GRC Analyst
$62k - $141kBooz Allen Hamilton
GRC Analyst
The Opportunity: Cyber threats evolve constantly. In this role, you'll turn complex risk into clear action by supporting Risk Management Framework (RMF) activities and driving Assessment and Authorization (A&A) packages through an Authorization to Operate (ATO). You'll partner with engineering and mission teams to scope controls, assess risk, remediate gaps, and sustain continuous monitoring so systems remain secure and compliant. Join us. The world can't wait.
You Have:
- 3+ years of experience within cyber risk management or security compliance functions
- Experience applying NIST RMF across categorization, control selection or implementation, assessment, authorization, and continuous monitoring
- Experience supporting A&A efforts and coordinating ATO decisions with authorizing officials
- Experience performing security control assessments and producing artifacts such as Security Assessment Reports (SAR) and Plans of Action and Milestones (POA&Ms)
- Experience developing and maintaining security documentation, including System Security Plans (SSP) and control implementation statements
- Knowledge of NIST SP 800-53 Rev.5 control families and tailoring controls to impact levels
- Knowledge of FISMA processes supporting RMF and authorization decisions
- Ability to translate technical findings into risk statements and remediation recommendations aligned to mission and business priorities, plan and execute continuous monitoring (ConMon), track residual risk, and drive closure of POA&Ms
- Public Trust
- Bachelor's degree and 3+ years of experience in information security, or 5+ years of experience in information security in lieu of a degree
Nice If You Have:
- Experience supporting A&A activities at health or research-focused government entities
- Experience communicating complex security concepts clearly to non-technical stakeholders and senior leaders
- Experience producing concise A&A documentation and executive-ready summaries
- Knowledge of structured writing and plain-language techniques for technical documentation
- Knowledge of stakeholder analysis and change management to drive adoption of security recommendations
- Ability to write crisply, edit meticulously, and proofread to ensure consistency across artifacts
- Ability to facilitate working sessions, build consensus, and present recommendations confidently
- Master's degree
Vetting: Applicants selected will be subject to a government investigation and may need to meet eligibility requirements of the U.S. government client; Public Trust determination is required.
Compensation
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.
Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $62,000.00 to $141,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date.
Identity Statement
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.
Candidate AI Usage Policy
AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided.
Work Model Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.
- Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.
- Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.
- Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.
$62k - $141k
GRC AnalystThe Opportunity:Cyber threats evolve constantly. In this role, you’ll turn complex risk into clear action by supporting Risk Management Framework (RMF) activities and driving Assessment and Authorization (A&A) packages through an Authorization to Operate (ATO...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work- ...Governance, Risk & Compliance (GRC) Analyst Washington D.C. CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage—domain dominance. The company's products are powered by Coherent Distributed Networks (CDN™...SuggestedContract workFor subcontractorCasual workRelocation package
- ...experience with full cycle Risk Management processes, including cATO, Risk Analysis, Risk Register functional application via Service Now IRM/GRC environment. Significant experience with Service Now ecosystem (concentrate on IRM), including cross-functional deployments,...Suggested
$120k - $145k
...build the future of identity with a team that holds a high bar for itself — keep reading. Overview Socure is seeking an Analyst, GRC – Public Sector to own the hands-on execution of the company’s governance, risk, and compliance operations for its public sector...SuggestedPermanent employmentFull timeContract work$99k - $225k
Enterprise Cybersecurity GRC Governance AnalystThe Opportunity: The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an experienced Information System Security Officer (ISSO) to bridge the gap between high-level policy and technical...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work- Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the complex landscape of cybersecurity compliance and risk management. You will work directly with clients to assess their...Full timeRemote work
- Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands-on experience in cybersecurity, compliance, and risk management. The internship...Full timeInternship
- A cybersecurity compliance consulting firm is looking for a GRC Analyst to help organizations manage cybersecurity compliance and risk. This fully remote position involves conducting assessments, developing security policies, supporting compliance audits, and collaborating...Remote job
- Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands‑on experience in cybersecurity, compliance, and risk management. The internship...Remote jobFull timeInternship
- ...Job Description Job Description JUNIOR GRC ANALYST ROCKVILLE, MD - HYBRID LONG TERM CONTRACT SEEKING SOMEONE WHO HAS WORKED WITH THE SERVICENOW GRC APPLICATION Overview: ~ The GRC Analyst supports the administration of Information Security Governance, Risk,...Long term contractInternship
$117.2k - $176.7k
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.Job CategoryEnterprise Technology & InfrastructureJob DetailsAbout SalesforceSalesforce is the #1 AI CRM, where humans with...Full time$77.2k - $96.5k
