Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Governance Risk & Compliance (GRC) Analyst

$130k - $170k

Virtru

Security Governance Risk & Compliance (GRC) Analyst Washington, DC - Remote About Virtru: While the rest of the security industry obsesses over locking data down to prevent it from being lost or stolen, we’re doing something fundamentally different at Virtru. We’re setting data free so that you can intentionally share it with others, but without sacrificing security, privacy, or control. We’ve created both a suite of powerful data protection applications and an open platform that’s sparking an ecosystem of innovation. Through the Trusted Data Format (TDF) open standard, we’re not just protecting data; we’re creating a new paradigm where security enables sharing rather than preventing it. Think of us as the Android of data protection: a robust platform with an open core that developers and partners can build upon, coupled with our own best‑in‑class applications that showcase what’s possible when you reimagine security from the ground up. Backed by Iconiq Capital, Bessemer Venture Partners, Foundry Capital, and Tiger Global, we’re helping Fortune 500 companies and government agencies discover that true data security means having the freedom to share, collaborate, and innovate—without compromise. Compensation: $130,000-$170,000/year Here at Virtru you’ll help build a cutting‑edge security compliance program aligned with FedRAMP, SOC 2, PCI, HIPAA, GDPR, and any other security/privacy framework you can think of, while getting your hands on some of today’s most important tools and tech like Kubernetes, GCP, AWS, Terraform. We put a high value on input from everyone on our team. Your voice will have a significant impact. With a constantly growing customer base, there is no shortage of challenging and exciting scaling/optimization work to ensure that we can provide the most secure and performant service. As a GRC Analyst at Virtru, you will be the primary point of contact for compliance‑related inquiries. You will lead and manage the organization’s efforts to achieve and maintain CMMC compliance by conducting gap analyses and developing a roadmap to address compliance requirements. You will also play a vital role in supporting our existing FedRAMP, SOC 2, and PCI DSS compliance. Responsibilities Manage and implement complex controls frameworks for large systems, including cloud infrastructure and SaaS services (GCP, AWS, GitHub, Okta, etc.). Design and develop automation solutions for evidence collection across cloud infrastructure, endpoints, and SaaS services. Conduct risk assessments across business units and processes, identify risk findings, and recommend remediation and risk‑mitigation strategies. Participate in incident response activities, providing risk analysis and remediation support as needed. Assist or implement automated controls to support risk mitigation efforts across various business units with stakeholders. Incorporate CMMC certification into Virtru’s slate of compliance assessments and ongoing monitoring activities (FedRAMP, SOC 2, PCI). Facilitate the third‑party vendor on‑boarding and annual review process by evaluating the security of current and prospective partners. Enhance the team with your individualism, spirit, and love of learning. Skills that Will Help You Thrive Minimum of 5+ years of information security, IT audit and/or IT risk management, or GRC analyst/engineer experience. Deep understanding of at least a few of the following: CMMC, NIST800‑53 &800‑171, FedRAMP, SOC2, PCI, and/or other global privacy compliance frameworks. Technical acumen: strong understanding of modern cloud technologies (AWS, GCP, Azure, etc.) and familiarity with GRC tools (Hyperproof, Vanta, Drata, etc.) and SIEM tools (Datadog, Splunk). You’re a relationship builder and have worked with both business and technical risk and understand how to translate risk to various levels of the organization. Experience training and coaching teams to become better security and privacy practitioners. Like working on an autonomous agile team. At Virtru, you will have ownership of security, but you’ll collaborate with everyone to ensure we produce and implement the right solutions. Ability to resolve conflicts and drive issues to completion. Work independently with little or no supervision while maintaining a high level of efficiency. Values that Will Set You Up for Success Thinking outside of the box to respectfully challenge teammates and managers in pursuit of excellence. Strong sense of urgency with an action‑oriented mindset. Ability to collaborate and adapt to shifting priorities as business needs evolve. Comfortable with asynchronous communication including Slack, email, Zoom, etc. Benefits Flexible PTO policy— we strongly encourage you to take time off (in addition to 14 holidays) to ensure that you are getting the proper time needed to unplug and recharge. $1,500 annual Learning & Development stipend focused on providing you the resources to continually learn and professionally grow. Frequent company‑sponsored team celebrations that provide ample opportunities to connect with teammates. Access to an Employee Assistance Program. Access to Headspace, a mental health app tailored to your specific needs. A flat 3% contribution to your retirement account. High degree of flexibility— need to take care of a family emergency? We give you the time and space to do so. Additional Perks Competitive compensation. Generous parental, medical, and bereavement policies. 401 K contribution and stock options. Full medical, dental, and vision benefits. New‑Hire swag and IT welcome boxes. Structured semi‑annual 360° performance reviews. Virtru is committed to building an inclusive environment for people of all backgrounds and everyone is encouraged to apply. Virtru is an Equal Opportunity Employer and does not discriminate on the basis of race, color, gender, religion, disability, national origin, protected veteran status, age, or any other status protected by applicable national, federal, state, or local law. #J-18808-Ljbffr

