GRC Analyst
$189k - $225kGoToMeeting
About the Role The GRC Analyst, Federal & Customer Programs is responsible for the hands‑on analysis, documentation, and operational execution of the company's security governance, risk, and compliance obligations. This role sits at the intersection of customer contracts, regulatory frameworks, and the company's security control environment — translating external requirements into clear, traceable internal commitments and evaluating how well current capabilities satisfy them. The GRC Analyst reviews incoming contractual security language, maps obligations to applicable frameworks and existing controls, produces compliance matrices and gap analyses, owns the operational risk assessment process, contributes to governance and policy lifecycle activities, and supports audit, assessment, and customer inquiry activities. A meaningful portion of this role is dedicated to ongoing contract and requirements analysis as new programs are awarded and existing programs evolve. The GRC Analyst serves as the security function's primary reviewer of incoming contractual cybersecurity language and works directly with legal and sourcing on flow‑down negotiation and redlines. Candidates who enjoy careful reading of contractual and regulatory text — and who want this to be a substantial part of their day‑to‑day work — will find this role a strong fit. This is a detail‑oriented, writing‑intensive role requiring strong analytical judgment, fluency across multiple compliance frameworks, and the ability to work effectively with legal, sourcing, program management, engineering, and security operations stakeholders. Key Responsibilities Contract & Requirements Analysis Review customer contracts, statements of work, security annexes, CDRLs, data protection addenda, and flow‑down clauses to identify cybersecurity, privacy, and information handling obligations applicable to the company. Extract and catalog specific security requirements from contractual language, and translate them into structured, testable statements suitable for traceability and control mapping. Compare identified requirements against the company's current product scope, control environment, and certification posture to determine where compliance is already met, partially met, or requires new implementation work. Produce gap analyses, compliance matrices, and Requirements Traceability Matrix (RTM) artifacts that clearly communicate the state of compliance for a given contract, program, or system. Serve as the security function's primary point of contact for legal and sourcing during contract review, redline cycles, and flow‑down negotiation, including review of subcontractor and supplier flow‑down language. Framework Mapping & Interpretation Maintain working proficiency across the frameworks relevant to the company's regulatory and contractual posture, including NIST SP 800‑171, NIST SP 800‑53, NIST CSF, CMMC, ISO 27001, FedRAMP, and applicable European frameworks such as NIS2 and GDPR. Map controls across frameworks to minimize duplicated work and enable consistent responses to overlapping requirements; contribute to a shared control inventory used by compliance, security, and program teams. Interpret framework language and authoritative guidance (NIST publications, DoD guidance, regulator FAQs) in the context of specific company systems and business scenarios and escape ambiguity for formal risk decisions when appropriate. Governance, Policy & ISMS Support Contribute to the maintenance of the company's Information Security Management System (ISMS) documentation set, including keeping control descriptions, evidence references, and scope statements accurate and current. Support the policy and standard lifecycle, including periodic review cycles, version control, exception governance, and clarification of control owner accountability. Produce compliance posture reporting and audit readiness metrics for governance forums and leadership review, including framework coverage, finding aging, and remediation progress. Deliverable Writing & Artifact Contribution Draft and revise compliance deliverables including System Security Plans (SSP), Plans of Action & Milestones (POA&M), policy and standard content, control narratives, customer security questionnaire responses, and audit artifacts. Author clear, concise written responses to customer, auditor, and regulator inquiries, calibrated to the technical level of the audience and consistent with approved company positioning. Risk Assessment & Treatment Own the operational risk assessment process and the supporting risk register, including conducting periodic and event‑driven risk assessments, documenting current state, identifying deficiencies, and developing risk treatment recommendations. Route risk acceptance and exception decisions to the appropriate decision authority with the underlying analysis and documentation prepared for review; track decisions and ensure follow‑through on conditions or expirations. Track open compliance findings and remediation activities, prepare status updates, and flag aging or high‑severity items for escalation. Third‑Party & Supply Chain Risk Contribute to vendor and supplier security review activities, including evaluating vendor security