Comfortable owning documentation, evidence, and trackers to a deadline. Detail‑oriented and discreet with sensitive security information. What You Will Own (90 to 180 Day Outcomes) Current, well‑organized control documentation and evidence repositories, moving from SharePoint into Vanta. The operational FedRAMP evidence effort: control documentation, gap‑finding tracking, and Trust Center content drafts. A monthly POA&M produced from Qualys findings using the FedRAMP template, with remediation tracked to closure. Completed, consistent security questionnaires delivered on time for GRC Lead review. The UK DVS documentation package and Kantara assessment materials kept current and submission‑ready. Core Responsibilities Compliance Documentation & Evidence — keep the record current and audit‑ready. Maintain control documentation, policies, and procedures, and migrate evidence into Vanta. Gather and organize evidence from engineering, DevSecOps, and operations leads. Convert implemented controls into machine‑readable (OSCAL / JSON) format for FedRAMP submission. Authorization & Assessment Support — run the operational side of our certifications. Refine and maintain the UK DVS / DIATF documentation package and scoping forms. Prepare Kantara assessment materials (SoCA, S3A, KAR) and the Rev 4 gap working draft. Coordinate assessment and pentest logistics, scheduling, and evidence with assessors and leads. Vulnerability & POA&M Tracking — keep the remediation record honest. Produce the monthly POA&M from Qualys findings using the FedRAMP template. Track vulnerability remediation and compensating controls with the RedTeam / DevSecOps leads. Maintain vulnerability and vendor‑risk evidence logs (for example, the BeyondTrust remediation log). Customer & Vendor Assurance Support — answer the questionnaires and support vendor risk. Complete security questionnaires (for example, CCRA and customer InfoSec assessments) consistent with prior responses. Support third‑party and vendor risk assessments and evidence requests. Route completed responses to the GRC Lead and management for review before submission. Research & Program Support — support the wider compliance effort. Provide compliance and privacy research to the document and product teams. Support ADA / Section 508 assessments and international import certification documentation (BIS, WPC, ATA Carnet). Help configure and maintain GRC tooling (Vanta) and keep the compliance calendar updated. What You Must Have Already Done Gathered and organized audit evidence and maintained compliance documentation to a deadline. Worked with a control framework (NIST 800-53, 800-63, ISO 27001, or SOC 2) on real evidence or gap work. Tracked vulnerabilities or POA&M items and coordinated remediation with technical teams. Completed a customer or vendor security questionnaire using documented evidence. Kept a tracker, repository, or evidence log accurate across many moving items. Required Qualifications Two or more years in GRC, security compliance, audit support, or a closely related role. Working knowledge of NIST SP 800-53 and/or NIST SP 800-63, ISO 27001, or SOC 2. Experience gathering evidence and maintaining compliance documentation. Experience with vulnerability or POA&M tracking and remediation coordination. Familiarity with vulnerability tooling (Qualys or Nessus) and evidence / GRC platforms (Vanta or similar). Strong writing and documentation skills for policies, procedures, and questionnaire responses. Highly organized and detail‑oriented, able to manage many concurrent items. Discreet and reliable with sensitive security and compliance information. Must be able to work onsite in Fairfax, VA; U.S. citizen (FedRAMP / federal customer). Preferred Qualifications Security+, GRCP, CySA+, or progress toward CISA. Exposure to FedRAMP or FISMA continuous monitoring (ConMon) and 3PAO assessments. Experience with Kantara / NIST 800-63 identity assurance or UK DIATF / DVS. Familiarity with OSCAL or machine‑readable control formats. Experience with security questionnaires (CAIQ, CCRA, customer InfoSec assessments). Background in an IDaaS, cloud, or federal‑contractor environment. You keep trackers and evidence current without being chased. You read a control and know what evidence proves it. You write clearly enough that your draft needs little rework before sign‑off. You chase the last 10 percent of detail that makes evidence audit‑ready. You handle sensitive information with discretion and never submit without review. What Success Looks Like Control documentation and evidence are current, organized, and audit‑ready in Vanta. The monthly POA&M is produced on time and remediation is tracked to closure. UK DVS and Kantara materials are submission‑ready ahead of each deadline. Security questionnaires are completed accurately and on time for GRC Lead review. Inherited workstreams from the departing analyst and intern continue without gaps. Why NextgenID NextgenID builds the compliance‑grade identity infrastructure that federal agencies and enterprises rely on to verify and credential identity at IAL3. Compliance is the product’s license to operate, and the evidence you produce is what