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Security Governance Risk & Compliance (GRC) Analyst in Washington DC vacancy
  •  ...Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands‑on experience in cybersecurity, compliance, and risk management. The internship... 
    Suggested
    Full time
    Internship
    Remote work

    Ruleset Security

    Arlington, VA
    1 day ago
  •  ...Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the...  .... You will work directly with clients to assess their security posture, develop policies, and guide them through compliance... 
    Suggested
    Full time
    Remote work

    Districttechgroup

    Washington DC
    1 day ago
  • A cybersecurity compliance consulting firm is looking for a GRC Analyst to help organizations manage cybersecurity compliance and risk. This fully remote position involves conducting assessments, developing security policies, supporting compliance audits, and collaborating... 
    Suggested
    Remote work

    Districttechgroup

    Washington DC
    19 hours ago
  •  ...cybersecurity support to U.S. Government agencies and critical...  ...Cyber Systems is seeking a Compliance Analyst to support cybersecurity governance, risk, compliance, and modernization...  ...support. CAP, CISSP, CISM, Security+. Experience with GRC tools and federal compliance... 
    Suggested
    Contract work
    For contractors

    Argo Cyber Systems

    Arlington, VA
    2 days ago
  •  ...integrators in the defense and government services industry. We...  ...to enable national security missions worldwide....  ...seeking a highly qualified Risk Mitigation Specialist...  ...FOCI policies to ensure compliance with emplaced...  ...enterprise systems or GRC/IRM tools. Preferred... 
    Suggested
    Contract work
    Work at office
    Worldwide

    SOSi

    Washington DC
    26 days ago
  • $140k - $190k

     ...Security, Risk and Compliance Consultant Washington, District of Columbia, United States WHO WE LOOK FOR...  ...Familiarity or direct experience with GRC/Cybersecurity solutions, tools and...  ...or projects with military or federal government agencies in Risk, Compliance or Information... 
    Permanent employment

    SEI

    Washington DC
    1 day ago
  • $78.9k - $123.3k

     ...oriented cybersecurity compliance professional to support...  ...responsible for managing the security authorization lifecycle...  ...Milestones (POA&Ms) Risk Assessments Continuous...  ...are subject to government customer review and approval...  ...risk, and compliance (GRC) platforms. Knowledge of... 
    Permanent employment
    Full time
    Part time
    Work at office
    Local area
    Remote work

    Noblis

    Washington DC
    1 day ago
  •  ...Clearance: Public Trust Position Overview The Risk Analyst supports federal information security, compliance, and governance activities across systems operating within the...  ...monitoring. Familiarity with eMASS, Archer, ServiceNow GRC, or similar. Strong analytical, documentation,... 

    TechPerm Incorporated

    Washington DC
    5 days ago
  •  ...Risk Mitigation Specialist Senior Our work depends on a Risk Mitigation Specialist Senior to engage in defense and security efforts within the Pacific theater. You will lead the development...  ...identified security gaps or compliance issues. Governance Support: Curate risk... 

