Cyber GRC Specialist
$95k - $115kBrown Advisory
Company OverviewEvery firm has a culture – the values, beliefs, methodology, attitudes and standards that reflect an organization’s DNA. But the truly inspiring firms – the game-changers, the industry leaders and the disruptors – have cultures that propel them to innovate and stand out. At Brown Advisory, we aim to be one of those inspired firms. Over the years, we have purposefully built and nurtured our client-first culture.Brown Advisory is an independent investment management and strategic advisory firm committed to delivering a combination of first-class performance, strategic advice and the highest level of client service. The firm’s clients—including individuals, families, family offices, endowments, foundations, charities, institutions, consultants, and financial intermediaries—are served by over 1,000 colleagues worldwide, all of whom are equity owners of the firm.Brown Advisory is currently seeking a Cyber GRC Specialist to support and mature the firm's governance, risk, compliance, and control-management routines. This blended role is designed for someone who can translate security requirements into practical business processes, drive evidence and accountability, and communicate clearly with technical and non-technical stakeholders.As part of a lean Information Security team within a mid-sized financial services organization, this individual will serve as a central coordinator for cyber risk, policy management, control testing, audit readiness, client and regulatory response support, and vulnerability remediation governance. The role is not intended to be a hands-on vulnerability engineering role; rather, it ensures the process, ownership, exceptions, reporting, and governance routines are working.Blended Role CoveragePrimary emphasis: Cyber GRC support for policies, controls, cyber risk tracking, audit coordination, exceptions, and governance routines.Blended coverage: Cyber Risk / Compliance Analyst work, ISO and risk-platform support, evidence coordination, client/regulatory response support, communications, and vulnerability governance.Duties and ResponsibilitiesSupport and mature core cyber governance routines, including policy management, control ownership, risk acceptance, exception handling, standards maintenance, and periodic leadership reporting.Maintain the cyber risk register and partner with technology and business owners to document risk decisions, remediation plans, due dates, dependencies, and residual risk.Serve as a key administrator and process contributor for ISO and security-risk management platforms such as Vanta or similar tools.Coordinate evidence collection, control testing, audit requests, client due diligence responses, regulatory requests, and recurring compliance deliverables.Translate ISO 27001, regulatory, client, and internal security expectations into practical controls and operating procedures appropriate for Brown Advisory's size and risk profile.Facilitate cross-functional communications for security change, SaaS inventory, policy enforcement, control adoption, and risk remediation.Coordinate vulnerability management governance, including scan-result intake, prioritization routines, remediation tracking, exception handling, and reporting.Partner with security engineers, infrastructure teams, application owners, Compliance, Legal, Operations, and Client Service to close control gaps in a business-aligned manner.Develop clear metrics for control effectiveness, audit readiness, exceptions, overdue remediation, and recurring governance activities.Identify process improvements that make security governance more repeatable, transparent, and useful without creating unnecessary bureaucracy.Preferred QualificationsBachelor's degree in cyber security, information systems, risk management, business, or a relevant field preferred; equivalent professional experience will be considered.3-6 years of experience in cyber GRC, information security, technology risk, IT audit, compliance, or related control-management work preferred.Working knowledge of ISO 27001, SOC 2, NIST CSF, CIS Controls, SEC/FINRA expectations, privacy requirements, or comparable control frameworks.Experience supporting audits, evidence collection, control testing, policy updates, issue tracking, or risk-register maintenance in a regulated environment; financial services experience preferred.CISA, CRISC, CISM, Security+, ISO 27001 Foundation/Lead Implementer, or similar professional designation preferred but not required.Technical SkillsCyber risk registers, exception management, control testing, evidence management, policy lifecycle management, and audit coordination.GRC or trust-management platforms such as Vanta, Archer, ServiceNow GRC, OneTrust, Drata, or similar tools.Vulnerability management governance, including prioritization, remediation tracking, aging analysis, exception workflows, and executive reporting.Strong knowledge of cyber security controls across identity, endpoint, cloud, network, data protection, application security, and third-party risk.Excellent writing, facilitation, and stakeholder-management skills, including the ability to turn technical risk into clear business language.Practical judgment about when to enforce, when to escalate, and when to help the business find a workable control path.Demonstrates curiosity and a continuous improvement mindset by identifying opportunities to enhance processes, improve efficiency, and thoughtfully leverage new technologies and tools, including AI-enabled productivity solutionsPersonal AttributesTake ownership and move initiatives forward without constant oversight.Balance technical depth, process discipline, and sound business judgment.Approach