Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Governance, Risk & Compliance (GRC) Lead, Federal

$158k - $184k

Mosaic

Backed by leading Silicon Valley investors, Peregrine helps public safety organizations, state and local and governments, federal agencies, and private-sector institutions address society’s challenges with unprecedented speed and accuracy. Our AI-enabled platform turns siloed and disconnected data into operational intelligence — instantly surfacing mission-critical information to empower better, faster decisions that improve outcomes at every touchpoint. Today Peregrine supports hundreds of customers across 30+ states and two countries, serving more than 125 million people — and we’re amplifying our impact as we expand into the enterprise and internationally. Our Team At Peregrine, we build software to power critical decision-making for public safety and emergency response organizations. These organizations use our technology to protect lives, protect property, and deliver their best service to the public. We are motivated to help institutions solve their hardest problems through better decision-making. We are passionate about creating cutting-edge, highly scalable data platforms that enable organizations to transform the way they interact with their data. As a team of service-oriented entrepreneurs, we trust each other, help each other, and dive into challenges together. We each strive to be empathetic, curious, inclusive, brave, and exceptional in our execution. Our customers are our partners; we listen to their needs, learn from their experiences, and develop effective software solutions to help them achieve transformational outcomes for their communities. Further, our team is advised by leading experts and practitioners in emergency management, justice, and civil liberties. These experts ensure we develop technology that is both operationally effective and trust-enhancing. Peregrine helps public safety organizations, state and local governments, federal agencies, and private-sector institutions turn complex and disconnected data into operational intelligence. Our platform supports mission-critical decisions in environments where security, availability, data protection, and customer trust are imperative. As Peregrine expands our work with federal customers, we are building the security and compliance capabilities necessary to operate some of our most sensitive deployments. The Role We are looking for a senior Governance, Risk, and Compliance leader to own Peregrine's FedRAMP High program and establish the security and compliance foundation required to support Department of War (DoW) deployments at DoD Impact Level (IL) 4, IL5, and IL6, ICD 503 accreditation for Top Secret environments, and agency-specific system authorizations. This is not a generalist compliance or audit-support role. You will translate federal and defense requirements into implementable technical and operational controls and work across Security, Engineering, Product, Legal, Federal Deployment, and GTM to guide those controls through assessment, authorization, and continuous operation as Peregrine's federal business evolves. Clearance and eligibility. You currently hold, or are able to obtain, an active U.S. security clearance (required), and are based in Washington, D.C. Our Washington, D.C. office is located in the Dupont Circle neighborhood, and this role is expected to be hybrid, with 4 in-office days per week. What You’ll Do Own Peregrine's FedRAMP High authorization program — sustaining and expanding our existing ATO through continuous monitoring, remediation, and reauthorization, including Peregrine's transition from FedRAMP Rev. 5 toward applicable FedRAMP 20x requirements. Translate FedRAMP, NIST, federal agency, DoW and Intelligence Community requirements into technical and operational controls and establish the control architecture necessary to support IL4, IL5, and ultimately IL6 deployments alongside ICD 503 environments. Lead agency-specific system authorizations, from initial engagement through ATO issuance and ongoing sponsorship. Partner with Security and Infrastructure Engineering to evaluate system boundaries, Identity, Credential, and Access Management (ICAM), network security, encryption and key management, logging, vulnerability and configuration management, hardening, supply-chain security, and incident response against federal and DoW requirements. Lead authorization artifacts, control implementation statements, evidence, assessment responses, and continuous-monitoring deliverables while ensuring documented controls are supported by architecture, configuration, automation, procedures, and operating evidence. Drive assessment findings and control gaps to closure and develop scalable control ownership, evidence collection, monitoring, and compliance-automation practices that improve the efficiency and quality of Peregrine's assurance program. Ensure external security representations accurately reflect implemented controls and evidence, and advise Peregrine's Federal and customer-facing teams during procurements, technical evaluations, security reviews, and customer engagements. About You You are comfortable operating as a senior individual contributor with broad organizational influence and can drive programs across engineering, security, product, legal, operations, and customer-facing teams. You approach compliance as an engineering and risk-management discipline and are willing to challenge weak implementations, unsupported assertions, and inadequate evidence. You can turn complex or evolving requirements into defensible implementation strategies and communicate technical security issues clearly to engineers, executives, assessors, customers, and government security officials. Preferred Certifications 10+ years of experience in information security, GRC, security assurance, or cybersecurity risk management, including personally leading significant portions of obtaining and maintaining FedRAMP High authorization for a cloud service provider (CSP) with one or more cloud service offerings (CSOs). Expertise in FedRAMP program management and federal Risk Management Framework (RMF) implementation through assessment, authorization, and remediation, plus at least two years of continuous monitoring — including 3PAO or government assessor engagement, authorization-package development, POA&M and accepted-weakness remediation, and agency or Authorizing Official engagement. Working knowledge of NIST SP 800-53 and SP 800-37, FedRAMP, the DoD Cloud Computing Security Requirements Guide, DoD cybersecurity risk management (RMF and the successor Cybersecurity Risk Management Construct), DISA SRGs/STIGs, applicable FIPS requirements, control overlays, and federal assessment and authorization practices. Technical understanding of cloud security architecture, including hands-on experience with AWS or AWS GovCloud, Kubernetes or containerized environments, Infrastructure as Code, and modern CI/CD. Experience designing sustainable compliance operations, including control ownership, evidence and weakness management, continuous monitoring, change management, and machine-readable assurance evidence such as OSCAL. Experience advising customer-facing teams through federal procurements, technical evaluations, and customer security reviews. An active or recently active U.S. government security clearance and U.S. citizenship. Bonus Points Direct experience establishing and maintaining DoD IL4, IL5, or IL6 environments. Experience with ICD 503 accreditation and the authorization of National Security Systems, classified systems, or cross-domain solutions. Experience supporting federal or defense customers in environments involving CUI or other sensitive government information. CISSP, CISA, CGRC, CISM, CCSP, or comparable security certifications. Salary Range: $158,000 - 184,000, Annually + Benefits + Equity (if applicable) + Bonus (if applicable) Information on the benefits offered is here. Peregrine Technologies is committed to creating an inclusive environment for all employees. We celebrate diversity and are a proud equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. #J-18808-Ljbffr Mosaic

