Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Compliance Analyst (GRC/RMF Focused)

Quzara LLC

Job Description

Job Description

Job Title: Compliance Analyst (GRC/RMF Focused)

Pay Type : SALARIED EXEMPT

Location: Hybrid, Washington, DC (DMV Area)

Summary of Position Role/Responsibilities

The Compliance Analyst (GRC/RMF Focused) supports governance, risk, and compliance (GRC) initiatives by developing, maintaining, and managing security documentation and compliance artifacts aligned with federal standards. This role plays a key part in supporting Risk Management Framework (RMF) activities, continuous monitoring, and authorization efforts across federal and regulated environments. This role requires strong expertise in NIST SP 800-53, FISMA, and related guidance, with the ability to translate technical system configurations into clear, audit-ready documentation. The ideal candidate is detail-oriented, organized, and capable of managing multiple compliance workstreams while engaging effectively with both technical and non-technical stakeholders.

Essential Functions of the Job

  • Experience authoring and maintaining security documentation, including System Security Plans (SSPs), control implementation statements, policies, and procedures
  • Strong knowledge of NIST SP 800-53 Moderate and High baselines and FISMA requirements
  • Ability to develop documentation in accordance with Agency-specific security and compliance requirements
  • Experience supporting FedRAMP and/or CMMC compliance efforts
  • Working understanding of SOC 2 principles and control structures
  • Hands-on experience with GRC tools
  • Ability to translate technical system configurations into clear, audit-ready documentation
  • Experience developing and managing POA&Ms and supporting continuous monitoring activities
  • Strong understanding of NIST standards and supporting guidance (e.g., 800-60, 800-37, 800-171, 800-137)
  • Ability to engage directly with customers, lead discussions, and clearly communicate requirements to both technical and non-technical stakeholders
  • Strong written and verbal communication skills with a focus on clarity and professionalism
  • Proven ability to manage multiple priorities and meet strict deadlines in a fast-paced environment
  • High attention to detail with strong organizational and documentation management skills
  • Proficiency with standard business tools (e.g., Microsoft Word, Excel, SharePoint, Teams)
  • Technical proficiency with On Prem environments, Cloud environments, and associated security concepts
  • Basic understanding of AI tools and ability to leverage them for documentation development (including effective prompting techniques)
  • Ability to work independently while coordinating effectively across internal teams and stakeholders.

Marginal Functions of the Job

  • Other duties as assigned

Normal Work Schedule

This is a full-time position. Standard business hours are Monday through Friday 8:30 AM to 5:30 PM. Additional time outside of these hours may be needed to complete the essential functions of the job.

Education, Training, and Experience

  • Bachelor’s degree in Cybersecurity, Information Technology, Information Systems, or a related field.
  • 3–6+ years of experience in GRC, RMF, or cybersecurity compliance roles within federal or regulated environments.
  • Strong knowledge of NIST SP 800-53, FISMA, and supporting NIST guidance (e.g., 800-37, 800-60, 800-171, 800-137).
  • Experience supporting FedRAMP, CMMC, and/or SOC 2 compliance efforts.
  • Hands-on experience with GRC platforms and compliance tracking tools.
  • Technical understanding of on-premise and cloud environments and associated security concepts.
  • Proven ability to produce audit-ready documentation and manage compliance artifacts.
  • Strong written and verbal communication skills with the ability to clearly convey complex information.
  • Demonstrated ability to manage multiple projects and deadlines with strong organizational skills.
  • Experience working independently while coordinating across cross-functional teams.
  • Must be a U.S. Citizen and eligible to support federal contracting environments.

Preferred Certifications

  • CISA (Certified Information Systems Auditor)
  • Security+, CISSP, or similar cybersecurity certification
  • FedRAMP or RMF-related training or certifications are a plus

EEO Statement

The Company is an Equal Employment Opportunity (EEO) employer and does not discriminate based on race, color, religion, sex, sexual orientation, national origin, age, marital status, disability, veteran's status, or any other basis protected by applicable discrimination laws.

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Compliance Analyst (GRC/RMF Focused) in Washington DC vacancy
  • $162k - $310k

    About the TeamGovernance, Risk, and Compliance (GRC) is foundational to Security delivering mission...  .... Your creativity and execution-focused approach will be critical in navigating...  ...security frameworks and policies (e.g., NIST, RMF, FedRAMP).Ability to communicate technical... 
    Suggested
    Work at office
    Local area
    Relocation package
    Flexible hours

    OpenAI

    Washington DC
    3 days ago
  • Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the complex landscape of cybersecurity compliance and risk management. You will work directly with clients to assess their... 
    Suggested
    Full time
    Remote work