questionnaires, reviewing supplier control attestations, and assessing residual risk for inclusion in procurement and program decisions. Support assessment of subcontractor and supplier flow‑down compliance, including coordinating with sourcing and program management on supplier security obligations and remediation. Audit & Assessment Support Support internal and external audit, assessment, and certification activities, including C3PAO engagements, ISO 27001 surveillance audits, customer assessments, and regulator inquiries. Coordinate evidence collection with system owners and control operators; validate that evidence is accurate, complete, and appropriately scoped before submission. Participate in assessor and auditor interviews as a subject matter contributor on specific controls and artifacts. Cross‑Functional Collaboration Partner with legal and sourcing on contract review, redlines, and flow‑down language; with security program management on milestones, schedules, and audit coordination; and with security engineering and IT on evidence, control implementation detail, and remediation planning. Serve as a knowledgeable point of contact for internal teams seeking to understand what a given regulatory or contractual requirement means in practice. What Success Looks Like in Year One Established a repeatable contract review intake process with legal and sourcing, including a maintained library of standard cybersecurity flow‑down clauses and review turnaround expectations. Produced an end‑to‑end Requirements Traceability Matrix for at least one active federal program, traceable from contract clauses through framework controls to evidence sources. Stood up the operational risk register and routine risk reporting cadence, with at least one full assessment cycle completed and risk treatment decisions documented. Maintained the ISMS documentation set in audit‑ready condition through at least one external assessment or surveillance cycle. Required Qualifications Five or more years of progressive experience in cybersecurity governance, risk, and compliance; IT audit; or a closely related discipline, with substantial hands‑on exposure to framework interpretation and contract requirement analysis. Demonstrated working knowledge of NIST SP 800‑171 and NIST SP 800‑53, including control families, assessment procedures, and common implementation patterns. Experience contributing to SSP and POA&M artifacts, compliance matrices, or Requirements Traceability Matrices in a regulated environment. Practical experience supporting at least one formal audit, certification, or assessment cycle (for example CMMC, ISO 27001, SOC 2, FedRAMP, or comparable). Strong technical writing skills, including the ability to produce accurate, concise, and audience‑appropriate compliance documentation. Writing samples may be requested as part of the interview process. Demonstrated comfort and interest in reading contractual and regulatory language carefully and translating it into specific, actionable internal requirements. This is a core part of the role, not an occasional task. Comfort working across multiple stakeholder groups — legal, sourcing, engineering, IT, security operations, and program management — and adjusting communication style accordingly. Bachelor's degree in Information Security, Information Systems, Business, a related field, or equivalent practical experience. Preferred Qualifications Direct experience with CMMC 2.0 assessment preparation, including familiarity with DFARS View phone number on click.appcast.io and 48 CFR Part 204. Familiarity with ISO 27001, FedRAMP, SOC 2, NIS2, GDPR data security obligations, or EU dual‑use export control regimes. Experience handling Controlled Unclassified Information (CUI) in accordance with NARA and DoD requirements. Exposure to aerospace, defense, space, or other regulated technology environments. Experience reviewing or negotiating cybersecurity flow‑down language in customer or supplier contracts. Working familiarity with Governance, Risk, and Compliance (GRC) tooling such as ServiceNow GRC, Archer, Hyperproof, Drata, Vanta, or equivalent. Industry certifications such as CISA, CRISC, CISSP, CGRC (formerly CAP), ISO 27001 Lead Implementer / Lead Auditor, CMMC Registered Practitioner (RP), or CMMC Certified Professional / Certified Assessor (CCP / CCA). Active US security clearance, or eligibility to obtain one. Spire operates a hybrid work model, and this position will require you to work a minimum of three days per week in the office. Access to US export‑controlled software and/or technology may be required for this role. If needed, Spire will arrange the necessary licenses—this is not something candidates need to have before applying. The anticipated base salary range for this position is $189,000 USD – $225,000 USD. Final base salary for this role will be based on location, skills, experience and qualifications. In addition to base compensation, this role may be eligible for annual equity awards and our employee benefits program, including vacation, sick, and personal time off; optional medical, dental, vision, life, and disability coverage; a 401(K) plan; health and wellness reimbursement program; and participation in Spire’s Employee Stock Purchase Plan. Global Perks Name Your Satellite