Vacancy posted 7 hours ago
Similar jobs that could be interesting for youBased on the Governance, Risk & Compliance (GRC) Lead, Federal in Washington DC vacancy
  • $158k - $184k

    Washington, D.C. Backed by leading Silicon Valley...  ..., state and local and governments, federal agencies , and private...  ...building the security and compliance capabilities necessary...  ...a senior Governance, Risk, and Compliance leader...  ...information security, GRC, security assurance, or... 
    Suggested
    Contract work
    For contractors
    For subcontractor
    Work at office
    Local area
    Relocation
    Visa sponsorship

    Peregrine Technologies, Inc.

    Washington DC
    4 days ago
  • Peregrine is seeking a senior Governance, Risk, and Compliance leader to own FedRAMP High and establish security foundations for DoD IL4-6 deployments...  ...security clearance and the ability to translate complex federal requirements into implementable controls across Security,... 
    Suggested

    Socket.dev

    Washington DC
    23 hours ago
  • Peregrine is seeking a senior Governance, Risk, and Compliance leader to own the FedRAMP High program and establish the security and compliance foundation...  ...for sensitive environments. You will translate federal and defense requirements into implementable controls, and... 
    Suggested

    Peregrine

    Washington DC
    2 days ago
  •  ...Technologies, Inc. in Washington, DC, is seeking a senior Governance, Risk, and Compliance leader to own FedRAMP High and establish security...  ...DoD IL4-IL6 deployments. This role requires translating federal requirements into implementable controls and guiding across... 
    Suggested

    Peregrine Technologies, Inc.

    Washington DC
    4 days ago
  • Palantir Technologies is seeking a GRC Program Manager to lead governance, risk, and compliance initiatives across Commercial, International, and USG environments. You will design scalable processes, coordinate FedRAMP/SOC 2/ISO 27001 audits, and translate regulatory requirements... 
    Suggested

    Palantir Technologies

    Washington DC
    3 days ago
  • Peregrine Technologies seeks a senior Governance, Risk, and Compliance leader to own the FedRAMP High program and establish security and compliance...  ...accreditation for Top Secret environments. This role translates federal and defense requirements into technical controls and... 

