Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Governance, Risk & Compliance (GRC) Analyst

SkyePoint Decisions

SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider headquartered in Dulles, Virginia with operations across the U.S. We provide innovative enterprise-wide solutions as well as targeted services addressing the complex challenges faced by our federal government clients. Our focus is on enabling our clients to deliver their mission most efficiently and effectively - anytime, anywhere, securely. We combine technical expertise, mission awareness, and an empowered workforce to produce meaningful results.

This is a contingent position based on contract win.

SkyePoint Decisions is seeking a Governance, Risk & Compliance (GRC) Analyst to support a cybersecurity program and compliance initiatives by managing governance processes, risk management activities, policy compliance efforts, and audit readiness programs. The GRC Analyst serves as a key contributor to ensuring information systems and cybersecurity operations comply with Federal regulations, NIST standards and HHS policies.

The position supports an integrated cybersecurity risk and compliance program by linking risks, POA&Ms, vulnerabilities, audit findings, incidents, corrective actions, and governance reporting to support executive decision-making and authorization activities. Collaborates with cybersecurity teams, system owners, ISSOs, auditors, and leadership to identify risks, monitor compliance, maintain governance documentation, and support continuous improvement of the organization's cybersecurity posture.

This position is fully remote.


Responsibilities:

  • Support governance and compliance activities within GRC platforms.
  • Maintain compliance records, risks, findings, and corrective action tracking.
  • Ensure data accuracy and completeness within governance systems.
  • Assist users with governance workflows and compliance processes.
  • Generate reports and metrics from GRC tools and repositories.
  • Support development, maintenance, and implementation of cybersecurity policies, procedures, standards, and guidelines.
  • Assist in mapping organizational controls to Federal cybersecurity requirements and frameworks.
  • Maintain governance documentation and standards repositories.
  • Ensure policies and procedures remain aligned with Federal requirements.
  • Support policy reviews, updates, and compliance assessments.
  • Maintain and update cybersecurity risk registers.
  • Perform risk identification, analysis, and tracking activities.
  • Support risk assessments and risk mitigation planning.
  • Monitor remediation activities for identified risks and control deficiencies.
  • Develop and maintain cybersecurity compliance metrics and reporting.
  • Support creation of executive dashboards and compliance scorecards.
  • Analyze program performance indicators and identify trends.


Required Qualifications:

  • Bachelor's degree in Cybersecurity, Information Systems, Information Assurance, Business Administration, or a related field.
  • Minimum 5 years of experience in cybersecurity governance, risk management, compliance, audit support, or information assurance.
  • Experience supporting Federal cybersecurity programs.
  • Knowledge of:


    • NIST Cybersecurity Framework (CSF)
    • NIST Risk Management Framework (RMF)
    • NIST SP 800-53 Rev. 5
    • FISMA
    • Federal cybersecurity compliance requirements


  • Experience conducting compliance reviews, risk assessments, or audit preparation activities.
  • Strong analytical, organizational, and written communication skills.
  • U.S. Citizenship required.
  • Ability to obtain and maintain a Public Trust.


Preferred Qualifications:

  • One or more of the following certifications:
    • CGRC (formerly CAP)
    • CRISC
    • CISA
    • CISSP
    • CISM
    • Security+
    • Certified in Governance, Risk and Compliance (GRC)




  • Experience supporting NIH, HHS, or other Federal civilian agencies.
  • Experience with governance and compliance platforms such as:


    • ServiceNow GRC
    • Archer
    • eMASS
    • Xacta



  • Experience supporting FISMA audits and OIG assessments.
  • Knowledge of Zero Trust Architecture and Federal cybersecurity modernization initiatives.
  • Experience developing executive-level cybersecurity reporting and dashboards.
  • Familiarity with privacy compliance requirements, including PTAs and PIAs.


Compensation:

Salary Range: $80,000 - $100,00

The SkyePoint Decisions salary range for this position is a general guideline only. It represents an estimated range for this position and is just one piece of our total compensation package.

Salary at SkyePoint is determined by various factors, including but not limited to location, work schedule, the candidate's combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability, market data and business considerations.

