Compliance Analyst (GRC/RMF Focused)
Quzara LLC
Job Description
Job Description
Job Title: Compliance Analyst (GRC/RMF Focused)
Pay Type : SALARIED EXEMPT
Location: Hybrid, Washington, DC (DMV Area)
Summary of Position Role/Responsibilities
The Compliance Analyst (GRC/RMF Focused) supports governance, risk, and compliance (GRC) initiatives by developing, maintaining, and managing security documentation and compliance artifacts aligned with federal standards. This role plays a key part in supporting Risk Management Framework (RMF) activities, continuous monitoring, and authorization efforts across federal and regulated environments. This role requires strong expertise in NIST SP 800-53, FISMA, and related guidance, with the ability to translate technical system configurations into clear, audit-ready documentation. The ideal candidate is detail-oriented, organized, and capable of managing multiple compliance workstreams while engaging effectively with both technical and non-technical stakeholders.
Essential Functions of the Job
- Experience authoring and maintaining security documentation, including System Security Plans (SSPs), control implementation statements, policies, and procedures
- Strong knowledge of NIST SP 800-53 Moderate and High baselines and FISMA requirements
- Ability to develop documentation in accordance with Agency-specific security and compliance requirements
- Experience supporting FedRAMP and/or CMMC compliance efforts
- Working understanding of SOC 2 principles and control structures
- Hands-on experience with GRC tools
- Ability to translate technical system configurations into clear, audit-ready documentation
- Experience developing and managing POA&Ms and supporting continuous monitoring activities
- Strong understanding of NIST standards and supporting guidance (e.g., 800-60, 800-37, 800-171, 800-137)
- Ability to engage directly with customers, lead discussions, and clearly communicate requirements to both technical and non-technical stakeholders
- Strong written and verbal communication skills with a focus on clarity and professionalism
- Proven ability to manage multiple priorities and meet strict deadlines in a fast-paced environment
- High attention to detail with strong organizational and documentation management skills
- Proficiency with standard business tools (e.g., Microsoft Word, Excel, SharePoint, Teams)
- Technical proficiency with On Prem environments, Cloud environments, and associated security concepts
- Basic understanding of AI tools and ability to leverage them for documentation development (including effective prompting techniques)
- Ability to work independently while coordinating effectively across internal teams and stakeholders.
Marginal Functions of the Job
- Other duties as assigned
Normal Work Schedule
This is a full-time position. Standard business hours are Monday through Friday 8:30 AM to 5:30 PM. Additional time outside of these hours may be needed to complete the essential functions of the job.
Education, Training, and Experience
- Bachelor’s degree in Cybersecurity, Information Technology, Information Systems, or a related field.
- 3–6+ years of experience in GRC, RMF, or cybersecurity compliance roles within federal or regulated environments.
- Strong knowledge of NIST SP 800-53, FISMA, and supporting NIST guidance (e.g., 800-37, 800-60, 800-171, 800-137).
- Experience supporting FedRAMP, CMMC, and/or SOC 2 compliance efforts.
- Hands-on experience with GRC platforms and compliance tracking tools.
- Technical understanding of on-premise and cloud environments and associated security concepts.
- Proven ability to produce audit-ready documentation and manage compliance artifacts.
- Strong written and verbal communication skills with the ability to clearly convey complex information.
- Demonstrated ability to manage multiple projects and deadlines with strong organizational skills.
- Experience working independently while coordinating across cross-functional teams.
- Must be a U.S. Citizen and eligible to support federal contracting environments.
Preferred Certifications
- CISA (Certified Information Systems Auditor)
- Security+, CISSP, or similar cybersecurity certification
- FedRAMP or RMF-related training or certifications are a plus
EEO Statement
The Company is an Equal Employment Opportunity (EEO) employer and does not discriminate based on race, color, religion, sex, sexual orientation, national origin, age, marital status, disability, veteran's status, or any other basis protected by applicable discrimination laws.