    Mosaic.tech

    Washington DC
    23 hours ago
  •  ...solutions based on industry-leading practices. ProSidian...  ...enterprise services/solutions for Risk Management | Compliance | Business Process | IT...  ..., defense and civilian government, and non-profit organizations...  ...& IT Modernization for Federal science agency HR modernizationThe... 
    Full time
    Contract work
    Temporary work
    For contractors
    H1b
    Work at office
    Flexible hours

    Prosidian Consultng

    Alexandria, VA
    23 hours ago
  • Palantir is seeking a GRC Program Manager to lead governance, risk, and compliance programs across Commercial, International, and US Government businesses. You will partner with compliance engineers, security teams, and developers to scale processes to meet regulatory... 

    Segment (Twilio)

    Washington DC
    3 days ago
  •  ...The successful candidate will provide project management and security expertise, managing a team to ensure compliance and risk management processes align with federal guidelines. Responsibilities include strategic leadership, project scheduling, security assessments, and... 
    Remote job

    Zermount, Inc.

    Arlington, VA
    1 day ago
  • Innovative Management Concepts, Inc. seeks a senior advisor to support federal IT portfolio management, budgeting, governance and decision support for critical national security initiatives. Responsibilities include executive briefings, cost analyses, and coordination... 

    Innovative Management Concepts, Inc.

    Arlington, VA
    1 day ago
  •  ...delivery of mission-critical services within a federal IT and cybersecurity environment in the...  ...large federal initiatives. You will lead QMP development, governance boards, and stakeholder communications, ensuring compliance with contract requirements and federal regulations... 
    Contract work

    Management Solutions

    Washington DC
    1 day ago
  •  ...as a primary liaison with federal agencies, the FedRAMP PMO,...  ...ongoing authorization and compliance activities. Lead FedRAMP Continuous Monitoring...  ...the System Security Plan, risk documentation, assessment artifacts...  ..., security engineering, governance, risk, compliance, or... 

    Jobtailor

    Washington DC
    4 days ago
  •  ...is seeking an Acquisition Lead/Program Manager to provide...  ...across all program phases in a federal contracting environment....  ...within budget, and aligned with government requirements and...  ...allocate resources, manage risks, and ensure compliance while leading cross-functional... 

    Steel Point Solutions

    Washington DC
    4 days ago
  • OpenAI is seeking a GRC Program Manager to lead US government compliance initiatives, drive FedRAMP ATOs, and coordinate with engineers and assessors in a highly...  ...and implement security controls, produce SSPs and risk assessments, and represent OpenAI during audits, while... 

    Heelsandtech

    Washington DC
    2 days ago
  • Zermount, Inc is seeking an ISSO Program Manager to lead security governance and RMF activities for a federal client. This role combines project management with cybersecurity expertise to ensure secure, compliant operations across enterprise systems. The role requires strong... 

    Hiring Our Heroes

    Arlington, VA
    4 days ago
  • $155k - $190k

    Unison Inc. in Washington, D.C. is seeking a Security Governance Manager to lead compliance operations and manage federal authorizations. The ideal candidate will have over 6 years of experience in GRC and security governance, including strong FedRAMP expertise. This role... 
    Remote job
    Work at office

    Unison Inc.

    Washington DC
    3 days ago
  •  ...corporation and a registered Government contractor that...  ...Position Title: System Compliance Lead Location:Washington...  ...and Technology (NIST) Risk Management Framework (...  ...Execute day to day Federal Information Security Management...  ...Risk, and Compliance (GRC) presentations for... 
    Full time
    For contractors

    gTANGIBLE Corporation

    Washington DC
    more than 2 months ago
  • Inovalon, based in Bowie, Maryland, seeks a Compliance, Risk and Business Manager to advance the company’s compliance posture in a healthcare...  ...8+ years in compliance/risk, a BA/BS, and a track record of leading risk assessments and remediation efforts. #J-18808-Ljbffr... 

    Inovalon Inc

    Bowie, MD
    3 days ago
  • SierTeK Ltd. is seeking a Senior Security Governance and Policy Analyst to support an opportunity in Washington D.C. The role reports to the I&A CISO and requires deep knowledge of federal cybersecurity policies and guidance for cloud and on-premise environments. You will... 

