Security Governance Risk & Compliance (GRC) Analyst
$130k - $170kVirtru
Security Governance Risk & Compliance (GRC) Analyst Washington, DC - Remote About Virtru: While the rest of the security industry obsesses over locking data down to prevent it from being lost or stolen, we’re doing something fundamentally different at Virtru. We’re setting data free so that you can intentionally share it with others, but without sacrificing security, privacy, or control. We’ve created both a suite of powerful data protection applications and an open platform that’s sparking an ecosystem of innovation. Through the Trusted Data Format (TDF) open standard, we’re not just protecting data; we’re creating a new paradigm where security enables sharing rather than preventing it. Think of us as the Android of data protection: a robust platform with an open core that developers and partners can build upon, coupled with our own best‑in‑class applications that showcase what’s possible when you reimagine security from the ground up. Backed by Iconiq Capital, Bessemer Venture Partners, Foundry Capital, and Tiger Global, we’re helping Fortune 500 companies and government agencies discover that true data security means having the freedom to share, collaborate, and innovate—without compromise. Compensation: $130,000-$170,000/year Here at Virtru you’ll help build a cutting‑edge security compliance program aligned with FedRAMP, SOC 2, PCI, HIPAA, GDPR, and any other security/privacy framework you can think of, while getting your hands on some of today’s most important tools and tech like Kubernetes, GCP, AWS, Terraform. We put a high value on input from everyone on our team. Your voice will have a significant impact. With a constantly growing customer base, there is no shortage of challenging and exciting scaling/optimization work to ensure that we can provide the most secure and performant service. As a GRC Analyst at Virtru, you will be the primary point of contact for compliance‑related inquiries. You will lead and manage the organization’s efforts to achieve and maintain CMMC compliance by conducting gap analyses and developing a roadmap to address compliance requirements. You will also play a vital role in supporting our existing FedRAMP, SOC 2, and PCI DSS compliance. Responsibilities Manage and implement complex controls frameworks for large systems, including cloud infrastructure and SaaS services (GCP, AWS, GitHub, Okta, etc.). Design and develop automation solutions for evidence collection across cloud infrastructure, endpoints, and SaaS services. Conduct risk assessments across business units and processes, identify risk findings, and recommend remediation and risk‑mitigation strategies. Participate in incident response activities, providing risk analysis and remediation support as needed. Assist or implement automated controls to support risk mitigation efforts across various business units with stakeholders. Incorporate CMMC certification into Virtru’s slate of compliance assessments and ongoing monitoring activities (FedRAMP, SOC 2, PCI). Facilitate the third‑party vendor on‑boarding and annual review process by evaluating the security of current and prospective partners. Enhance the team with your individualism, spirit, and love of learning. Skills that Will Help You Thrive Minimum of 5+ years of information security, IT audit and/or IT risk management, or GRC analyst/engineer experience. Deep understanding of at least a few of the following: CMMC, NIST800‑53 &800‑171, FedRAMP, SOC2, PCI, and/or other global privacy compliance frameworks. Technical acumen: strong understanding of modern cloud technologies (AWS, GCP, Azure, etc.) and familiarity with GRC tools (Hyperproof, Vanta, Drata, etc.) and SIEM tools (Datadog, Splunk). You’re a relationship builder and have worked with both business and technical risk and understand how to translate risk to various levels of the organization. Experience training and coaching teams to become better security and privacy practitioners. Like working on an autonomous agile team. At Virtru, you will have ownership of security, but you’ll collaborate with everyone to ensure we produce and implement the right solutions. Ability to resolve conflicts and drive issues to completion. Work independently with little or no supervision while maintaining a high level of efficiency. Values that Will Set You Up for Success Thinking outside of the box to respectfully challenge teammates and managers in pursuit of excellence. Strong sense of urgency with an action‑oriented mindset. Ability to collaborate and adapt to shifting priorities as business needs evolve. Comfortable with asynchronous communication including Slack, email, Zoom, etc. Benefits Flexible PTO policy— we strongly encourage you to take time off (in addition to 14 holidays) to ensure that you are getting the proper time needed to unplug and recharge. $1,500 annual Learning & Development stipend focused on providing you the resources to continually learn and professionally grow. Frequent company‑sponsored team celebrations that provide ample opportunities to connect with teammates. Access to an Employee Assistance Program. Access to Headspace, a mental health app tailored to your specific needs. A flat 3% contribution to your retirement account. High degree of flexibility— need to take care of a family emergency? We give you the time and space to do so. Additional Perks Competitive compensation. Generous parental, medical, and bereavement policies. 