- A federal services provider is seeking a Cybersecurity Analyst in Alexandria, VA, focused on governance, risk, and compliance (GRC) activities. The ideal candidate should have a minimum of 10 years of relevant experience and senior-level cybersecurity certifications. You...Suggested
- ...Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the complex landscape of cybersecurity compliance and risk management. You will work directly with clients to assess their...SuggestedFull timeRemote work
$162k - $310k
...office closures throughout the year for focus and recharge, plus paid sick or safe time... .... About the Team Governance, Risk, and Compliance (GRC) is foundational to Security delivering... ...security frameworks and policies (e.g., NIST, RMF, FedRAMP). Ability to communicate...SuggestedFull timeWork at officeLocal areaRelocation packageFlexible hours$130k - $180k
...’ll help build a cutting edge security compliance program aligned with FedRAMP, SOC 2, PCI... ...secure and performant service. As a GRC Analyst at Virtru, you will be the primary... ...annual Learning & Development Stipend focused on providing you the resources to continually...SuggestedRemote jobLocal areaFlexible hoursShift work- ...Job Description Job Description Salary: RMF / Compliance Analyst Position Overview The RMF / Compliance Analyst provides hands-on support... ...documentation. Experience using Archer or comparable GRC/security documentation platforms. Strong technical...SuggestedContract work
$130k - $216k
...Sr. ServiceNow GRC Business Analyst This position is listed on behalf of a partner company, who... ...is a senior-level consulting position focused on leading ServiceNow-driven... ...strong emphasis on Governance, Risk, and Compliance (GRC). You will act as a key bridge between...Temporary work- A leading federal services provider is seeking a Cybersecurity Analyst in Alexandria, VA. This role includes managing governance, risk, and compliance activities to ensure compliance with DoD requirements. The ideal candidate will have at least 10 years of relevant experience...
$98k - $163k
...Will Do:Guidehouse is seeking an IT Audit & Compliance professional to help our client at a... ...federal cybersecurity frameworks. This role focuses on audit preparation and coordination.... ...security and privacy controls), NIST SP 800‑37 (RMF), NIST SP 800‑171 (CUI), FISMA, FISCAM,...Flexible hours- ...Apogee Global RMS is seeking a GRC / NIST RMF Specialist to support federal programs requiring disciplined governance, risk, and compliance execution. This role is built for practitioners who understand the full lifecycle of NIST RMF, can translate controls into actionable...
- ...The Governance, Risk, and Compliance (GRC) Analyst supporting federal and customer programs is responsible for evaluating, documenting, and operationalizing cybersecurity and compliance requirements across the organization. This position works across contractual obligations...Contract work
- ...Security Compliance Support Role Provides direct support to the Director Security Governance, Risk and Compliance and security shared... ...and various security solutions. ~ Experience in working with GRC systems/modules. ~ Experience in working across enterprises with...
- ...A cybersecurity compliance consulting firm is looking for a GRC Analyst to help organizations manage cybersecurity compliance and risk. This fully remote position involves conducting assessments, developing security policies, supporting compliance audits, and collaborating...Remote work
- ...holds a high bar for itself — keep reading. About the Role Socure is seeking an Analyst, GRC – Public Sector to execute and enhance the company's governance, risk, and compliance operations for its public sector business. Reporting to the Director of GRC – Public...Permanent employmentContract workRemote work
$84k - $100k
...GRC Analyst Uplight is creating a new category of energy. We make software that manages energy resources in homes and businesses—including... ...sales and operations functions by managing security and compliance-related tasks such as completing Request for Proposals and...Local areaFlexible hoursShift work- ...functional application via Service Now IRM/GRC environment. Significant experience... ...processes creation and integrations. Nice to have: Privacy (HIPAA) and PCI Compliance experience. Required Skills : Business Analysis Additional Skills : Business Analyst
- BCG Attorney Search is seeking a mid-level healthcare associate for a law firm in Washington, DC. This role will focus on pharmacy, pharmaceutical supply chain, PBM, and reimbursement matters while addressing complex regulatory and commercial issues. The candidate should...
