Cyber GRC Specialist
$95k - $115kBrown Advisory
Company OverviewEvery firm has a culture – the values, beliefs, methodology, attitudes and standards that reflect an organization’s DNA. But the truly inspiring firms – the game-changers, the industry leaders and the disruptors – have cultures that propel them to innovate and stand out. At Brown Advisory, we aim to be one of those inspired firms. Over the years, we have purposefully built and nurtured our client-first culture.Brown Advisory is an independent investment management and strategic advisory firm committed to delivering a combination of first-class performance, strategic advice and the highest level of client service. The firm’s clients—including individuals, families, family offices, endowments, foundations, charities, institutions, consultants, and financial intermediaries—are served by over 1,000 colleagues worldwide, all of whom are equity owners of the firm.Brown Advisory is currently seeking a Cyber GRC Specialist to support and mature the firm's governance, risk, compliance, and control-management routines. This blended role is designed for someone who can translate security requirements into practical business processes, drive evidence and accountability, and communicate clearly with technical and non-technical stakeholders.As part of a lean Information Security team within a mid-sized financial services organization, this individual will serve as a central coordinator for cyber risk, policy management, control testing, audit readiness, client and regulatory response support, and vulnerability remediation governance. The role is not intended to be a hands-on vulnerability engineering role; rather, it ensures the process, ownership, exceptions, reporting, and governance routines are working.Blended Role CoveragePrimary emphasis: Cyber GRC support for policies, controls, cyber risk tracking, audit coordination, exceptions, and governance routines.Blended coverage: Cyber Risk / Compliance Analyst work, ISO and risk-platform support, evidence coordination, client/regulatory response support, communications, and vulnerability governance.Duties and ResponsibilitiesSupport and mature core cyber governance routines, including policy management, control ownership, risk acceptance, exception handling, standards maintenance, and periodic leadership reporting.Maintain the cyber risk register and partner with technology and business owners to document risk decisions, remediation plans, due dates, dependencies, and residual risk.Serve as a key administrator and process contributor for ISO and security-risk management platforms such as Vanta or similar tools.Coordinate evidence collection, control testing, audit requests, client due diligence responses, regulatory requests, and recurring compliance deliverables.Translate ISO 27001, regulatory, client, and internal security expectations into practical controls and operating procedures appropriate for Brown Advisory's size and risk profile.Facilitate cross-functional communications for security change, SaaS inventory, policy enforcement, control adoption, and risk remediation.Coordinate vulnerability management governance, including scan-result intake, prioritization routines, remediation tracking, exception handling, and reporting.Partner with security engineers, infrastructure teams, application owners, Compliance, Legal, Operations, and Client Service to close control gaps in a business-aligned manner.Develop clear metrics for control effectiveness, audit readiness, exceptions, overdue remediation, and recurring governance activities.Identify process improvements that make security governance more repeatable, transparent, and useful without creating unnecessary bureaucracy.Preferred QualificationsBachelor's degree in cyber security, information systems, risk management, business, or a relevant field preferred; equivalent professional experience will be considered.3-6 years of experience in cyber GRC, information security, technology risk, IT audit, compliance, or related control-management work preferred.Working knowledge of ISO 27001, SOC 2, NIST CSF, CIS Controls, SEC/FINRA expectations, privacy requirements, or comparable control frameworks.Experience supporting audits, evidence collection, control testing, policy updates, issue tracking, or risk-register maintenance in a regulated environment; financial services experience preferred.CISA, CRISC, CISM, Security+, ISO 27001 Foundation/Lead Implementer, or similar professional designation preferred but not required.Technical SkillsCyber risk registers, exception management, control testing, evidence management, policy lifecycle management, and audit coordination.GRC or trust-management platforms such as Vanta, Archer, ServiceNow GRC, OneTrust, Drata, or similar tools.Vulnerability management governance, including prioritization, remediation tracking, aging analysis, exception workflows, and executive reporting.Strong knowledge of cyber security controls across identity, endpoint, cloud, network, data protection, application security, and third-party risk.Excellent writing, facilitation, and stakeholder-management skills, including the ability to turn technical risk into clear business language.Practical judgment about when to enforce, when to escalate, and when to help the business find a workable control path.Demonstrates curiosity and a continuous improvement mindset by identifying opportunities to enhance processes, improve efficiency, and thoughtfully leverage new technologies and tools, including AI-enabled productivity solutionsPersonal AttributesTake ownership and move initiatives forward without constant oversight.Balance technical depth, process discipline, and sound business judgment.Approach risk management pragmatically rather than theoretically.Thrive in collaborative, high-accountability environments.Communicate clearly with technical and non-technical colleagues.Bring an entrepreneurial mindset to building and improving security capabilities.Applicants must be authorized to work in the United States without the need for current or future employer-sponsored work authorization (e.g., H-1B , O-1, F-1 (OPT), TN, or any other non-immigrant visa classifications that require employer support or sponsorship).MD Salary: $95-$115k. Commensurate with experience and location. Does not include bonus or long term incentive eligibility (if applicable).BenefitsAt Brown Advisory we offer a competitive compensation package, including full benefits.