risk management pragmatically rather than theoretically.Thrive in collaborative, high-accountability environments.Communicate clearly with technical and non-technical colleagues.Bring an entrepreneurial mindset to building and improving security capabilities.Applicants must be authorized to work in the United States without the need for current or future employer-sponsored work authorization (e.g., H-1B , O-1, F-1 (OPT), TN, or any other non-immigrant visa classifications that require employer support or sponsorship).MD Salary: $95-$115k. Commensurate with experience and location. Does not include bonus or long term incentive eligibility (if applicable).DC Salary: $104.5K–$126.5K. Commensurate with experience and location. Does not include bonus or long-term incentive eligibility (if applicable).BenefitsAt Brown Advisory we offer a competitive compensation package, including full benefits.• Medical• Dental• Vision• Wellness program participation incentive• Financial wellness program• Fitness event fee reimbursement• Gym membership discounts• Colleague Assistance Program• Telemedicine Program (for those enrolled in Medical)• Adoption Benefits• Daycare late pick-up fee reimbursement• Basic Life & Accidental Death & Dismemberment Insurance• Voluntary Life & Accidental Death & Dismemberment Insurance• Short Term Disability• Paid parental leave• Group Long Term Disability• Pet Insurance• 401(k) (50% employer match up to IRS limit, 4 year vesting)Brown Advisory is an Equal Employment Opportunity Employer.SummaryLocation: Baltimore, MD; Washington D.C.Type: Full time
- ...Chameleon Integrated Services seeks an ISSM / Senior Cybersecurity & GRC Lead to serve as the primary cybersecurity advisor to the... ...the enterprise RMF package and coordinate GRC efforts across live cyber operations. This role requires deep experience with RMF, eMASS...Cyber
$143.91k - $187.09k
INFORMATION TECHNOLOGY SPECIALIST (INFOSEC) Key Responsibilities Serves as the Chief Technical Officer (CTO) to the Director, Vulnerability... ...agency is hiring for this position? This position is with DOD Cyber Crime Center, Department of the Air Force. What is the salary...CyberRemote work$114.1k - $268.18k
...consider a career in Advisory.KPMG is currently seeking a Lead Specialist, IAM Delivery Manager to join our Managed Services practice.Responsibilities:Provide management coordination and oversight of Cyber Managed Services delivery of contracted services; work with client...CyberH1bLocal area$140k - $150k
...exception records, and implementation documentation in partnership with GRC and technology owners.Execute immediate remediation actions where... ...leadership.Preferred QualificationsBachelor's degree in cyber security, computer science, engineering, information systems, or...CyberFull timeTemporary workH1bImmediate startWorldwide- ...Training allowance ~ PTO and more ISSM / Senior Cybersecurity & GRC Lead Location: Linthicum Heights, MD Employment Type:... ..., you must also be deeply familiar with the live, operational cyber environment. This position encompasses overseeing technical boundaries...CyberFull timeContract workTemporary work
$110k - $135k
...documentation, metrics, and leadership reporting in partnership with GRC.Drive remediation of identity-related audit findings, penetration... ...unnecessarily.Preferred QualificationsBachelor's degree in cyber security, computer science, information systems, engineering, or...CyberFull timeTemporary workFor contractorsH1bWorldwide- ...operational intelligence, counter unmanned aerial systems and cyber security. TechINT Solutions Group has developed a unique analytical... .... TechINT is currently looking for a Cyber Exploitation Specialist position on the REACT contract to support the C5ISR Center at Aberdeen...CyberFull timeContract work
- ...and validation and verification ~2 years of experience with Anti-tamper, Reverse Engineering and/or Risk Management Framework and Cyber Resiliency Insight Global is hiring multiple candidates for these roles and pay will vary based on a number of factors including...CyberFull time
- ...clearance with TS/SCI eligibility to qualify for consideration. Responsibilities: Design, implement, and sustain a secure, scalable cyber range network supporting Red Team operations, adversary emulation, penetration testing, malware analysis, cyber research, and...CyberFull time
- ...A McLean, VA based cyber security company is searching for Senior Forward Deployed Engineer to join their scaling team. Their product is used to protect the nations critical infrastructure including water treatment facilities, power plants, manufacturing, supply chains...CyberFull time
$135.9k - $238.4k
...Officer (“Associate General Counsel”), to serve as a trusted advisor to the University, with a primary focus on privacy, information and cyber security, and data governance. The Associate General Counsel will also advise on digital accessibility, records management, and a...CyberFull timeWork at officeMonday to Friday- ...RESIDENT THREAT OPERATIONS ANALYST Trinity Cyber is a leading developer and provider of advanced cybersecurity technologies and services. Our breakthrough core technology - Full Content Inspection (FCI)™ - can deeply, quickly, and precisely find threats within files...CyberFull timeLocal area
- ...recognized for its expertise in providing innovative technology exploitation, operational intelligence, counter unmanned aerial systems, and cyber security. We have developed a unique analytical methodology to identify technologies that could be used for illicit purposes.TechINT...CyberRemote work