- ...experienced Project Manager to support the Enterprise Compliance organization in the implementation and integration of a... ...tool within the broader Governance, Risk, and Compliance (GRC) ecosystem. This role will focus on assisting in driving the execution of the system...Contract workWork at office
- Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands-on experience in cybersecurity, compliance, and risk management. The internship...Full timeInternship
- Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands‑on experience in cybersecurity, compliance, and risk management. The internship...Remote jobFull timeInternship
- ...LLC is looking for a Customer Success Program Manager to oversee GRC services for federal agencies in Washington DC. The role... ...remote but may require on-site work in DC. Join a dynamic company focused on innovation and customer service excellence! #J-18808-Ljbffr...Remote job
- OpenAI is seeking a GRC Program Manager in Washington, DC, to drive ATO processes for FedRAMP and other government clients. This role involves collaborating with engineering teams, creating compliance documentation, and acting as a subject matter expert during audits....Relocation package
- ...Compliance Analyst The Compliance Analyst serves as the project compliance expert on a wide portfolio of Clark's government-funded construction... ...We value candidates who are highly motivated, customer-focused and open-minded team players ready to dig into a highly...For contractorsWork experience placementFor subcontractorLocal area
- ...senior-level experience, a strong knowledge of NIST RMF, and demonstrated leadership in managing large,... ...senior Government representatives and ensure compliance with security protocols. A competitive benefits package and focus on employee culture are included. #J-18808-...
- ...LIS Solutions is seeking a Junior Compliance Officer to join their team in Arlington, VA. This role focuses on supporting federal law enforcement by handling sensitive data and conducting audits related to Employment Eligibility Verification Forms (I-9). The ideal candidate...Work at office
- ...Compliance Analyst Compliance Analyst Location: Arlington, VA (On-Site) Citizenship: US only Clearance: Active TS/SCI (DHS EOD Suitability... .... ~ CAP, CISSP, CISM, Security+. ~ Experience with GRC tools and federal compliance programs. ~ Ability to brief...Contract workFor contractors
- ...Compliance Data Analyst ProSidian is a Management And Operations Consulting Services firm that focuses on providing value to clients through tailored solutions based on industry-leading practices. ProSidian provides enterprise services/solutions for Risk Management...Contract workH1bWork at office
$125k - $290k
...employees and encourage them to pursue their ambitions. Weaver focuses on helping people lead balanced, integrated lives, supported... ...Commercial Tax Manager or Senior Manager provides federal tax compliance and planning services to large middle market and public companies...Flexible hours$100k - $130k
...total customer satisfaction has remained the cornerstone of our business. Our business model focuses on integrity, loyalty, and trust. Position Overview The Compliance Analyst Level IV provides expertise on special projects, advising senior management and law enforcement...Permanent employmentContract workTemporary workWork at officeFlexible hours$101.25k - $136.5k
...business in a secure environment. Job Summary We are seeking a Privacy Compliance Analyst with strong expertise in HIPAA regulations to support enterprise privacy initiatives. This role focuses on ensuring compliance with the HIPAA Privacy Rule across operational processes...Temporary work- ...government contracting firm based in Washington DC is seeking a qualified Vetting Analyst. In this role, you will assist customers in processing vetting requests from federal agencies, focusing on research, case analysis, and report preparation. Candidates should have a...Contract workWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Compliance Analyst (GRC/RMF Focused). Be the first to apply!
- governance risk & compliance analyst Washington DC
- regulatory officer Washington DC
- regulatory affairs specialist Washington DC
- information security compliance analyst Washington DC
- regulatory compliance specialist Washington DC
- compliance coordinator Washington DC
- compliance consultant Washington DC
- junior compliance officer Washington DC
- senior compliance analyst Washington DC
- regulatory affairs consultant Washington DC