In addition to a competitive salary, SkyePoint offers benefits including a certification incentive program, PTO, floating federal holiday options, several insurance options including HMO and High Deductible plans with Health Savings Accounts [HSAs], Flex Spending Accounts [FSAs], Full Dental Plans, Vision, ST/LT Disability, Life Insurance, and 401k matched.

What We Can Offer You:

  • At SkyePoint, we go B.I.G. (beginning in GRATITUDE) by recognizing all we have and giving back to our employees, families, and communities. It instills a positive mindset that permeates all we do. By beginning in gratitude, SkyePoint can continue to spread living in gratitude each day.
  • Great Benefits: Several insurance options including HMO and High Deductible plans with Health Savings Accounts [HSAs], Flex Spending Accounts [FSAs], Full Dental Plans, ST/LT Disability, Life Insurance, floating federal holiday options, and 401k matched
  • Certificate Incentive Program: To promote professional development, we recognize and reward employees who obtain new certifications aligned with business needs.
  • Flexible Work Environment


SkyePoint Decisions is an established ISO 9001:2015 and ISO/IEC 27001:2013 certified small business and appraised at CMMI Level 3 for Services and Development. We possess a common vision of excellence and foster a collaborative team culture built upon individual performance and accountability. We invest in our people and systems to create value for our clients. It is the SkyePoint Way. We are grateful for the opportunity to work with exceptional people and give back to the communities we serve. Our employees value the flexibility at SkyePoint that allows them to balance quality work and their personal lives.

SkyePoint Decisions is a participating E-Verify Employer.

U.S. Citizenship is required for most positions.

Equal Opportunity Employer/Veterans/Disabled.

CCPA Disclosure Notice Here

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Governance, Risk & Compliance (GRC) Analyst in Bethesda, MD vacancy
  • Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the complex landscape of cybersecurity compliance and risk management. You will work directly with clients to assess their... 
    Suggested
    Full time
    Remote work

    Districttechgroup

    Washington DC
    3 days ago
  •  ...Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands-on experience in cybersecurity, compliance, and risk management. The internship... 
    Suggested
    Full time
    Internship

    Ruleset Security

    Arlington, VA
    3 days ago
  •  ...Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands‑on experience in cybersecurity, compliance, and risk management. The internship... 
    Suggested
    Full time
    Internship
    Remote work

    Ruleset Security

    Arlington, VA
    2 days ago
  •  ...Job Description Job Description JUNIOR GRC ANALYST ROCKVILLE, MD - HYBRID LONG TERM CONTRACT SEEKING SOMEONE WHO HAS...  ...Analyst supports the administration of Information Security Governance, Risk, and Compliance programs, including policy exception management and... 
    Suggested
    Long term contract
    Internship

    System One

    Rockville, MD
    3 days ago
  • A cybersecurity compliance consulting firm is looking for a GRC Analyst to help organizations manage cybersecurity compliance and risk. This fully remote position involves conducting assessments, developing security policies, supporting compliance audits, and collaborating... 
    Suggested
    Remote job

    Districttechgroup

    Washington DC
    3 days ago
  • $146k - $194k

     ...years. ABOUT THE JOB As a Senior Compliance Analyst, you will serve as a key leader...  ...enterprise. Alongside the Cybersecurity Risk and Compliance Team, you will work...  ...Author and optimize high-quality Governance, Risk, and Compliance (GRC) documentation, including System... 
    Full time
    Work experience placement
    Immediate start

    Anduril Industries

    Washington DC
    4 days ago
  • $100k - $120k

     ...Overview The Compliance and Risk Analyst assists the IT Program Manager in the registration of all Application and Database Management Systems (DADMS) for inclusion into the investment portfolio. Responsibilities Use the IT portfolio tool to manage the... 
    Temporary work
    Work at office
    Immediate start
    Flexible hours
    Shift work

    Integral Services Company

    Falls Church, VA
    4 days ago
  • Job Title: Risk and Compliance Systems Analyst (Oracle ERP Fusion and RMC) Location: Vienna, VA Pay Rate: open to W2 and established 1099's Work Model: Hybrid, onsite 3 days a week Position type: multiyear contract We are looking for an Oracle ERP Fusion security and controls... 
    Contract work
    For contractors
    Local area
    3 days per week