...Time: Be the Linchpin of Security and Compliance at WWT As an Information Security (InfoSec) Governance, Risk, and Compliance (GRC) Analyst within Audit and Compliance, you will play a pivotal role in ensuring that WWT’s information security practices not only align...Full timeContract workPart timeRemote workFlexible hoursShift work- Marriott International (MI) is transforming its global network technology to offer the most advanced, most secure, most reliable, and most scalable networks in the hospitality industry .We are seeking a highly skilled and motivated professional to lead our Network Observability...Full timeTemporary workRemote workFlexible hours
$100k - $140k
About Us: ProShares now offers one of the largest lineups of ETFs, with over $100 billion in assets. The company is a leader in strategies such as crypto, dividend growth, interest rate hedged bond and geared (leveraged and inverse) ETF investing. ProShares continues to...- The Baldwin Group is an award-winning entrepreneur-led and inspired insurance brokerage firm delivering expertly crafted Commercial Insurance and Risk Management, Private Insurance and Risk Management, Employee Benefits and Benefit Administration, Asset and Income Protection...Full timeContract workWork at office
- Job SummaryThe Analyst, AI Model Governance is responsible for supporting the oversight and compliance of AI models within the organization. This role tracks model inventories, conducts risk assessments, and prepares documentation for audits and regulatory inquiries. The...Full timeWork at officeRemote workFlexible hours
$152.66k - $261.71k
...SQL, SAS, or similar analytical toolsProfessional certifications such as FRM (Financial Risk Manager) or CFA (Chartered Financial Analyst) are advantageousDon't meet all the requirements? We encourage you to still apply if you think you are the right person to join our...Full timeRemote workFlexible hours$43k - $44.63k
About DataScan by Solifi: Headquartered in Alpharetta, Georgia, DataScan stands at the forefront of delivering cutting-edge wholesale asset financing and inventory risk management solutions. Our commitment lies in empowering lenders to efficiently oversee their operations...Temporary workLive inImmediate startFlexible hoursNight shift$69.84k - $108.85k
Overview We are a values driven organization putting Relationships FIRST . EagleBank (NASDAQ - EGBN) is focused on being Flexible, Involved, Responsive, Strong, and Trusted . By prioritizing meaningful connections with our customers, employees, and shareholders, we relentlessly...Work at officeLocal areaRemote workFlexible hours$176.97k - $303.37k
Overview We are a values driven organization putting Relationships FIRST. EagleBank (NASDAQ - EGBN) is focused on being Flexible, Involved, Responsive, Strong, and Trusted. By prioritizing meaningful connections with our customers, employees, and shareholders, we relentlessly...Full timeWork at officeRemote workFlexible hours$50 per hour
Requisition ID: 11664ERP Eligible?: YesERP amount: $50 LMRecognitionRelocation: PossibleType: ExemptShift: 1Clearance Prior to Start: NoneFinal Clearance: NonePay Transparency: $100,200.00 - $186,200.00Experience Level: Experienced ProfessionalFT/PT/Casual: FullTimeDepartment...Full timeTemporary workWork experience placementCasual workLocal areaFlexible hours$73.8k - $130.18k
...candidates desiring new skillsets, willing to transform processes, dive into analyses to solve challenges and grow. Our risk management analysts provide comprehensive support for Lockheed Martin's corporate insurance programs and offers general risk management assistance to...Full timeTemporary workPart timeWork experience placementWork at officeRemote workFlexible hours2 days per week$120k - $150k
Competitive Power Ventures, Inc. (“CPV”), with headquarters in Silver Spring, MD, and an office in Braintree, MA is a leading clean energy company built around the belief that progressive companies can be powerful leaders in creating a better world. CPV is looking for a...Temporary workWork at officeLocal areaFlexible hours- ...Information Security (OIT/OIS) program covering enterprise cybersecurity architecture and engineering. We are seeking Risk and Compliance Analysts to own the risk, compliance, and supply chain reporting spine of the program.Program: VA Cybersecurity Architecture and...Full timeContract workInterim roleWork at officeRemote work
- Company DescriptionProSidian is a Management And Operations Consulting Services firm that focuses on providing value to clients through tailored solutions based on industry-leading practices. ProSidian provides enterprise services/solutions for Risk Management | Compliance...Full timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
- Kroll’s North American Investigations, Diligence and Compliance practice is seeking a Senior Manager based in the U.S. This is a wide-ranging role in the Financial Investigations team. The Senior Manager will develop and manage investigations and consulting cases, including...Temporary work
- Company DescriptionProSidian is a Management and Operations Consulting Services Firm focusing on providing value to clients through tailored solutions based on industry leading practices. ProSidian services focus on the broad spectrum of Risk Management, Compliance, Business...Contract workFor contractorsWork at officeFlexible hours
- R&D Security and Supply Chain Risk Advisor Advanced Resource Technologies is currently recruiting for a R&D Security and Supply Chain Risk Advisor to support the ARPA-H. This position is full-time, exempt. Start date is immediate upon selection and public trust clearance...Full timeWork at officeImmediate start
- Global Solutions Network Inc is seeking a Regulatory Document Coordinator to support NIH. The role involves managing SOPs, WIs, and training modules, ensuring proper version control, approvals, and controlled distribution within the DFOM/BSL environments. Candidate should...
- The Compliance Coo rdinator is responsible for ensuring compliance with all affordable housing program requirements, including LIHTC, HUD, and other applicable regulatory programs. This position supports resident eligibility, recertification processes, reporting requirements...Temporary workWork at officeImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!