makes it real. As GRC Analyst, you will see your work in every certification we hold and every customer questionnaire we clear, and you will grow into deeper risk and program ownership. For the right person, this is the path to a senior GRC or GRC Lead role. NextgenID focuses on improving the efficiency and speed of mission‑critical, high assurance identity enrollment and credentialing operations that are essential to hundreds of millions of users worldwide. Our technologies are engineered to dramatically reduce the time and cost of capturing accurate data when creating a digital identity. Our industry‑neutral solutions revolve around "Supervised Remote‑Identity Proofing" to automatically, securely and "remotely" perform all proofing, enrollment and credentialing processes and workflows for our customers. The industry is taking notice as we are now working with some of the largest agencies in the US Defense, intelligence, Civil, State and Local government markets, as well as other national governments and commercial organizations throughout the world. #J-18808-Ljbffr
$99k - $225k
Enterprise Cybersecurity GRC Governance AnalystThe Opportunity: The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an experienced Information System Security Officer (ISSO) to bridge the gap between high-level policy and technical...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work- NextgenID is hiring a GRC Analyst to manage compliance documentation, evidence, and audit support for FedRAMP, Kantara, and UK identity programs. The role is onsite at Fairfax, VA, with a strong focus on evidence, questionnaire responses, and remediation tracking. You will...Suggested
- ...SAP Application Security And GRC Analyst (Sr.) CGI is seeking a Senior SAP GRC and Application Security Analyst to join an SAP S/4HANA Greenfield implementation project for a large government contract. As a senior-level SAP GRC and Application Security Consultant, you...SuggestedContract workWork at office2 days per week
- ...Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands-on experience in cybersecurity, compliance, and risk management. The internship...SuggestedFull timeInternship
- ...Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands‑on experience in cybersecurity, compliance, and risk management. The internship...SuggestedFull timeInternshipRemote work
- ...Compliance And Risk Analyst The Compliance And Risk Analyst assists the IT Program Manager in the registration of all Application and Database Management Systems (DADMS) for inclusion into the investment portfolio. Responsibilities Use the IT portfolio tool...Temporary workWork at officeImmediate startFlexible hours
- ...missions worldwide. Job Description This position is contingent upon award of contract SOSi is seeking a Risk and Compliance Analyst to support mission requirements for a structured approach to further develop, integrate, and sustain a scalable, federated data...Full timeContract workFor contractorsRemote workWorldwide
$80k - $125k
...Canada, Israel, Japan, and the U.K. For more information, visit Position Summary The Governance, Risk & Compliance (GRC) Analyst is responsible for supporting and maintaining the organization's cybersecurity governance, risk management, and compliance...Flexible hours$151.9k - $173.4k
Compliance Privacy Advisor, Manager The Capital One Privacy Compliance team is seeking a Manager, Compliance Privacy Advisor with a passion for mitigation privacy risks at a tech focused finance institution. They will join us to perform key privacy compliance activities...Full timeTemporary workPart timeLocal area- ...Skill and ExperienceThe ideal candidate is a highly organized Risk Analyst with strong project management and documentation skills who can... .... Experience supporting Governance, Risk, and Controls (GRC) programs in financial services or other regulated environments....Full timeTemporary workWork at officeRelocation
- ...Job Title: Risk and Compliance Systems Analyst (Oracle ERP Fusion and RMC) Location: Vienna, VA Pay Rate: open to W2 and established 1099's Work Model: Hybrid, onsite 3 days a week Position type: multiyear contract We are looking for an Oracle ERP Fusion security and controls...Contract workFor contractorsLocal area3 days per week
- ...our clients, team, and community while delivering excellence. Overview: KYM is seeking a Archer Governance, Risk, and Compliance (GRC) Consultant to execute and support the implementation of a successful DHS program. Responsibilities: Develop, administer,...Hourly payImmediate start
$87.7k - $100.1k
The Enterprise Compliance Governance Training team is seeking a collaborative, analytically focused risk management professional to join our team. As a Sr Risk Specialist at the Senior Associate level in Corporate Compliance, you will work in a strong team environment to...Full timePart timeWork at officeLocal area- Capital One is seeking a Principal Associate Compliance Advisor - Third Party Compliance in McLean, Virginia. The role advises lines of business and Third-Party Managers on compliance risks across the lifecycle and supports governance, advisory, and QA functions within ...
