Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Governance, Risk & Compliance (GRC) Analyst

CHAOS Industries

Governance, Risk & Compliance (GRC) Analyst

Washington D.C.

CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage—domain dominance. The company's products are powered by Coherent Distributed Networks (CDN™), empowering warfighters, commercial air operators, and border protection teams to act faster, adapt rapidly, and stay ahead of evolving threats.

CHAOS Industries was founded in 2022 and has raised a total of $1 billion in funding from leading investors, including 8VC, Accel, and Valor Equity Partners. The company is headquartered in Los Angeles, with offices in Washington, D.C., San Francisco, San Diego, Seattle, and London. For more information, please visit

Role Overview:

  • Own and mature the CHAOS Industries cybersecurity GRC program by establishing governance structure, policies, standards, expectations, and accountability across CHAOS businesses.
  • You'll report to the IT/Cybersecurity Program Director and work daily with IT, Cybersecurity, Physical Security, and Manufacturing – teams with different priorities and vocabulary; therefore, you'll spend real time translating broad requirements into controls people adopt.
  • Build and manage cybersecurity risk processes, including risk registers, findings, vulnerabilities, remediation plans, ownership, escalation, and business acceptance.
  • If you enjoy designing frameworks that fit the organization rather than forcing the organization to fit a template, and you want direct input into how a defense company governs risk, this is the seat.

Responsibilities:

  • Own risk assessments across several departments and maintain the centralized risk register.
  • Design and maintain a unified, original control framework tailored to CHAOS Industries' operating environment, including a security-by-design approach to systems development and defined: Maximum Tolerable Downtime (MTD), Recovery Point Objective (RPO), and Recovery Time Objective (RTO) for critical systems.
  • Write and maintain policy that goes beyond minimum mandatory compliance, building genuine security maturity rather than satisfying the floor of any one requirement.
  • Manage GRC tooling and related workflows to support risk assessments, control monitoring, and reporting.
  • Prepare for, coordinate, and help run third-party and certification audits, including evidence collection, gap assessments, and auditor liaison.
  • Act as the connective tissue between different department to then develop security and compliance requirements for partner teams and drive them to execution.
  • Report regularly to the Program Director and executive stakeholders on risk posture, audit status, and program maturity.
  • Onsite presence required 4 days per week.
  • Travel: up to 25%, primarily to support Manufacturing and Physical Security control validation across company sites.
  • Physical demands: occasional access to manufacturing floor environments, including required PPE and periods of standing or walking during facility walkthroughs.
  • Support customer, vendor, supplier, and subcontractor cybersecurity risk management, including questionnaires, contract reviews, security expectations, and customer-facing services.
  • Coordinate cybersecurity audits, assessments, evidence requests, customer reviews, and remediation tracking in partnership with Legal, Compliance, commercial teams, IT, and business leaders.

Minimum Requirements:

  • Bachelor's degree or equivalent experience in computer science, cybersecurity, information security, Information Technology, Information Assurance, or a related field, or equivalent practical experience.
  • Deep knowledge of NIST CSF, NIST RMF, the ISO/IEC 27000 series, UK Cyber Essentials, CMMC/NIST 800-171, NIST 800-53.
  • Experience selecting, implementing, or administering GRC tooling and workflows.
  • Exposure to widely recognized governance, risk, and compliance frameworks spanning security, privacy, and quality management domains.
  • Familiarity with OT/ICS security concepts.
  • Minimum of 5 years hands-on GRC or compliance experience combined with prior experience in a DoD environment or military service.
  • Has directly supported a third-party or certification audit from evidence collection through closure.
  • Can apply recognized governance, risk, and compliance frameworks well enough to design real, working controls tailored to a specific organization, not just describe them generically.
  • Has performed or directly supported a formal risk assessment (identification, scoring, and treatment) using a defined methodology.

Preferred Requirements:

  • Experience supporting third-party audits in a cloud-centric environment.
  • Has built or materially contributed to a risk register, control framework, or compliance program, not only operated within one already established elsewhere.
  • Has written policy or procedure documentation that a non-security audience could follow and act on.

Why CHAOS?

  • Health Benefits: Medical, dental, and vision benefits 100% paid for by the company
  • Additional benefits: 401k (+ 50% company match up to 6% of pay), FSA, HSA, life insurance, and more
  • Our Perks: Free daily lunch, 'No meeting Fridays', unlimited PTO, casual dress code
  • Compensation Components: Competitive base salaries, generous pre-IPO stock option grants, relocation assistance, and (coming soon!) annual bonuses
  • Team Growth: 350 employees and counting across 5 global offices
Vacancy posted 12 hours ago
Similar jobs that could be interesting for youBased on the Governance, Risk & Compliance (GRC) Analyst in Washington DC vacancy
  •  ...Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the complex landscape of cybersecurity compliance and risk management. You will work directly with clients to assess their... 
    Suggested
    Full time
    Remote work

    Districttechgroup

    Washington DC
    4 days ago
  • Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands‑on experience in cybersecurity, compliance, and risk management. The internship... 
    Suggested
    Remote job
    Full time
    Internship