    System One

    Vienna, VA
    4 days ago
  • Risk and Compliance Systems Analyst - Apex Systems Job #: 3015294 Site: Headquarters (HDQ) Business Unit: Fin Tech & Prod Mgmt Description: Hybrid - 3 days per week on site at HDQ (Vienna, VA) preferred; team will consider GPO (Pensacola, FL) for the right candidate.... 
    For contractors
    3 days per week

    Apex Systems

    Merrifield, VA
    1 day ago
  • $117.3k - $133.9k

     ...Overview The Compliance Tester III (Principal Associate) performs a key second line of defense role, to help ensure business processes are...  ...Testing team. The Compliance Tester III will execute risk-based control reviews under the leadership of a team lead, for... 
    Full time
    Part time
    Work at office
    Local area

    kozmetickesluzby.vecnakraska.sk - Jobboard

    McLean, VA
    16 hours ago
  •  ...Zero Trust Analyst Zero Trust Analyst Location: Arlington, VA (On-Site) Citizenship...  ...critical cybersecurity support to U.S. Government agencies and critical infrastructure...  ...to support cybersecurity governance, risk, compliance, and modernization activities in... 
    Contract work
    For contractors

    Argo Cyber Systems

    Arlington, VA
    2 days ago
  •  ...Description Job Description GRC Analyst – Rockville, MD About us...  ...innovation. We serve both government and commercial sectors,...  ...Produce status reports. B. Risk Analysis - Using County-...  ...HIPAA Security Training or Compliance Certificates Preferred experience... 
    Contract work
    For contractors
    Internship
    Work at office

    Creative Information Technology, Inc.

    Falls Church, VA
    8 days ago
  •  ...integrators in the defense and government services industry. We deliver...  ...seeking a highly qualified Risk Mitigation Specialist to support...  ...DCSA FOCI policies to ensure compliance with emplaced mitigation...  ...working with enterprise systems or GRC/IRM tools. Preferred... 
    Contract work
    Work at office
    Worldwide

    SOSi

    Washington DC
    2 days ago
  • $96.5k - $110.1k

     ...Overview Senior Risk Specialist | Retail Bank The Conduct Risk and Sales Practices...  ...Retail Risk MPG (Monitoring, Process, & Governance) mission is a passionate and dynamic...  ...will be working with select business, Compliance, Human Resources and Risk stakeholders to... 
    Permanent employment
    Full time
    Part time
    Work at office
    Local area

    Capital One

    McLean, VA
    a month ago
  •  ...Compliance Data Analyst ProSidian is a Management And Operations Consulting Services firm that focuses...  ...enterprise services/solutions for Risk Management | Compliance | Business...  ...[NSF0098098] candidates with relevant Government And Public Services Sector Experience... 
    Contract work
    H1b
    Work at office

    ProSidian Consulting

    Alexandria, VA
    15 hours ago
  • $164.8k - $188.1k

     ...Data Analyst Manager - Model Risk Office At Capital One, data is at the center of everything we do....  ...driven decision making. The Model Risk Governance - Reporting and Automation team sits...  ...committed to non‑discrimination in compliance with applicable federal, state, and... 
    Full time
    Part time
    Work experience placement
    Work at office
    Local area

    Socket

    McLean, VA
    16 hours ago
  • $90k - $200k

     ...Senior Manager, Investigations, Diligence, and Compliance - Specialist Kroll’s North American Investigations, Diligence and Compliance practice...  ...intelligence, internal (client) investigations, insider risk compliance assessments, consulting projects and forensic matters... 
    Temporary work
    Flexible hours

    Kroll

    Washington DC
    3 days ago
  • $176.97k - $303.37k

     ...Chief Compliance Officer Location : Location US-MD-Bethesda ID 2026-2153 Location : Address 7500 Old Georgetown...  ...Full Time Regular Business Unit Description Risk and Compliance Overview We are a values driven organization... 
    Full time
    Work at office
    Remote work
    Flexible hours

    EagleBank

    Bethesda, MD
    2 days ago
  •  ...Description SAIC is seeking a Cybersecurity Compliance analyst in Arlington, VA. The roles and...  ...technical, and analytical expertise of the Risk Management Framework with knowledge of...  ...non-compliance justifications, preparing government client for non-compliant reporting by... 