$177.7k - $202.8k
Overview Compliance Advisor Senior Manager The Senior Manager, Compliance performs a key risk management role in the second line of defense, providing primary compliance support to the ‘New to Credit’ credit card business segment. We are looking for a dynamic, strategic...Full timePart timeLocal area- COMFORT SYSTEMS is looking for a Compliance Privacy Advisor, Manager to mitigate privacy risks and manage compliance activities in McLean, VA. The ideal candidate should have a strong background in privacy compliance, experience in risk management, and the ability to work...
$104k - $166k
ResponsibilitiesPeraton is hiring for a Trade Compliance Manager to join our growing Trade Compliance team in our legal department. This position will support efforts pertaining to US government agencies across the intelligence, space, cyber, defense, and civilian markets...Contract workFor contractorsWork at officeShift work$99k - $225k
Information Security Risk SpecialistThe Opportunity:As an Information Security Risk Specialist on our team, you will leverage your expertise to collaborate closely with contractor and DoD government system owners, as well as system administrators and developers, to identify...Full timeContract workPart timeFor contractorsWork at officeLocal areaRemote work$69.4k - $158k
Risk Management AnalystThe Opportunity:Use your industry or domain expertise to assess risk posture to develop innovative solutions to complex problems supporting a dynamic Navy Middle Tier Acquisition (MTA) technical program focused on rapid prototyping and fielding across...Full timeContract workPart timeWork at officeLocal areaRemote work- Navy Federal Credit Union currently does not provide sponsorship for this role. Applicants must be authorized to work in the United States without the need for current or future sponsorship.Responsible for supporting the risk management function by evaluating, analyzing...InternshipMonday to Friday
- Playing an essential role in the U.S. economy, Fannie Mae is foundational to housing finance. Here, your expertise can help fuel purpose-driven innovation that expands access to homeownership and affordable rental housing across the country. Join Fannie Mae to grow your...Full timeWork at officeRemote work
$57.5k - $117.9k
...Job Title: Junior Risk Analyst – Enterprise Risk Management Job Category: Finance and Accounting Time Type: Full time Minimum Clearance Required to Start: None Employee Type: Regular Percentage of Travel Required: Up to 10% Type of Travel: Continental US Anticipated Posting...Full timeContract workWork experience placementFlexible hours$92.3k - $166.85k
Leidos has a new and exciting opportunity for a Sr. Compliance Reporting Analyst in our Intel Security Sector's Analysis Solutions Business Area. Our talented team is at the forefront in Security Engineering, Computer Network Operations (CNO), Mission Software, Analytical...Full timeFor contractorsImmediate startFlexible hours- ...Overview BRMi is seeking a Risk Analyst – Control Testing who will support the Risk Control Self-Assessment (RCSA) process by performing control design assessments and control performance testing across security-related business areas, with a primary focus on fraud operations...Contract workTemporary workLocal areaVisa sponsorshipWork visa
$96.5k - $110.1k
...using SQL and other methods to determine root cause and/or patterns that would be beneficial in resolving the issues. Partner with analyst teams as a subject matter expert to support the deployment, monitoring, and maintenance of new and existing suite of data quality controls...Full timePart timeLocal area- ...Senior Risk Analyst Immediate need for a talented Senior Risk Analyst with experience in the Banking & Financial Industry. This is a 06+ Months Contract opportunity with long-term potential and is located in McLean, VA. Please review the job description below. Key...Contract workImmediate start
- ...Capital One is seeking a Senior Analyst in the Balance Sheet Management group to support Interest Rate Risk Management (IRR) analytics. You will develop analyses, build dashboards, and automate data workflows to evaluate IRR and FX positions, guiding strategic risk decisions...
- Key Responsibilities: Execute design assessments on assigned controls. Follow enterprise guidelines and accepted sampling techniques to select appropriate samples for testing. Execute control performance testing on assigned controls. Document analysis,...
$111.2k - $126.9k
...teams to implement new products for Treasury, develop new capabilities, and deliver high quality data. We are looking for a Senior Analyst to work with the team and Agile pod in delivering cloud-based solutions for the overall business intent through close collaboration...Full timePart timeLocal area$98k - $148k
Freddie Mac seeks an experienced individual contributor in operational risk management to help manage non-financial risks effectively. You will be responsible for identifying risks, preparing assessments, and supporting oversight activities. Ideal candidates possess 5-...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!