• Medical• Dental• Vision• Wellness program participation incentive• Financial wellness program• Fitness event fee reimbursement• Gym membership discounts• Colleague Assistance Program• Telemedicine Program (for those enrolled in Medical)• Adoption Benefits• Daycare late pick-up fee reimbursement• Basic Life & Accidental Death & Dismemberment Insurance• Voluntary Life & Accidental Death & Dismemberment Insurance• Short Term Disability• Paid parental leave• Group Long Term Disability• Pet Insurance• 401(k) (50% employer match up to IRS limit, 4 year vesting)Brown Advisory is an Equal Employment Opportunity Employer.SummaryLocation: Baltimore, MDType: Full time
$80k - $128k
ResponsibilitiesPeraton is seeking a Partner Experience Specialist in our Linthicum, MD office in support of our Department of Defense (DoD... ...offers a unique opportunity to work at the forefront of cyber investigations, digital forensics, cyber threat analysis, and mission...CyberContract workWork at officeShift work$104.24k - $156.36k
...Overview About M.C. Dean M.C. Dean is Building Intelligence. We design, build, operate, and maintain cyber-physical solutions for the nation's most mission-critical facilities, secure environments, complex infrastructure, and global enterprises. With over 7,00...Cyber- ...0. Lead the annual enterprise technology and cybersecurity risk assessment. Establish an automated technology and cyber governance risk and compliance (GRC) program to continuously monitor and report on technology and cyber risk and control effectiveness. Lead the company...CyberFull timeWork at officeShift work
$140k - $150k
...exception records, and implementation documentation in partnership with GRC and technology owners.Execute immediate remediation actions where... ...leadership.Preferred QualificationsBachelor's degree in cyber security, computer science, engineering, information systems, or...CyberFull timeTemporary workH1bImmediate startWorldwide$110k - $135k
...documentation, metrics, and leadership reporting in partnership with GRC.Drive remediation of identity-related audit findings, penetration... ...unnecessarily.Preferred QualificationsBachelor's degree in cyber security, computer science, information systems, engineering, or...CyberFull timeTemporary workFor contractorsH1bWorldwide$121.9k - $219.41k
...making support through analysis and recommendations and escalation of cyber risk decisions to appropriate committees. • Manage stakeholder... ...program management, governance, risk, and compliance (GRC), or a related field.Experience conducting or facilitating assessment...CyberPermanent employmentImmediate start$84k - $156k
...mind, our employees deliver end‑to‑end technology solutions connecting the space, air, land, sea and cyber domains in the interest of national security. Job Title: Specialist, Quality Engineer Job Code: 39717 Job Location: Hanover, MD Job Schedule: 9/80 We are looking for...CyberLocal areaFlexible hours- ...estate transactions seeking an experienced full-time Post Closing Specialist for our team in Catonsville, MD. This is a full-time, on... ...and remitting final water bills -Staying up to date on cyber security and industry regulations Qualifications: -Minimum...CyberFull timeWork at officeNight shift
- ...operational intelligence, counter unmanned aerial systems and cyber security. TechINT Solutions Group has developed a unique analytical... .... TechINT is currently looking for a Cyber Exploitation Specialist position on the REACT contract to support the C5ISR Center at Aberdeen...CyberFull timeContract work
$140.61k - $253.08k
...serves as the strategic leader in advancing global technology and cyber risk coverage while simultaneously acting as the function’s... ...natural language processing for document review, anomaly detection, GRC platform enhancements).Embed data-driven risk management techniques...CyberPermanent employment$84k - $156k
...mind, our employees deliver end‑to‑end technology solutions connecting the space, air, land, sea and cyber domains in the interest of national security. Job Title: Specialist, Quality Engineer Job Code: 39717 Job Location: Hanover, MD Job Schedule: 9/80 We are looking for...CyberLocal areaFlexible hours$135.9k - $238.4k
...Officer (“Associate General Counsel”), to serve as a trusted advisor to the University, with a primary focus on privacy, information and cyber security, and data governance. The Associate General Counsel will also advise on digital accessibility, records management, and a...CyberFull timeWork at officeMonday to Friday- DescriptionSAIC is seeking a Damage Assessment Management Office (DAMO) Cyber Triage Analyst with an active Top Secret clearance to support the Office of the Under Secretary of Defense for Research and Engineering (OUSD R&E) Damage Assessment Management Office (DAMO) Defense...CyberWork experience placementWork at office