    General Dynamics Information Technology

    Washington DC
    2 days ago
  •  ...effects-as-a-service to national security partners across five domains...  ...team is responsible for the compliance execution of global export...  ...escalation support for high‑risk, complex, or ambiguous compliance...  ...policies, SOPs, and governance frameworks across licensing,... 
    Full time
    Temporary work
    Work at office
    Monday to Friday
    Shift work

    Metrea

    Washington DC
    3 days ago
  • $102.83k - $190.97k

     ...) out of our DC office.* THE JOB: The Senior Information Security Risk Analyst will support the assessment of information security risks across...  ...page for instructions to submit your request. In compliance with local law, we are disclosing the compensation, or a range... 
    Full time
    Contract work
    Temporary work
    Work at office
    Local area

    Warner Bros. Discovery

    Washington DC
    17 hours ago
  • $80 - $95 per hour

     ...IT - Info Security Analyst V Onsite Flexibility: Hybrid — 2 days/week in...  ...proactive identification of out-of-compliance assets and supporting...  ...Experience with ServiceNow Risk assessments Risk technology...  ...across enterprise technology and governance programs. With a strong... 
    Contract work
    For contractors
    Work at office
    Work visa
    Monday to Friday
    Shift work
    2 days per week

    Global Technical Talent, an Inc. 5000 Company

    Laurel, MD
    5 days ago
  •  ...About the Role: Join CFM Partners GRC, Inc. as a Regulatory Compliance Specialist  - Content & Product....  ...services professionals in the securities industry. This role focuses on...  .... helps organizations strengthen governance, manage risk, and build a lasting culture of compliance... 

    CFM Partners GRC, Inc.

    Washington DC
    25 days ago
  • $80k - $128k

     ...Peraton is currently seeking a Risk and Vulnerability Analyst. Location: Chandler, AZ or...  ...Analyst supports a 24x7 Security Operations Center (SOC) by...  ...continuous visibility, compliance, and timely remediation to...  ...valued partner to essential government agencies and supports... 
    Contract work
    Shift work

    Peraton

    Washington DC
    2 days ago
  •  ...Exempt: No Reports To: ARMADA HQ Security Clearance Required: Top Secret *******...  ...Responsibilities: Security Specialist II - Risk Assessment Specialist will manage the...  ...with applicable state and local laws governing non-discrimination in employment in every... 
    Full time
    For contractors
    Local area
    Relocation

    Armada Ltd

    Washington DC
    6 days ago
  • $60k

     ...programs across national security, defense, and public service...  ...and improving essential government systems and services,...  ...This role is remote. The Risk, Quality, and Performance Analyst serves as the Risk,...  ...management activities to ensure compliance with contract... 
    Contract work
    Remote work

    MAXIMUS

    Washington DC
    2 days ago
  •  ...Senior Vice President, Legal and Chief Compliance Officer (CCO) About the Company Nationally recognized healthcare services...  ...-level role that directly impacts organizational strategy, governance, and risk posture. The successful candidate will be a trusted advisor... 

    Confidential

    Washington DC
    1 day ago
  •  ...ANSER enhances national and homeland security by strengthening public institutions....  ...a Staff Action Officer to serve as a Governance Program Analyst supporting an Office of the Secretary...  ...and external DoW organizations. Ensure compliance with security, protocol, timeline,... 
    Work at office

    Analytic Services Inc

    Alexandria, VA
    2 days ago
  •  ...role involves developing and implementing compliance strategies, ensuring adherence to...  ...regulations, and mitigating compliance risks. The Senior Consultant will be instrumental...  ...these risks, and ensure alignment with government standards. Audit & Assessment : Conduct... 