    SIERTEK LTD

    Washington DC
    3 days ago
  • CodeSphere LLC in Washington, DC seeks a Generative AI Safety & Compliance Officer to oversee governance of LLMs and generative deployments across enterprise products. You will build guardrails for hallucinations, prompt injection, and bias while ensuring GDPR, CCPA, and... 

    myBridge Corporation

    Washington DC
    3 days ago
  • GCA is seeking a Program Manager to oversee a federal IT modernization program in Washington, DC. You will be responsible for managing concurrent task orders encompassing network and cybersecurity engineering while ensuring program-level oversight. The ideal candidate has... 
    Permanent employment

    GCA

    Washington DC
    3 days ago
  • Guidehouse is seeking a cybersecurity professional to lead RMF and A&A activities for federal clients, focusing on documentation, control implementation, and continuous authorization. You will work across on‑premise and cloud platforms, aligning with FedRAMP, FISMA, and... 

    Guidehouse

    Mc Lean, VA
    1 day ago
  • $139.5k - $188.7k

     ...Reporting, Enablement and Governance (S-REG) team's mission is...  ...their Sustainability risks and opportunities. We are...  ...experience- 5+ years of leading cross-functional initiatives...  ...carbon accounting tools, or GRC (Governance, Risk, and Compliance) systems.Amazon is an... 
    Worldwide
    Flexible hours

    Amazon

    Arlington, VA
    2 days ago
  •  ...solutions based on industry-leading practices. ProSidian...  ...enterprise services/solutions for Risk Management | Compliance | Business Process | IT...  ..., defense and civilian government, and non-profit organizations...  ...& IT Modernization for Federal science agency HR modernizationThe... 
    Full time
    Contract work
    Temporary work
    For contractors
    H1b
    Work at office
    Flexible hours

    Prosidian Consultng

    Alexandria, VA
    23 hours ago
  • $171k - $231.3k

    AWS is seeking a Principal Business Development Lead to own the go-to-market strategy and sales execution for AI-powered mission solutions...  ...ideal candidate brings deep familiarity with HHS mission areas, federal health procurement, and the ability to coordinate cross-... 
    Contract work
    Flexible hours

    AmazonWebServices

    Arlington, VA
    23 hours ago
  •  ...solutions based on industry-leading practices. ProSidian...  ...enterprise services/solutions for Risk Management | Compliance | Business Process | IT...  ..., defense and civilian government, and non-profit organizations...  ...& IT Modernization for Federal science agency HR modernizationThe... 
    Full time
    Contract work
    Temporary work
    For contractors
    H1b
    Work at office
    Flexible hours

    Prosidian Consultng

    Alexandria, VA
    1 day ago
  •  ...solutions based on industry-leading practices. ProSidian...  ...enterprise services/solutions for Risk Management | Compliance | Business Process | IT...  ..., defense and civilian government, and non-profit organizations...  ...& IT Modernization for Federal science agency HR modernizationThe... 
    Full time
    Contract work
    Temporary work
    For contractors
    H1b
    Work at office
    Flexible hours

    Prosidian Consultng

    Alexandria, VA
    1 day ago
  •  ...solutions based on industry-leading practices. ProSidian...  ...enterprise services/solutions for Risk Management | Compliance | Business Process | IT...  ..., defense and civilian government, and non-profit organizations...  ...& IT Modernization for Federal science agency HR modernizationThe... 
    Full time
    Contract work
    Temporary work
    For contractors
    H1b
    Work at office
    Flexible hours

    Prosidian Consultng

    Alexandria, VA
    1 day ago
  •  ...solutions based on industry-leading practices. ProSidian...  ...enterprise services/solutions for Risk Management | Compliance | Business Process | IT...  ..., defense and civilian government, and non-profit organizations...  ...& IT Modernization for Federal science agency HR modernizationThe... 
    Full time
    Contract work
    Temporary work
    For contractors
    H1b
    Work at office
    Flexible hours

    Prosidian Consultng

    Alexandria, VA
    1 day ago
  •  ...GHD is seeking a Senior Proposal Specialist to lead proposal efforts for U.S. Federal Agency clients. This role involves developing proposal strategies, ensuring compliance, and executing effective teamwork to deliver high-quality proposals while collaborating closely... 
    Work at office

    GHD

    Bowie, MD
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Governance, Risk & Compliance (GRC) Lead, Federal. Be the first to apply!