Program (NYSP) Launch Attendance Generous Time Off Policy Education Assistance Program Employee Assistance Program (EAP) Employee Stock Purchase Program (ESPP) Family Leave Fitness Reimbursement Employee Referral Program Healthy snacks & beverages in every office About Spire We improve life on Earth with data from space. Spire Global is a space‑to‑cloud analytics company that owns and operates the largest multi‑purpose constellation of satellites. Its proprietary data and algorithms provide the most advanced maritime, aviation, and weather tracking in the world. In addition to its constellation, Spire’s data infrastructure includes a global ground station network and 24/7 operations that provide real‑time global coverage of every point on Earth. We are proud to be an equal‑opportunity employer and are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, marital status, disability, gender identity or veteran status. #J-18808-Ljbffr
$84k - $100k
...GRC Analyst Uplight is creating a new category of energy. We make software that manages energy resources in homes and businesses—including things like smart thermostats, electric vehicles, solar panels, storage batteries, heat pumps, and even people's behavior—to generate...SuggestedLocal areaFlexible hoursShift work- ...A cybersecurity compliance consulting firm is looking for a GRC Analyst to help organizations manage cybersecurity compliance and risk. This fully remote position involves conducting assessments, developing security policies, supporting compliance audits, and collaborating...SuggestedRemote work
- ...The Governance, Risk, and Compliance (GRC) Analyst supporting federal and customer programs is responsible for evaluating, documenting, and operationalizing cybersecurity and compliance requirements across the organization. This position works across contractual obligations...SuggestedContract work
- ...Analysis, Risk Register functional application via Service Now IRM/GRC environment. Significant experience with Service Now... ...have: Privacy (HIPAA) and PCI Compliance experience. Required Skills : Business Analysis Additional Skills : Business AnalystSuggested
$130k - $180k
...is building a cutting‑edge security compliance program aligned with FedRAMP, SOC2, PCI, HIPAA, GDPR, and other frameworks. As a GRC Analyst you’ll help manage these initiatives using tools such as Kubernetes, GCP, AWS, Terraform, and others. Responsibilities Lead compliance...SuggestedLocal areaFlexible hours- GoTo Meeting is seeking a GRC Analyst, Federal & Customer Programs, to manage security governance, risk, and compliance obligations. Responsibilities include analyzing contracts, mapping obligations to compliance frameworks, and producing compliance matrices. The ideal...
- Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the complex landscape of cybersecurity compliance and risk management. You will work directly with clients to assess their...Full timeRemote work
- Neier Inc. is looking for a GRC Analyst to enhance their security compliance program. You will lead compliance efforts for CMMC, manage complex control frameworks, and design automation solutions to streamline risk assessments. The ideal candidate has over 5 years of experience...Flexible hours
- A leading federal services provider is seeking a Cybersecurity Analyst in Alexandria, VA. This role includes managing governance, risk, and compliance activities to ensure compliance with DoD requirements. The ideal candidate will have at least 10 years of relevant experience...
- A federal services provider is seeking a Cybersecurity Analyst in Alexandria, VA, focused on governance, risk, and compliance (GRC) activities. The ideal candidate should have a minimum of 10 years of relevant experience and senior-level cybersecurity certifications. You...
- ...The Squires Group in Arlington, VA is seeking an experienced SAP Security Analyst to support a major ERP modernization initiative in a federal environment. This position involves implementing and maintaining application security within an SAP S/4HANA landscape, with 75...Remote work
- Job Description Job Description:\n\nCompany Description ProSidian is a Management And Operations Consulting Services firm that focuses on providing value to clients through tailored solutions based on industry-leading practices. ProSidian provides enterprise services...Full timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
$70k - $80k
...Job Title: Mid-Level GRC Analyst Location: 1‑day on‑site at HQ - Silver Spring, MD Clearance Required: Public Trust Eligible Salary: $70K-$80K Job Summary The Mid‑Level GRC Analyst will support cybersecurity governance, risk management, and compliance (GRC) initiatives...Apprenticeship$70k - $80k
...Mid-Level GRC Analyst Location: 1-day on-site at HQ - Silver Spring, MD Clearance Required: Public Trust Eligible Salary: $70K-$80K Application Deadline: June 30, 2026 To apply, please follow these steps: # Visit ibsscorp.com/careers . # Select...Apprenticeship- ...Creative Solutions Services, LLC in Silver Spring, MD, is seeking a Mid-Level GRC Analyst to support cybersecurity governance, risk management, and compliance initiatives. This role requires hands-on experience supporting compliance activities and the ability to develop...