    Ruleset Security

    Arlington, VA
    2 days ago
  • Security Compliance Support Role Provides direct support to the Director Security Governance, Risk and Compliance and security shared service team by assuring information system...  ...security solutions. Experience in working with GRC systems/modules. Experience in working... 
    Suggested

    Software Technology Inc

    Washington DC
    1 day ago
  • Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands-on experience in cybersecurity, compliance, and risk management. The internship... 
    Suggested
    Full time
    Internship

    Ruleset Security

    Arlington, VA
    2 days ago
  • $99k - $225k

    Enterprise Cybersecurity GRC Governance AnalystThe Opportunity: The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an experienced Information System Security Officer (ISSO) to bridge the gap between high-level policy and technical... 
    Suggested
    Full time
    Contract work
    Part time
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    2 days ago
  • PBS is seeking a Security Analyst II to mature PBS’s governance, risk, and compliance programs, including risk management, policy development, GRC tooling, and AI governance, while providing hands-on security operations support across cloud and on-prem environments. The... 

    PBS

    Alexandria, VA
    4 days ago
  •  ...practices. ProSidian services focus on the broad spectrum of Risk Management, Compliance, Business Process, IT Effectiveness, Energy &...  ...engagements for Private Companies, Fortune 1,000 Enterprises, and Government Agencies of all sizes. Our Services are deployed across... 
    Contract work
    For contractors
    Work at office
    Flexible hours

    Prosidian Consultng

    Arlington, VA
    4 days ago
  • $96.5k - $110.1k

     ...Overview Senior Risk Specialist, Compliance Governance Analyst The Compliance Governance, Oversight and Validation (CGOV) team within Compliance & Ethics is seeking a collaborative, analytically-focused risk management professional to support our well-managed governance... 
    Full time
    Part time
    Local area
    Immediate start

    Capital One

    McLean, VA
    27 days ago
  •  ...integrators in the defense and government services industry. We deliver...  ...seeking a highly qualified Risk Mitigation Specialist to support...  ...DCSA FOCI policies to ensure compliance with emplaced mitigation...  ...working with enterprise systems or GRC/IRM tools.Preferred... 
    Contract work
    Work at office
    Worldwide

    SOSi

    Washington DC
    1 day ago
  •  ...provides enterprise services/solutions for Risk Management | Compliance | Business Process | IT Effectiveness...  ...and private, defense and civilian government, and non-profit organizations. Our...  ...DescriptionProSidian Seeks a Governance & Risk Analyst | Human Capital Programmatic... 
    Full time
    Contract work
    Temporary work
    For contractors
    H1b
    Work at office
    Flexible hours

    Prosidian Consultng

    Alexandria, VA
    1 day ago
  •  ...Role: GRC Analyst Location: Mount Laurel, NJ/ Fort Lauderdale, FL/ Charlotte, NC - Hybrid: 2 days onsite, 3 days work from home Duration...  ...4.) Ability to work independently Nice-To-Have 1.) Governance, Risk and Controls experience 2.) big 4 consulting firm experience... 
    Work from home

    Spectraforce Technologies

    Laurel, MD
    20 hours ago
  • Job SummaryThe Analyst, AI Model Governance is responsible for supporting the oversight and compliance of AI models within the organization. This role tracks model inventories, conducts risk assessments, and prepares documentation for audits and regulatory inquiries. The... 
    Full time
    Work at office
    Remote work
    Flexible hours

    Marriott International

    Bethesda, MD
    20 hours ago
  •  ...Enterprise Risk Management AnalystWe are seeking an Enterprise Risk Management Analyst to support the Department of State IT Governance Support Services Bureau of Consular Affairs. This position supports the decision-making framework for addressing several enterprise-... 
    Work at office

    Ryde Technologies

    Washington DC
    4 days ago
  • A cybersecurity compliance consulting firm is looking for a GRC Analyst to help organizations manage cybersecurity compliance and risk. This fully remote position involves conducting assessments, developing security policies, supporting compliance audits, and collaborating... 
    Remote job

    Districttechgroup

    Washington DC
    5 days ago
  •  ...cybersecurity architecture and engineering. We are seeking Risk and Compliance Analysts to own the risk, compliance, and supply chain reporting...  ...are risk and compliance experience at a large company or Government agency similar in size and scope to VA, DoD, GSA, or IRS.... 
    Full time
    Contract work
    Interim role
    Work at office
    Remote work

    Triumph Enterprises

    Washington DC
    4 days ago
  •  .... Significant experience with full cycle Risk Management processes, including cATO, Risk...  ...application via Service Now IRM/GRC environment. Significant experience with...  ...creation and integrations. Nice to have: Privacy (HIPAA) and PCI Compliance experience. E-Solutions

    E-Solutions

    Washington DC
    1 day ago
  •  ...and the impact is felt by businesses, governments, and millions of people every day....  ...reading. Overview Socure is seeking an Analyst, GRC - Public Sector to own the hands-on...  ...execution of the company's governance, risk, and compliance operations for its public sector... 
    Permanent employment
    Contract work