401 K contribution and stock options. Full medical, dental, and vision benefits. New‑Hire swag and IT welcome boxes. Structured semi‑annual 360° performance reviews. Virtru is committed to building an inclusive environment for people of all backgrounds and everyone is encouraged to apply. Virtru is an Equal Opportunity Employer and does not discriminate on the basis of race, color, gender, religion, disability, national origin, protected veteran status, age, or any other status protected by applicable national, federal, state, or local law. #J-18808-Ljbffr
- ...Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands‑on experience in cybersecurity, compliance, and risk management. The internship...SuggestedFull timeInternshipRemote work
- ...Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the... .... You will work directly with clients to assess their security posture, develop policies, and guide them through compliance...SuggestedFull timeRemote work
- A cybersecurity compliance consulting firm is looking for a GRC Analyst to help organizations manage cybersecurity compliance and risk. This fully remote position involves conducting assessments, developing security policies, supporting compliance audits, and collaborating...SuggestedRemote work
- ...cybersecurity support to U.S. Government agencies and critical... ...Cyber Systems is seeking a Compliance Analyst to support cybersecurity governance, risk, compliance, and modernization... ...support. CAP, CISSP, CISM, Security+. Experience with GRC tools and federal compliance...SuggestedContract workFor contractors
- ...integrators in the defense and government services industry. We... ...to enable national security missions worldwide.... ...seeking a highly qualified Risk Mitigation Specialist... ...FOCI policies to ensure compliance with emplaced... ...enterprise systems or GRC/IRM tools. Preferred...SuggestedContract workWork at officeWorldwide
$140k - $190k
...Security, Risk and Compliance Consultant Washington, District of Columbia, United States WHO WE LOOK FOR... ...Familiarity or direct experience with GRC/Cybersecurity solutions, tools and... ...or projects with military or federal government agencies in Risk, Compliance or Information...Permanent employment$78.9k - $123.3k
...oriented cybersecurity compliance professional to support... ...responsible for managing the security authorization lifecycle... ...Milestones (POA&Ms) Risk Assessments Continuous... ...are subject to government customer review and approval... ...risk, and compliance (GRC) platforms. Knowledge of...Permanent employmentFull timePart timeWork at officeLocal areaRemote work- ...Clearance: Public Trust Position Overview The Risk Analyst supports federal information security, compliance, and governance activities across systems operating within the... ...monitoring. Familiarity with eMASS, Archer, ServiceNow GRC, or similar. Strong analytical, documentation,...
- ...Risk Mitigation Specialist Senior Our work depends on a Risk Mitigation Specialist Senior to engage in defense and security efforts within the Pacific theater. You will lead the development... ...identified security gaps or compliance issues. Governance Support: Curate risk...
- ...effects-as-a-service to national security partners across five domains... ...team is responsible for the compliance execution of global export... ...escalation support for high‑risk, complex, or ambiguous compliance... ...policies, SOPs, and governance frameworks across licensing,...Full timeTemporary workWork at officeMonday to FridayShift work
$102.83k - $190.97k
...) out of our DC office.* THE JOB: The Senior Information Security Risk Analyst will support the assessment of information security risks across... ...page for instructions to submit your request. In compliance with local law, we are disclosing the compensation, or a range...Full timeContract workTemporary workWork at officeLocal area$80 - $95 per hour
...IT - Info Security Analyst V Onsite Flexibility: Hybrid — 2 days/week in... ...proactive identification of out-of-compliance assets and supporting... ...Experience with ServiceNow Risk assessments Risk technology... ...across enterprise technology and governance programs. With a strong...Contract workFor contractorsWork at officeWork visaMonday to FridayShift work2 days per week- ...About the Role: Join CFM Partners GRC, Inc. as a Regulatory Compliance Specialist - Content & Product.... ...services professionals in the securities industry. This role focuses on... .... helps organizations strengthen governance, manage risk, and build a lasting culture of compliance...