    Federal Mangement Systems

    Washington DC
    19 hours ago
  •  ...cybersecurity support to U.S. Government agencies and critical infrastructure...  ...is seeking a Zero Trust Analyst to support cybersecurity governance, risk, compliance, and modernization activities in...  ...Responsibilities Assess current-state security architecture and capabilities... 
    Contract work
    For contractors

    Argo Cyber Systems

    Arlington, VA
    2 hours ago
  • $90k - $200k

     ...Senior Manager, Investigations, Diligence, and Compliance - Specialist Kroll’s North American Investigations, Diligence and Compliance practice...  ...intelligence, internal (client) investigations, insider risk compliance assessments, consulting projects and forensic matters... 
    Temporary work
    Flexible hours

    Kroll

    Washington DC
    2 days ago
  •  ...Overview The Compliance and Risk Analyst assists the IT Program Manager in the registration of all Application and Database Management Systems...  ...each mission with a focus on keeping our nation safe and secure. Integral is headquartered in McLean, VA and serves clients... 
    Temporary work
    Work at office
    Immediate start
    Flexible hours

    Integral Services Company

    Falls Church, VA
    3 days ago
  •  ...integrators in the defense and government services industry. We...  ...results to enable national security missions worldwide. Job...  ...SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability...  ...recommendations ·  Support cloud compliance scans and assessment... 
    Contract work
    Work at office
    Worldwide
    Monday to Friday
    Weekend work
    Afternoon shift

    SOSi

    Washington DC
    25 days ago
  •  ...is seeking a Cybersecurity Compliance analyst in Arlington, VA. The roles...  ...analytical expertise of the Risk Management Framework with knowledge...  ...justifications, preparing government client for non-compliant...  ...the IAM/IAT-II level (CompTIA Security+, GSEC, SSCP, or CCNA-... 

    SAIC

    Arlington, VA
    3 days ago
  •  ...Vulnerability Management Analyst Location - Joint Base...  ...- CompTIA Security+ or equivalent About TIME...  ..., reviewing DISA STIG compliance, coordinating remediation...  ...activities, and assisting with Risk Management Framework (...  ..., or other federal government cybersecurity... 
    Temporary work
    Local area
    Flexible hours

    TIME Systems

    District Heights, MD
    4 days ago
  • $90k - $95k

    Technical Business Analyst Imagineeer, LLC — North Bethesda, Maryland...  ...health, defense, homeland security, and transportation. We...  ...production without breaking governance, compliance, or mission continuity. Our...  ...accelerates delivery and reduces risk. If real delivery motivates... 
    Work experience placement
    Local area

    Imagineeer, LLC

    Silver Spring, MD
    5 days ago
  •  ...technology and network solutions for government customers. Founded in 1985, NDi's...  ...The Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst supports the Agency's Office of the...  ...that ICT/OT products and services meet security, integrity, and resilience standards... 
    For contractors
    Work at office

    Network Designs Inc.

    Washington DC
    a month ago
  • $70k - $150k

     ...Associate Manager, Investigations, Diligence and Compliance - Specialist Kroll’s North American Investigations, Diligence and Compliance...  ...adequacy and effectiveness of internal controls, performing insider risk compliance assessments, managing projects and resources,... 
    Temporary work
    Interim role
    Flexible hours

    Kroll

    Washington DC
    1 day ago
  •  ...of Defense and other national security customers. Our Joint Systems...  ...is seeking a Project Control Analyst (PCA) to work closely with Project...  ...to maintain strong overall governance of project budgets, revenue...  ...and followed and potential risks are mitigated. Ensure the accurate... 
    For subcontractor

    DCS Corp

    Alexandria, VA
    4 days ago
  • Risk and Compliance Systems Analyst - Apex Systems Job #: 3015294 Site: Headquarters (HDQ) Business Unit: Fin Tech & Prod Mgmt Description: Hybrid...  ...a skilled contractor to join our Finance Technology Security and Controls team. The team is responsible for security... 
    For contractors
    3 days per week

    Apex Systems

    Merrifield, VA
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Governance Risk & Compliance (GRC) Analyst. Be the first to apply!