    SAIC

    Arlington, VA
    4 days ago
  • $140k - $190k

     ...Security, Risk and Compliance Consultant Washington, District of Columbia, United States WHO WE LOOK...  ...Familiarity or direct experience with GRC/Cybersecurity solutions, tools and...  ...Work or projects with military or federal government agencies in Risk, Compliance or Information... 
    Permanent employment

    SEI

    Washington DC
    2 days ago
  • $85k - $115k

     ...with real insurance data and analytics projects as part of NFP’s Property & Casualty Actuarial team. You’ll work with experienced analysts and actuaries to analyze large datasets, build models and dashboards, automate workflows and translate data into actionable insights... 

    NFP, an Aon company

    Bethesda, MD
    1 day ago
  • $70k - $150k

     ...Investigations Kroll's North American Investigations, Diligence and Compliance - Specialist practice is seeking an Associate Manager based in...  ...and effectiveness of internal controls, performing insider risk compliance assessments, managing projects and resources,... 
    Temporary work
    Interim role
    Flexible hours

    Kroll

    Washington DC
    1 day ago
  •  ...Regulatory Reporting Analyst The Regulatory Reporting team provides governance across all regulatory filings and related obligations globally. The...  ...maintain reporting accuracy Partner with compliance, legal, finance, risk, technology, and trading teams to document requirements... 
    Work at office

    Point72 Private Investments

    Washington DC
    3 days ago
  •  ...Strategic Analysis, Inc. is seeking a SAP Security Risk & Compliance Analyst (TS/SCI w/ CI Poly) to assess and strengthen security posture across...  ..., risk-based decision making, and collaboration with government and contractor teams. Responsibilities include conducting... 
    For contractors

    Strategic Analysis

    Arlington, VA
    16 hours ago
  • $132k - $178k

     ...Enterprise Risk Analyst Denver, CO or Long Beach, CA or Washington...  ...engineering, security, legal, compliance, and operations teams to...  ...Jira, Confluence, enterprise GRC platforms, and MS Project....  ...assessor interactions, and government partner reviews. Qualifications... 
    Permanent employment
    Contract work
    Work at office

    True Anomaly

    Washington DC
    5 days ago
  • $158.6k - $237.8k

     ...applications for the position of Geopolitical Risk Analyst - Maritime and Transnational through...  ...hours. Liaising frequently with government and military counterparts and...  ...this role is listed on this posting in compliance with applicable law. Please note that the... 
    Worldwide
    Relocation
    Overseas
    Visa sponsorship
    Work visa
    Flexible hours

    Chevron

    Washington DC
    4 days ago
  • $120.8k - $137.9k

     ...Principal Risk Specialist As a Principal Risk Associate at Capital One you'll be responsible for working with business partners...  ...across multiple stakeholder groups to ensure documentation of compliance with applicable laws and regulations as relates to International... 
    Full time
    Part time
    Work at office
    Local area

    Capital One

    McLean, VA
    3 days ago
  • $78.9k - $123.3k

     ...detail-oriented cybersecurity compliance professional to support...  ...Action and Milestones (POA&Ms) Risk Assessments Continuous Monitoring...  ...Substitutions are subject to government customer review and approval....  ..., risk, and compliance (GRC) platforms. Knowledge of cloud... 
    Permanent employment
    Full time
    Part time
    Work at office
    Local area
    Remote work

    Noblis

    Washington DC
    3 days ago
  •  ...Predictive Risk Modeler We are seeking an experienced predictive risk modeler to perform risk assessment on FHA multifamily housing portfolio. To perform in this role, the potential candidate will need skills in econometrics, statistical analysis, and modelling.... 

    Aegis Corps

    Arlington, VA
    5 days ago
  • $260k - $365k

    ## Financial Services Regulatory & Compliance Associate (Senior Level)Applyremote type: Onsitelocations: Miami: Atlanta: Washington, D.C....  ...services laws and regulations (e.g., BSA/AML, sanctions, third-party risk management, and consumer compliance). Enforcement experience is... 
    Full time
    Temporary work
    Work at office
    Flexible hours

    Greenberg Traurig

    Washington DC
    16 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Governance, Risk & Compliance (GRC) Analyst. Be the first to apply!