    Districttechgroup

    Washington DC
    3 days ago
  • $99k - $225k

    Enterprise Cybersecurity GRC Governance AnalystThe Opportunity:...  ...Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an...  ...technical tools. A central focus of this role is identifying...  ...SPs, Risk Management Framework (RMF), Federal Information... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    5 days ago
  • Client Solution Architects (CSA) is seeking an Analyst I to support on-site in the Arlington, VA area. The role focuses on IT portfolio analysis, governance, and enterprise integration for federal contracts and programs. You will develop DoDAF products, validate architecture... 
    Suggested
    Contract work
    For subcontractor

    CSA Global LLC

    Arlington, VA
    16 hours ago
  • A leading federal services provider is seeking a Cybersecurity Analyst in Alexandria, VA. This role includes managing governance, risk, and compliance activities to ensure compliance with DoD requirements. The ideal candidate will have at least 10 years of relevant experience... 
    Suggested

    PingWind Inc

    Alexandria, VA
    16 hours ago
  • $115k - $135k

     ...government clients. Our focus is on enabling our clients...  ...SkyePoint Decisions is seeking a RMF/Assessment & Authorization (A&A) Analyst tosupport the...  ...Operate (ATO) status in compliance with Federal cybersecurity...  ...governance, risk, and compliance (GRC) platforms such as eMASS,... 
    Contract work
    Remote work

    Socket.dev

    Bethesda, MD
    4 days ago
  • $90k - $160k

     ...locate missing children, and more.The RoleAs a GRC Program Manager, you are the engine behind Palantir's Governance, Risk, and Compliance programs. You partner with compliance...  ...stakeholder needs to free up our specialists to focus on the problems they are best equipped to... 
    Full time
    Work experience placement
    Work at office
    Local area
    Immediate start
    Remote work
    Work from home
    Relocation package

    Palantir Technologies

    Washington DC
    5 days ago
  • Zermount, Inc is seeking an ISSO Program Manager to lead security governance and RMF activities for a federal client. This role combines project management with cybersecurity expertise to ensure secure, compliant operations across enterprise systems. The role requires strong... 

    Hiring Our Heroes

    Arlington, VA
    3 days ago
  •  ...Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands-on experience in cybersecurity, compliance, and risk management. The internship... 
    Full time
    Internship

    Ruleset Security

    Arlington, VA
    3 days ago
  •  ...Analysis, Risk Register functional application via Service Now IRM/GRC environment. Significant experience with Service Now...  ...including cross-functional deployments, processes creation and integrations. Nice to have: Privacy (HIPAA) and PCI Compliance experience.... 

    Samprasoft

    Washington DC
    1 day ago
  •  ...Security Compliance Support Role Provides direct support to the Director Security Governance, Risk and Compliance and security shared...  ...and various security solutions. ~ Experience in working with GRC systems/modules. ~ Experience in working across enterprises with... 

    Software Technology Inc

    Washington DC
    5 days ago
  •  ...Operations Consulting Services firm that focuses on providing value to clients through...  ...services/solutions for Risk Management | Compliance | Business Process | IT Effectiveness |...  ...DescriptionProSidian Seeks a Compliance Data Analyst | Human Capital Programmatic Evaluation... 
    Full time
    Contract work
    Temporary work
    For contractors
    H1b
    Work at office
    Flexible hours

    Prosidian Consultng

    Alexandria, VA
    4 days ago
  • $216k - $240k

    About the TeamGovernance, Risk, and Compliance (GRC) is foundational to Security delivering mission outcomes at OpenAI. The GRC team provides...  ...coordinated company office closures throughout the year for focus and recharge, plus paid sick or safe time (1 hour per 30 hours... 
    Work at office
    Local area
    Flexible hours

    OpenAI

    Washington DC
    5 days ago
  • $115k - $125k

     ...Cybersecurity Compliance Analyst ISSO Support | Continuous Monitoring | Security Control Assessments...  ...federal FISMA systems. This role is focused on the day-to-day coordination and...  ..., Security Control Assessments (SCAs), RMF and A&A/ATO support, POA&M tracking,... 
    Full time
    Contract work
    Remote work
    3 days per week

    RCG

    Suitland, MD
    5 hours ago
  • Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands‑on experience in cybersecurity, compliance, and risk management. The internship... 
    Remote job
    Full time
    Internship

    Ruleset Security

    Arlington, VA
    5 days ago
  • SkyePoint Decisions is seeking a Governance, Risk & Compliance (GRC) Analyst to support a cybersecurity program and compliance initiatives by managing governance processes, risk management activities, policy compliance efforts, and audit readiness programs. The GRC Analyst... 
    Remote job

    SkyePoint Decisions

    Bethesda, MD
    5 days ago
  • A cybersecurity compliance consulting firm is looking for a GRC Analyst to help organizations manage cybersecurity compliance and risk. This fully remote position involves conducting assessments, developing security policies, supporting compliance audits, and collaborating... 
    Remote job

