Governance, Risk & Compliance (GRC) Analyst
SkyePoint Decisions
SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider headquartered in Dulles, Virginia with operations across the U.S. We provide innovative enterprise-wide solutions as well as targeted services addressing the complex challenges faced by our federal government clients. Our focus is on enabling our clients to deliver their mission most efficiently and effectively - anytime, anywhere, securely. We combine technical expertise, mission awareness, and an empowered workforce to produce meaningful results.
This is a contingent position based on contract win.
SkyePoint Decisions is seeking a Governance, Risk & Compliance (GRC) Analyst to support a cybersecurity program and compliance initiatives by managing governance processes, risk management activities, policy compliance efforts, and audit readiness programs. The GRC Analyst serves as a key contributor to ensuring information systems and cybersecurity operations comply with Federal regulations, NIST standards and HHS policies.
The position supports an integrated cybersecurity risk and compliance program by linking risks, POA&Ms, vulnerabilities, audit findings, incidents, corrective actions, and governance reporting to support executive decision-making and authorization activities. Collaborates with cybersecurity teams, system owners, ISSOs, auditors, and leadership to identify risks, monitor compliance, maintain governance documentation, and support continuous improvement of the organization's cybersecurity posture.
This position is fully remote.Responsibilities:
- Support governance and compliance activities within GRC platforms.
- Maintain compliance records, risks, findings, and corrective action tracking.
- Ensure data accuracy and completeness within governance systems.
- Assist users with governance workflows and compliance processes.
- Generate reports and metrics from GRC tools and repositories.
- Support development, maintenance, and implementation of cybersecurity policies, procedures, standards, and guidelines.
- Assist in mapping organizational controls to Federal cybersecurity requirements and frameworks.
- Maintain governance documentation and standards repositories.
- Ensure policies and procedures remain aligned with Federal requirements.
- Support policy reviews, updates, and compliance assessments.
- Maintain and update cybersecurity risk registers.
- Perform risk identification, analysis, and tracking activities.
- Support risk assessments and risk mitigation planning.
- Monitor remediation activities for identified risks and control deficiencies.
- Develop and maintain cybersecurity compliance metrics and reporting.
- Support creation of executive dashboards and compliance scorecards.
- Analyze program performance indicators and identify trends.
Required Qualifications:
- Bachelor's degree in Cybersecurity, Information Systems, Information Assurance, Business Administration, or a related field.
- Minimum 5 years of experience in cybersecurity governance, risk management, compliance, audit support, or information assurance.
- Experience supporting Federal cybersecurity programs.
- Knowledge of:
- NIST Cybersecurity Framework (CSF)
- NIST Risk Management Framework (RMF)
- NIST SP 800-53 Rev. 5
- FISMA
- Federal cybersecurity compliance requirements
- Experience conducting compliance reviews, risk assessments, or audit preparation activities.
- Strong analytical, organizational, and written communication skills.
- U.S. Citizenship required.
- Ability to obtain and maintain a Public Trust.
Preferred Qualifications:
- One or more of the following certifications:
- CGRC (formerly CAP)
- CRISC
- CISA
- CISSP
- CISM
- Security+
- Certified in Governance, Risk and Compliance (GRC)
- Experience supporting NIH, HHS, or other Federal civilian agencies.
- Experience with governance and compliance platforms such as:
- ServiceNow GRC
- Archer
- eMASS
- Xacta
- Experience supporting FISMA audits and OIG assessments.
- Knowledge of Zero Trust Architecture and Federal cybersecurity modernization initiatives.
- Experience developing executive-level cybersecurity reporting and dashboards.
- Familiarity with privacy compliance requirements, including PTAs and PIAs.
Compensation:
Salary Range: $80,000 - $100,00
The SkyePoint Decisions salary range for this position is a general guideline only. It represents an estimated range for this position and is just one piece of our total compensation package.
Salary at SkyePoint is determined by various factors, including but not limited to location, work schedule, the candidate's combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability, market data and business considerations.
In addition to a competitive salary, SkyePoint offers benefits including a certification incentive program, PTO, floating federal holiday options, several insurance options including HMO and High Deductible plans with Health Savings Accounts [HSAs], Flex Spending Accounts [FSAs], Full Dental Plans, Vision, ST/LT Disability, Life Insurance, and 401k matched.
What We Can Offer You:
- At SkyePoint, we go B.I.G. (beginning in GRATITUDE) by recognizing all we have and giving back to our employees, families, and communities. It instills a positive mindset that permeates all we do. By beginning in gratitude, SkyePoint can continue to spread living in gratitude each day.