- Morgan State University invites applicants for a grant-funded contractual full-time position to support the inaugural Office of Research Compliance. The Research Compliance Administrator will oversee the Research Security Program, developing procedures, training, and compliance...CyberFull timeWork at office
$160k - $230k
As the Global Cyber and Intelligence Partnerships Lead, you will establish, build, and manage relationships with key stakeholders across government, the intelligence community, peer financial institutions, and cybersecurity associations. You will play a critical role in...CyberTemporary work- .../project management, applications development, infrastructure, Cyber security, and enterprise content/data management services. We have... ...project type and how role supports The Security Operations Specialist will be responsible for operating and maintaining security tools...CyberFor contractorsWork at office
$163.4k - $322.1k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities... ...(IRM), governance, risk, and compliance (GRC), and Security Operations (SecOps)... ...Developer, Certified Implementation Specialist, Certified Technical Architect, Certified...CyberLocal areaVisa sponsorship- ...recognized for its expertise in providing innovative technology exploitation, operational intelligence, counter unmanned aerial systems, and cyber security. We have developed a unique analytical methodology to identify technologies that could be used for illicit purposes....CyberRemote work
$134.5k - $265.1k
Position Summary Deloitte’s Cyber Services help our clients to be secure, vigilant, and resilient in the face of an ever-increasing array of cyber threats and vulnerabilities. Our Cyber Risk practice helps organizations with the management of information and technology...CyberLocal areaVisa sponsorship$239k - $278.75k
...and priority outcomes for value realization, collaborating with specialists to develop business cases around measurable benefits.Conduct... ...leadership across relevant technologies (e.g., security technologies, cyber threat intelligence, risk and regulatory topics, emerging...CyberFull timeRemote workVisa sponsorshipWork visa$135k - $216k
...highly talented, highly motivated, and high-performing team. This position offers a unique opportunity to work at the forefront of cyber investigations, digital forensics, cyber threat analysis, and mission support in a dynamic and collaborative environment. The successful...CyberContract workWork at officeShift work- ...A large Engineering customer of Marathon TS is seeking an experienced Cyber Security Specialist to join their dynamic team. Position Responsibilities: Conduct ICS/SCADA system inventories following guidance including, but not limited to U.S. Army ICS Inventory...Cyber
$128.82k - $203.15k
...organization’s IT policies and procedures and developing and implementing strategies to safeguard the organization’s digital assets against cyber threats and ensure that all digital products meet accessibility standards. The CIO will also play a crucial role in fostering a...CyberWork at officeLocal areaRemote work3 days per week- ...real world. Our team of software and systems engineers bring experience working with cutting-edge advancements in cryptography, cyber-physical systems, MBSE, and formal methods for both government and commercial applications. We leverage a unique suite of...CyberFull timeContract workRemote workFlexible hours
$82.6k - $162.8k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity... ...readiness.Collaborating with business stakeholders, cyber specialists, developers, testers, and alliance/vendor teams to drive delivery...CyberLocal areaVisa sponsorship$134.5k - $265.1k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions...CyberLocal areaVisa sponsorship$107.93k - $188k
...You’ll DoAs a Senior Consultant, Enterprise Security on the GPS Cyber team, you will be responsible for…Designing and implementing... ...Security Engineer Associate, or Certified Kubernetes Security Specialist (CKS)The wage range for this role takes into account the wide range...CyberLocal area$146k - $234k
...highly talented, highly motivated, and high-performing team. This position offers a unique opportunity to work at the forefront of cyber investigations, digital forensics, cyber threat analysis, and mission support in a dynamic and collaborative environment. The successful...CyberFull timeContract workWork at officeMonday to FridayShift work- We’re seeking someone to join our team as a Cyber Threat Intelligence - Technical Analysis and Investigations Lead in Technology to... ...at VP which is part of the job family responsible for providing specialist cyber expertise and creating solutions that protect the organization...CyberTemporary workLocal area
- Position Summary Deloitte’s Cyber team helps clients address evolving cybersecurity challenges and opportunities by delivering solutions and managed services that reduce complexity, strengthen resilience, and support confident growth. As a Google SecOps Manager supporting...CyberLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber GRC Specialist. Be the first to apply!
- mental health specialist Baltimore, MD
- instructional technology specialist Baltimore, MD
- resolution specialist Baltimore, MD
- independent living specialist Baltimore, MD
- criminal justice specialist Baltimore, MD
- delivery assurance specialist Baltimore, MD
- entry level safety specialist Baltimore, MD
- senior specialist Baltimore, MD
- restaurant specialist Baltimore, MD
- wellness specialist Baltimore, MD