    Districttechgroup

    Washington DC
    3 days ago
  • $146k - $194k

     ...to the military in months, not years.ABOUT THE JOBAs a Senior Compliance Analyst, you will serve as a key leader and subject matter expert (...  ...and optimize high-quality Governance, Risk, and Compliance (GRC) documentation, including System Security Plans, POA&Ms, policies... 
    Full time
    Work experience placement
    Immediate start

    Anduril Industries

    Washington DC
    3 days ago
  • $78.9k - $123.3k

     ...seeking a detail-oriented cybersecurity compliance professional to support system authorization...  ...will have experience working with NIST RMF, NIST SP 800-53 controls, security authorization...  ..., and governance, risk, and compliance (GRC) platforms. Knowledge of cloud security... 
    Permanent employment
    Full time
    Part time
    Work at office
    Local area
    Remote work

    Noblis

    Washington DC
    3 days ago
  •  ...services/solutions for Risk Management, Compliance, Business Process, IT Effectiveness, Engineering...  ...Seeks a Contract Compliance Analyst | Compliance / Risk / Regulatory: Risk,...  ...exposure preferred.Skills RequiredPrimarily focused on Management and Financial Consulting,... 
    Full time
    Contract work
    Temporary work
    For contractors
    Work at office
    Remote work
    Flexible hours

    Prosidian Consultng

    Washington DC
    3 days ago
  • A consulting firm seeks a Security & Compliance Analyst to support various client environments, concentrating on security operations, compliance preparedness, and risk management. This hands-on position involves collaboration with IT leadership to ensure effective maintenance... 
    Remote work

    Envision Consulting LLC

    Alexandria, VA
    16 hours ago
  • $86k - $114k

     ...ABOUT THE TEAMAnduril’s International Trade Compliance team is a resourceful and collaborative...  ...seeks an experienced Export Compliance Analyst to help build our Compliance team...  ...processes for complex rules, with a singular focus on helping Anduril deploy its path-making... 
    Full time
    For contractors
    Work experience placement
    Immediate start

    Anduril Industries

    Washington DC
    4 days ago
  • $89k - $105k

     ...Expectations are high, and so are the rewards. The compliance team supporting Robinhood’s credit card...  ...business goals.As Lead Compliance Analyst, you will play a critical role in...  ...with a drive to build compliant, customer-focused financial products.Ability to view Compliance... 
    Work at office
    Flexible hours
    Shift work
    3 days per week

    Robinhood Financial

    Washington DC
    1 day ago
  • SkyePoint Decisions is seeking an RMF/Assessment & Authorization (A&A) Analyst to support the implementation and maintenance of the...  ...stakeholders to ensure ATO status in compliance with Federal requirements. The role focuses on developing and maintaining authorization... 
    Remote job

    Socket.dev

    Bethesda, MD
    4 days ago
  • MDW Associates is seeking a Privacy and Civil Liberties Analyst in Alexandria, VA to support the Privacy and Civil Liberties Division. On-site 3-5 days/week, focusing on Privacy Act compliance, SORNs, PIAs, and PII protection. The role involves drafting and reviewing SORNs... 
    3 days per week

    MDW Associates

    Alexandria, VA
    3 days ago
  • Federal Management Systems is seeking a detail-oriented Junior Compliance Officer in Washington, D.C. This role focuses on data management and compliance auditing, ensuring the integrity of immigration compliance and employment eligibility systems. Key responsibilities... 

    Federal Management Systems

    Washington DC
    3 days ago
  • Northrop Grumman Space Systems seeks a Global Trade Analyst - level 2 to guide export/import compliance for US government programs. You will apply ITAR/EAR knowledge, manage regulatory requests, and coordinate with contracts, supply chain, and engineering teams to ensure... 
    Relocation

    Northrop Grumman

    Mc Lean, VA
    16 hours ago
  • $28.5 per hour

     ...Compliance Analyst This position will support the Foundation's conservation award-making activities by focusing on the areas of compliance and risk analysis relating to the Foundation and its subrecipients and for programmatically funded contractors. Essential Duties... 
    Hourly pay
    Full time
    Contract work
    For contractors
    Local area

    National Fish and Wildlife Foundation

    Washington DC
    1 day ago
  •  ...Compliance Analyst The Compliance Analyst serves as the project compliance expert on a wide portfolio of Clark's government-funded construction...  ...We value candidates who are highly motivated, customer-focused and open-minded team players ready to dig into a highly... 
    For contractors
    Work experience placement
    For subcontractor
    Local area

    Clark Construction Group

    Capitol Heights, MD
    5 days ago
  • $35 - $45 per hour

     ...Labor Compliance Specialist Certified Payroll This role focuses on ensuring full labor and payroll compliance across multiple construction projects by actively monitoring certified payroll records, managing subcontractor setup and documentation in a labor compliance... 
    Contract work
    Temporary work
    Apprenticeship
    For subcontractor
    Work at office
    Remote work
    2 days per week

    Actalent

    Washington DC
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Compliance Analyst (GRC/RMF Focused). Be the first to apply!