- Great Benefits: Several insurance options including HMO and High Deductible plans with Health Savings Accounts [HSAs], Flex Spending Accounts [FSAs], Full Dental Plans, ST/LT Disability, Life Insurance, floating federal holiday options, and 401k matched
- Certificate Incentive Program: To promote professional development, we recognize and reward employees who obtain new certifications aligned with business needs.
- Flexible Work Environment
SkyePoint Decisions is an established ISO 9001:2015 and ISO/IEC 27001:2013 certified small business and appraised at CMMI Level 3 for Services and Development. We possess a common vision of excellence and foster a collaborative team culture built upon individual performance and accountability. We invest in our people and systems to create value for our clients. It is the SkyePoint Way. We are grateful for the opportunity to work with exceptional people and give back to the communities we serve. Our employees value the flexibility at SkyePoint that allows them to balance quality work and their personal lives.
SkyePoint Decisions is a participating E-Verify Employer.
U.S. Citizenship is required for most positions.
Equal Opportunity Employer/Veterans/Disabled.
CCPA Disclosure Notice Here
- Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the complex landscape of cybersecurity compliance and risk management. You will work directly with clients to assess their...SuggestedFull timeRemote work
- ...Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands-on experience in cybersecurity, compliance, and risk management. The internship...SuggestedFull timeInternship
- ...Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands‑on experience in cybersecurity, compliance, and risk management. The internship...SuggestedFull timeInternshipRemote work
- ...Job Description Job Description JUNIOR GRC ANALYST ROCKVILLE, MD - HYBRID LONG TERM CONTRACT SEEKING SOMEONE WHO HAS... ...Analyst supports the administration of Information Security Governance, Risk, and Compliance programs, including policy exception management and...SuggestedLong term contractInternship
- A cybersecurity compliance consulting firm is looking for a GRC Analyst to help organizations manage cybersecurity compliance and risk. This fully remote position involves conducting assessments, developing security policies, supporting compliance audits, and collaborating...SuggestedRemote job
$146k - $194k
...years. ABOUT THE JOB As a Senior Compliance Analyst, you will serve as a key leader... ...enterprise. Alongside the Cybersecurity Risk and Compliance Team, you will work... ...Author and optimize high-quality Governance, Risk, and Compliance (GRC) documentation, including System...Full timeWork experience placementImmediate start$100k - $120k
...Overview The Compliance and Risk Analyst assists the IT Program Manager in the registration of all Application and Database Management Systems (DADMS) for inclusion into the investment portfolio. Responsibilities Use the IT portfolio tool to manage the...Temporary workWork at officeImmediate startFlexible hoursShift work- Job Title: Risk and Compliance Systems Analyst (Oracle ERP Fusion and RMC) Location: Vienna, VA Pay Rate: open to W2 and established 1099's Work Model: Hybrid, onsite 3 days a week Position type: multiyear contract We are looking for an Oracle ERP Fusion security and controls...Contract workFor contractorsLocal area3 days per week
- Risk and Compliance Systems Analyst - Apex Systems Job #: 3015294 Site: Headquarters (HDQ) Business Unit: Fin Tech & Prod Mgmt Description: Hybrid - 3 days per week on site at HDQ (Vienna, VA) preferred; team will consider GPO (Pensacola, FL) for the right candidate....For contractors3 days per week
$117.3k - $133.9k
...Overview The Compliance Tester III (Principal Associate) performs a key second line of defense role, to help ensure business processes are... ...Testing team. The Compliance Tester III will execute risk-based control reviews under the leadership of a team lead, for...Full timePart timeWork at officeLocal area- ...Zero Trust Analyst Zero Trust Analyst Location: Arlington, VA (On-Site) Citizenship... ...critical cybersecurity support to U.S. Government agencies and critical infrastructure... ...to support cybersecurity governance, risk, compliance, and modernization activities in...Contract workFor contractors
- ...Description Job Description GRC Analyst – Rockville, MD About us... ...innovation. We serve both government and commercial sectors,... ...Produce status reports. B. Risk Analysis - Using County-... ...HIPAA Security Training or Compliance Certificates Preferred experience...Contract workFor contractorsInternshipWork at office
- ...integrators in the defense and government services industry. We deliver... ...seeking a highly qualified Risk Mitigation Specialist to support... ...DCSA FOCI policies to ensure compliance with emplaced mitigation... ...working with enterprise systems or GRC/IRM tools. Preferred...Contract workWork at officeWorldwide
$96.5k - $110.1k