$80k - $128k
...Peraton is currently seeking a Risk and Vulnerability Analyst. Location: Chandler, AZ or... ...Analyst supports a 24x7 Security Operations Center (SOC) by... ...continuous visibility, compliance, and timely remediation to... ...valued partner to essential government agencies and supports...Contract workShift work- ...Exempt: No Reports To: ARMADA HQ Security Clearance Required: Top Secret *******... ...Responsibilities: Security Specialist II - Risk Assessment Specialist will manage the... ...with applicable state and local laws governing non-discrimination in employment in every...Full timeFor contractorsLocal areaRelocation
$60k
...programs across national security, defense, and public service... ...and improving essential government systems and services,... ...This role is remote. The Risk, Quality, and Performance Analyst serves as the Risk,... ...management activities to ensure compliance with contract...Contract workRemote work- ...Senior Vice President, Legal and Chief Compliance Officer (CCO) About the Company Nationally recognized healthcare services... ...-level role that directly impacts organizational strategy, governance, and risk posture. The successful candidate will be a trusted advisor...
- ...ANSER enhances national and homeland security by strengthening public institutions.... ...a Staff Action Officer to serve as a Governance Program Analyst supporting an Office of the Secretary... ...and external DoW organizations. Ensure compliance with security, protocol, timeline,...Work at office
- ...role involves developing and implementing compliance strategies, ensuring adherence to... ...regulations, and mitigating compliance risks. The Senior Consultant will be instrumental... ...these risks, and ensure alignment with government standards. Audit & Assessment : Conduct...
- ...cybersecurity support to U.S. Government agencies and critical infrastructure... ...is seeking a Zero Trust Analyst to support cybersecurity governance, risk, compliance, and modernization activities in... ...Responsibilities Assess current-state security architecture and capabilities...Contract workFor contractors
$90k - $200k
...Senior Manager, Investigations, Diligence, and Compliance - Specialist Kroll’s North American Investigations, Diligence and Compliance practice... ...intelligence, internal (client) investigations, insider risk compliance assessments, consulting projects and forensic matters...Temporary workFlexible hours- ...Overview The Compliance and Risk Analyst assists the IT Program Manager in the registration of all Application and Database Management Systems... ...each mission with a focus on keeping our nation safe and secure. Integral is headquartered in McLean, VA and serves clients...Temporary workWork at officeImmediate startFlexible hours
- ...integrators in the defense and government services industry. We... ...results to enable national security missions worldwide. Job... ...SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability... ...recommendations · Support cloud compliance scans and assessment...Contract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
- ...is seeking a Cybersecurity Compliance analyst in Arlington, VA. The roles... ...analytical expertise of the Risk Management Framework with knowledge... ...justifications, preparing government client for non-compliant... ...the IAM/IAT-II level (CompTIA Security+, GSEC, SSCP, or CCNA-...
- ...Vulnerability Management Analyst Location - Joint Base... ...- CompTIA Security+ or equivalent About TIME... ..., reviewing DISA STIG compliance, coordinating remediation... ...activities, and assisting with Risk Management Framework (... ..., or other federal government cybersecurity...Temporary workLocal areaFlexible hours
$90k - $95k
Technical Business Analyst Imagineeer, LLC — North Bethesda, Maryland... ...health, defense, homeland security, and transportation. We... ...production without breaking governance, compliance, or mission continuity. Our... ...accelerates delivery and reduces risk. If real delivery motivates...Work experience placementLocal area- ...technology and network solutions for government customers. Founded in 1985, NDi's... ...The Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst supports the Agency's Office of the... ...that ICT/OT products and services meet security, integrity, and resilience standards...For contractorsWork at office
$70k - $150k
...Associate Manager, Investigations, Diligence and Compliance - Specialist Kroll’s North American Investigations, Diligence and Compliance... ...adequacy and effectiveness of internal controls, performing insider risk compliance assessments, managing projects and resources,...Temporary workInterim roleFlexible hours- ...of Defense and other national security customers. Our Joint Systems... ...is seeking a Project Control Analyst (PCA) to work closely with Project... ...to maintain strong overall governance of project budgets, revenue... ...and followed and potential risks are mitigated. Ensure the accurate...For subcontractor
- Risk and Compliance Systems Analyst - Apex Systems Job #: 3015294 Site: Headquarters (HDQ) Business Unit: Fin Tech & Prod Mgmt Description: Hybrid... ...a skilled contractor to join our Finance Technology Security and Controls team. The team is responsible for security...For contractors3 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Governance Risk & Compliance (GRC) Analyst. Be the first to apply!
- risk consultant Washington DC
- senior quantitative risk analyst Washington DC
- operational risk consultant Washington DC
- it risk analyst Washington DC
- operational risk specialist Washington DC
- risk officer Washington DC
- risk analyst Washington DC
- regulatory affairs specialist Washington DC
- healthcare compliance officer Washington DC
- regulatory compliance specialist Washington DC