$130k - $180k
...challenging and exciting scaling/optimization work to ensure that we can provide the most secure and performant service. As a GRC Analyst at Virtru, you will be the primary point of contact for compliance-related inquiries. You will lead and manage the organization's...Remote jobLocal areaFlexible hoursShift work- ...Proficiency with common office productivity tools (e.g., Microsoft Excel, Word, PowerPoint) and comfort working with enterprise systems or GRC/IRM tools. Preferred Qualifications Master’s degree in Business Administration, Public Policy, Security Studies, Risk...Contract workWork at officeWorldwide
- Job Description Job Description Healthcare Fraud Investigator Employment Type: Full-Time, Mid-Level Department: Litigation Support CGS is seeking a Healthcare Fraud Investigator to provide Legal Support for a large Government Project in Nashville, TN. The ...Full timeWork experience placementWork at officeLocal area
- ...processes, policies, and people delivering value. See Link To the ProSidian website at Description ProSidian Seeks a Compliance Data Analyst | Human Capital Programmatic Evaluation & Compliance - Regulatory Compliance [NSF0098098] for Program Support on a Exempt W2: No...Full timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
- ...Kellogg, Hansen, Todd, Figel & Frederick, P.L.L.C. is seeking a highly skilled and detail-oriented Governance, Risk, and Compliance (GRC) Officer to oversee and enhance our firm's risk management, compliance, and governance practices. This individual will be responsible...Shift work
$68k - $73k
Oceana is seeking a detail-oriented Specialist, Corporate Risk, to support safety, security, and risk management across the organization. This full-time position based in Washington, DC, plays a crucial role in assessing risks, coordinating procedures, and maintaining ...Full timeWork at office- Compliance & Risk Specialist ProSidian is a Management And Operations Consulting Services firm that focuses on providing value to clients through tailored solutions based on industry-leading practices. ProSidian provides enterprise services/solutions for Risk Management...Contract workH1bWork at office
$60 - $70 per hour
Job Summary Randstad is seeking a highly organized Regulatory Compliance & Documentation Manager to lead a critical compliance and process‑optimization initiative for a major transportation client in Washington, DC. In this role, you will bridge the gap between internal...Hourly payContract workTemporary workWork experience placement- ...investigations and analysis of high-risk customers, entities, and transactions to ensure compliance with BSA, AML, and OFAC regulations. The analyst will conduct daily reviews of high-risk customers and will, as needed, conduct ad-hoc reviews from various lines of business. The...Work at officeLocal areaRemote work
- ...) filings. This includes identifying potential violations, documenting findings, and escalating suspicious activity as needed. The analyst will review automated and manual reports, work closely with internal departments, and ensure all reporting obligations are met accurately...Work at officeLocal areaRemote work
- ...Job Description Job Description Metis Technology Solutions, Inc. is seeking a highly qualified Senior Regulatory Analyst to provide specialized engineering and analytical services in support of National Airspace System (NAS) operations. This role focuses on supporting...Visa sponsorship
- Job Description Job Description Position Summary: The Compliance Specialist reports directly to the Director of Compliance and is responsible for assisting the Compliance Department in ensuring compliance with all federal laws, state laws, and agency regulations...Work experience placementInterim roleWork at office3 days per week1 day per week
- ...career growth, and winning ideas. Military Veterans Encouraged to Apply. Job Description: NDi is seeking a Mid-Level Regulatory Analyst to support a federal aviation safety analytics program for the Federal Aviation Administration (FAA). The program supports the...For contractorsRemote work
$24.76 per hour
Job Description Job Description Compliance Specialist This position is responsible for providing on-site leasing and compliance for one or more residential multifamily apartment communities. We are seeking a dedicated and knowledgeable Affordable Housing Compliance...Hourly payFull timeTemporary workInterim roleWork at officeLocal areaMonday to FridayWeekend workAfternoon shift- ...State banking regulations and assist with developing and implementing the Company’s Compliance Program. In addition, the Compliance Analyst is responsible for adhering to and complying with all Company policies and procedures and Federal and State banking laws....Work at officeLocal areaRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!