...Overview Senior Risk Specialist | Retail Bank The Conduct Risk and Sales Practices... ...Retail Risk MPG (Monitoring, Process, & Governance) mission is a passionate and dynamic... ...will be working with select business, Compliance, Human Resources and Risk stakeholders to...Permanent employmentFull timePart timeWork at officeLocal area- ...Compliance Data Analyst ProSidian is a Management And Operations Consulting Services firm that focuses... ...enterprise services/solutions for Risk Management | Compliance | Business... ...[NSF0098098] candidates with relevant Government And Public Services Sector Experience...Contract workH1bWork at office
$164.8k - $188.1k
...Data Analyst Manager - Model Risk Office At Capital One, data is at the center of everything we do.... ...driven decision making. The Model Risk Governance - Reporting and Automation team sits... ...committed to non‑discrimination in compliance with applicable federal, state, and...Full timePart timeWork experience placementWork at officeLocal area$90k - $200k
...Senior Manager, Investigations, Diligence, and Compliance - Specialist Kroll’s North American Investigations, Diligence and Compliance practice... ...intelligence, internal (client) investigations, insider risk compliance assessments, consulting projects and forensic matters...Temporary workFlexible hours$176.97k - $303.37k
...Chief Compliance Officer Location : Location US-MD-Bethesda ID 2026-2153 Location : Address 7500 Old Georgetown... ...Full Time Regular Business Unit Description Risk and Compliance Overview We are a values driven organization...Full timeWork at officeRemote workFlexible hours- ...Description SAIC is seeking a Cybersecurity Compliance analyst in Arlington, VA. The roles and... ...technical, and analytical expertise of the Risk Management Framework with knowledge of... ...non-compliance justifications, preparing government client for non-compliant reporting by...
$140k - $190k
...Security, Risk and Compliance Consultant Washington, District of Columbia, United States WHO WE LOOK... ...Familiarity or direct experience with GRC/Cybersecurity solutions, tools and... ...Work or projects with military or federal government agencies in Risk, Compliance or Information...Permanent employment$85k - $115k
...with real insurance data and analytics projects as part of NFP’s Property & Casualty Actuarial team. You’ll work with experienced analysts and actuaries to analyze large datasets, build models and dashboards, automate workflows and translate data into actionable insights...$70k - $150k
...Investigations Kroll's North American Investigations, Diligence and Compliance - Specialist practice is seeking an Associate Manager based in... ...and effectiveness of internal controls, performing insider risk compliance assessments, managing projects and resources,...Temporary workInterim roleFlexible hours- ...Regulatory Reporting Analyst The Regulatory Reporting team provides governance across all regulatory filings and related obligations globally. The... ...maintain reporting accuracy Partner with compliance, legal, finance, risk, technology, and trading teams to document requirements...Work at office
- ...Strategic Analysis, Inc. is seeking a SAP Security Risk & Compliance Analyst (TS/SCI w/ CI Poly) to assess and strengthen security posture across... ..., risk-based decision making, and collaboration with government and contractor teams. Responsibilities include conducting...For contractors
$132k - $178k
...Enterprise Risk Analyst Denver, CO or Long Beach, CA or Washington... ...engineering, security, legal, compliance, and operations teams to... ...Jira, Confluence, enterprise GRC platforms, and MS Project.... ...assessor interactions, and government partner reviews. Qualifications...Permanent employmentContract workWork at office$158.6k - $237.8k
...applications for the position of Geopolitical Risk Analyst - Maritime and Transnational through... ...hours. Liaising frequently with government and military counterparts and... ...this role is listed on this posting in compliance with applicable law. Please note that the...WorldwideRelocationOverseasVisa sponsorshipWork visaFlexible hours$120.8k - $137.9k
...Principal Risk Specialist As a Principal Risk Associate at Capital One you'll be responsible for working with business partners... ...across multiple stakeholder groups to ensure documentation of compliance with applicable laws and regulations as relates to International...Full timePart timeWork at officeLocal area$78.9k - $123.3k
...detail-oriented cybersecurity compliance professional to support... ...Action and Milestones (POA&Ms) Risk Assessments Continuous Monitoring... ...Substitutions are subject to government customer review and approval.... ..., risk, and compliance (GRC) platforms. Knowledge of cloud...Permanent employmentFull timePart timeWork at officeLocal areaRemote work- ...Predictive Risk Modeler We are seeking an experienced predictive risk modeler to perform risk assessment on FHA multifamily housing portfolio. To perform in this role, the potential candidate will need skills in econometrics, statistical analysis, and modelling....
$260k - $365k
## Financial Services Regulatory & Compliance Associate (Senior Level)Applyremote type: Onsitelocations: Miami: Atlanta: Washington, D.C.... ...services laws and regulations (e.g., BSA/AML, sanctions, third-party risk management, and consumer compliance). Enforcement experience is...Full timeTemporary workWork at officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Governance, Risk & Compliance (GRC) Analyst. Be the first to apply!