    Socure Inc

    Washington DC
    1 day ago
  • $117.2k - $176.7k

     ...hold dual citizenship with the ability to meet customer and government screening standards applicable to this role....  ...stakeholder organizations creating synergies and reducing risk of non-compliance with internal or external requirementsSupport change management... 
    Full time

    Salesforce

    Washington DC
    3 days ago
  • $117.2k - $176.7k

     ...and you are the future of Salesforce.The ExperienceThe Global Compliance and Certification (GCC) team is responsible for enterprise-wide...  ...Salesforce leadership has the information needed to make strategic, risk-based decisions. The GCC team is a division within the Product... 
    Full time

    Salesforce

    Washington DC
    20 hours ago
  •  ...provides enterprise services/solutions for Risk Management | Compliance | Business Process | IT Effectiveness...  ...and private, defense and civilian government, and non-profit organizations. Our...  ...DescriptionProSidian Seeks a Compliance Data Analyst | Human Capital Programmatic... 
    Full time
    Contract work
    Temporary work
    For contractors
    H1b
    Work at office
    Flexible hours

    Prosidian Consultng

    Alexandria, VA
    1 day ago
  • $208.55k - $254.85k

     ...providers.Job Summary:The Director of Governance, Risk and Compliance provides strategic oversight of the Governance Risk and Compliance (GRC) information security team to ensure compliance...  ...— hiring, developing, and retaining analysts across policy, risk assessment, control... 
    Full time
    Casual work
    Work at office
    Local area
    Immediate start
    Flexible hours

    Surescripts

    Arlington, VA
    20 hours ago
  •  ...provides enterprise services/solutions for Risk Management, Compliance, Business Process, IT Effectiveness,...  ...and private, defense and civilian government, and non-profit organizations. Our...  ...DescriptionProSidian Seeks a Contract Compliance Analyst | Compliance / Risk / Regulatory:... 
    Full time
    Contract work
    Temporary work
    For contractors
    Work at office
    Remote work
    Flexible hours

    Prosidian Consultng

    Washington DC
    20 hours ago
  • $47.35 - $76.2 per hour

     ...Senior Manager Of Risk Management And ComplianceThis is a temporary position...  ...Manager of Risk Management and Compliance supports and monitors IT governance and risk management strategies across...  ...disciplineExperience with major enterprise GRC, DevSecOps, cybersecurity... 
    Hourly pay
    Temporary work
    Remote work
    Flexible hours

    Marriott

    Bethesda, MD
    4 days ago
  • $130k - $147k

    Job DescriptionECS is seeking a Senior Business Analyst to work in our Washington, DC (hybrid) office. Please Note:...  ...including national security systems, that are managed in a governance, risk management, compliance (GRC) application, and that are governed by federal laws... 
    Contract work
    Work at office

    ECS Federal

    Washington DC
    1 day ago
  • $100k - $172k

     ...continues to drive and deliver positive impact in the world. As a Risk and Compliance Specialist - Global Trade, you will manage and scale a...  ....Core ResponsibilitiesManage the submission of U.S. government trade controls and customs registrations, authorizations, reports... 
    Full time
    Contract work
    For contractors
    Work experience placement
    Work at office
    Remote work
    Work from home
    Overseas
    Relocation package

    Palantir Technologies

    Washington DC
    20 hours ago
  • $120.8k - $137.9k

     ...Overview Enterprise Risk Organization Governance & Reporting Specialist The Enterprise Risk Organization (ERO) Chief of Staff Team serves...  ...disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital... 
    Full time
    Part time
    Local area

    Capital One

    McLean, VA
    a month ago
  • $87.7k - $100.1k

     ...Overview Senior Risk Associate - Risk, Infrastructure, and Governance Commercial Risk is a first line of defense function which supports our Commercial...  ...with partners within Commercial Risk, Compliance, Legal, and various groups across the organization.... 
    Full time
    Part time
    Work at office
    Local area

    Capital One

    McLean, VA
    14 days ago
  • $90k - $200k

     ...InvestigationsKroll's North American Investigations, Diligence and Compliance practice is seeking a Senior Manager based in the U.S. This is...  ...intelligence, internal (client) investigations, insider risk compliance assessments, consulting projects and forensic matters... 
    Temporary work

    Kroll

    Washington DC
    4 days ago
  • $100k - $130k

     ...its Information Technology Compliance (ITC) team, and we’re looking for an IT Compliance Analyst to help build what comes...  ...and management of NYSE’s risk-based IT compliance program...  ...experience in one or more of: IT Governance, Risk, and Compliance (GRC) IT SDLC or business... 
    Full time
    Work at office
    Monday to Friday

    ICE

    Washington DC
    1 day ago
  • A consulting firm seeks a Security & Compliance Analyst to support various client environments, concentrating on security operations, compliance preparedness, and risk management. This hands-on position involves collaboration with IT leadership to ensure effective maintenance... 
    Remote work

    Envision Consulting LLC

    Alexandria, VA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Governance, Risk & Compliance (GRC) Analyst. Be the first to apply!