- DescriptionSAIC is seeking a Damage Assessment Management Office (DAMO) Cyber Triage Analyst with an active Top Secret clearance to support the Office of the Under Secretary of Defense for Research and Engineering (OUSD R&E) Damage Assessment Management Office (DAMO) Defense...CyberWork experience placementWork at office
- .../project management, applications development, infrastructure, Cyber security, and enterprise content/data management services. We have... ...project type and how role supports The Security Operations Specialist will be responsible for operating and maintaining security tools...CyberFor contractorsWork at office
$121.9k - $219.41k
...focus business architecture domain and technical architecture domain (infrastructure, applications, integration, information & data, cyber security, etc.)Familiarity with information management practices, regulatory requirements and data privacy laws, especially those...CyberPermanent employmentImmediate start- ...seeking an Associate General Counsel and Privacy Officer to serve as a trusted advisor with a primary focus on privacy, information and cyber security, and data governance. The successful candidate will have a deep understanding of the laws, regulations, and industry best...Cyber
$86k - $138k
ResponsibilitiesPeraton is seeking a Cyber Threat Analyst in our Linthicum, MD office in support of our Department of Defense (DoD) customer as part of a highly talented, highly motivated, and high-performing team. This position offers a unique opportunity to work at the...CyberContract workFor contractorsWork at officeShift work- ...capabilities, and other AI-enabled tools designed around mission and operational requirements. You’ll partner with cybersecurity specialists, data scientists, software engineers, and mission stakeholders to move concepts from research and prototypes into deployable...Cyber
- ...and protect our deployed warfighter across Air, Electronic, Land, Sea, and Weapon Systems productsContributing to the efforts of the Cyber Security and Infrastructure Support (CSIS) team to support the assessment and authorization of products in accordance with Risk...CyberInterim roleFlexible hours
$112k - $179k
ResponsibilitiesPeraton is seeking a Cyber Threat Team Lead in our Linthicum, MD office in support of our Department of Defense (DoD) customer as part of a highly talented, highly motivated, and high-performing team. This position offers a unique opportunity to work at...CyberContract workWork at officeShift work$300k
...The Edens Group, LLC has been retained to identify and recruit a Strategic Sales Account Executive for a leader in Identity Theft and Cyber Protection Services to fuel growth during their next phase of expansion. Our client is a well-established firm, with revenue in the...CyberFull timeWork at office$95k - $170k
Morgan Stanley is seeking a Vice President, Cyber, Technology and Information Security (CTIS) Risk Oversight Lead in the CTIS team within Non-Financial Risk. The successful candidate will be responsible for leading a team focused on independent oversight and monitoring...CyberTemporary workLocal area- ...Redhawk Federal is seeking a former deputy CIO, chief technology officer, or IT division chief in a DoD cyber or IT organization, or a contractor strategy lead who reported directly to a CIO and CISO. Successful candidate will have overseen a team that received, interpreted...CyberFull timeFor contractors
$105.4k - $207.8k
Position Summary As a Physical Security Senior Consultant in Deloitte’s Cyber Defense & Resilience team, you will help clients strengthen physical security, operational resilience, and mission assurance across critical facilities, infrastructure, and operations....CyberLocal areaVisa sponsorship$163.4k - $322.1k
...interpersonal skills and professional demeanorAbility to meet deadlinesAbility to mentor and provide clear guidance to othersThe teamDeloitte’s Cyber Defense & Resilience practice helps organizations protect people, facilities, assets, and operations alongside data and technology....CyberLocal areaVisa sponsorship- ...state governmentagencies with over 100 cleared technical experts specializing inmission solution areas of Digital, AI & Analytics, Cyber, andEngineering. Our technologistsare recognized as industry leaders with demonstrated expertise ininnovating and transforming our client...CyberContract workFor subcontractor
$239k - $278.75k
...and priority outcomes for value realization, collaborating with specialists to develop business cases around measurable benefits.Conduct... ...leadership across relevant technologies (e.g., security technologies, cyber threat intelligence, risk and regulatory topics, emerging...CyberFull timeRemote workVisa sponsorshipWork visa- Full Visibility LLC seeks a Program Manager with TS/SCI clearance to lead a complex federal IT and cybersecurity program onsite in Linthicum Heights, MD. Responsible for executive-level leadership, governance, and interfacing with Government stakeholders, ensuring alignment...CyberFor subcontractor
$134.5k - $265.1k
Position Summary Our Deloitte Cyber Defense & Resilience team recognizes that resilient organizations must protect not only data and technology, but also people, facilities, assets, and operations. Join our Physical Security consulting team to help clients address...CyberContract workLocal areaVisa sponsorship
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber GRC Specialist. Be the first to apply!
- senior safety specialist Baltimore, MD
- grocery specialist Baltimore, MD
- localization specialist Baltimore, MD
- agency management specialist Baltimore, MD
- restaurant specialist Baltimore, MD
- outreach specialist Baltimore, MD
- renovation specialist Baltimore, MD
- generation specialist Baltimore, MD
- maintenance specialist Baltimore, MD
- welding specialist Baltimore, MD



