Compliance Analyst (GRC/RMF Focused)
CL 1e6d8f31 073f 48cd b324 b581c00084bf
Job Title: Compliance Analyst (GRC/RMF Focused) Pay Type: SALARIED EXEMPT Location: Hybrid, Washington, DC (DMV Area) Summary of Position Role/Responsibilities The Compliance Analyst (GRC/RMF Focused) supports governance, risk, and compliance (GRC) initiatives by developing, maintaining, and managing security documentation and compliance artifacts aligned with federal standards. This role plays a key part in supporting Risk Management Framework (RMF) activities, continuous monitoring, and authorization efforts across federal and regulated environments. This role requires strong expertise in NIST SP 800-53, FISMA, and related guidance, with the ability to translate technical system configurations into clear, audit‑ready documentation. The ideal candidate is detail‑oriented, organized, and capable of managing multiple compliance workstreams while engaging effectively with both technical and non‑technical stakeholders. Essential Functions of the Job Experience authoring and maintaining security documentation, including System Security Plans (SSPs), control implementation statements, policies, and procedures Strong knowledge of NIST SP 800-53 Moderate and High baselines and FISMA requirements Ability to develop documentation in accordance with Agency‑specific security and compliance requirements Experience supporting FedRAMP and/or CMMC compliance efforts Working understanding of SOC 2 principles and control structures Hands‑on experience with GRC tools Ability to translate technical system configurations into clear, audit‑ready documentation Experience developing and managing POA&Ms and supporting continuous monitoring activities Strong understanding of NIST standards and supporting guidance (e.g., 800-60, 800-37, 800-171, 800-137) Ability to engage directly with customers, lead discussions, and clearly communicate requirements to both technical and non‑technical stakeholders Strong written and verbal communication skills with a focus on clarity and professionalism Proven ability to manage multiple priorities and meet strict deadlines in a fast‑paced environment High attention to detail with strong organizational and documentation management skills Proficiency with standard business tools (e.g., Microsoft Word, Excel, SharePoint, Teams) Technical proficiency with On Prem environments, Cloud environments, and associated security concepts Basic understanding of AI tools and ability to leverage them for documentation development (including effective prompting techniques) Ability to work independently while coordinating effectively across internal teams and stakeholders. Marginal Functions of the Job Other duties as assigned Normal Work Schedule This is a full‑time position. Standard business hours are Monday through Friday 8:30 AM to 5:30 PM. Additional time outside of these hours may be needed to complete the essential functions of the job. Education, Training, and Experience Bachelor’s degree in Cybersecurity, Information Technology, Information Systems, or a related field. 3–6+ years of experience in GRC, RMF, or cybersecurity compliance roles within federal or regulated environments. Strong knowledge of NIST SP 800-53, FISMA, and supporting NIST guidance (e.g., 800-37, 800-60, 800-171, 800-137). Experience supporting FedRAMP, CMMC, and/or SOC 2 compliance efforts. Hands‑on experience with GRC platforms and compliance tracking tools. Technical understanding of on‑premise and cloud environments and associated security concepts. Proven ability to produce audit‑ready documentation and manage compliance artifacts. Strong written and verbal communication skills with the ability to clearly convey complex information. Demonstrated ability to manage multiple projects and deadlines with strong organizational skills. Experience working independently while coordinating across cross‑functional teams. Must be a U.S. Citizen and eligible to support federal contracting environments. Preferred Certifications CISA (Certified Information Systems Auditor) Security+, CISSP, or similar cybersecurity certification FedRAMP or RMF‑related training or certifications are a plus EEO Statement The Company is an Equal Employment Opportunity (EEO) employer and does not discriminate based on race, color, religion, sex, sexual orientation, national origin, age, marital status, disability, veteran's status, or any other basis protected by applicable discrimination laws. #J-18808-Ljbffr CL 1e6d8f31 073f 48cd b324 b581c00084bf
$162k - $310k
About the TeamGovernance, Risk, and Compliance (GRC) is foundational to Security delivering mission... .... Your creativity and execution-focused approach will be critical in navigating... ...security frameworks and policies (e.g., NIST, RMF, FedRAMP).Ability to communicate technical...SuggestedWork at officeLocal areaRelocation packageFlexible hours- Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the complex landscape of cybersecurity compliance and risk management. You will work directly with clients to assess their...SuggestedFull timeRemote work
- ...Confiz is hiring a GRC Data Analyst / Program Management professional to support privacy assessment and compliance initiatives. This role will help advance the privacy program by... ...startups. What makes Confiz stand out is our focus on processes and culture. Confiz is ISO 90...SuggestedTemporary workRemote workMonday to FridayMonday to Thursday
$99k - $225k
Enterprise Cybersecurity GRC Governance AnalystThe Opportunity:... ...Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an... ...technical tools. A central focus of this role is identifying... ...SPs, Risk Management Framework (RMF), Federal Information...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work- A leading federal services provider is seeking a Cybersecurity Analyst in Alexandria, VA. This role includes managing governance, risk, and compliance activities to ensure compliance with DoD requirements. The ideal candidate will have at least 10 years of relevant experience...Suggested
$115k - $135k
...government clients. Our focus is on enabling our clients... ...SkyePoint Decisions is seeking a RMF/Assessment & Authorization (A&A) Analyst tosupport the... ...Operate (ATO) status in compliance with Federal cybersecurity... ...governance, risk, and compliance (GRC) platforms such as eMASS,...Contract workRemote work- ...specialist to maintain Authority to Operate (ATO) by enforcing RMF, STIGs, and data protection standards. The role requires DoD 85... ...vulnerability reporting to protect PII/PHI. Join a team dedicated to compliance and risk management for federal systems. #J-18808-Ljbffr E...
$90k - $160k
...locate missing children, and more.The RoleAs a GRC Program Manager, you are the engine behind Palantir's Governance, Risk, and Compliance programs. You partner with compliance... ...stakeholder needs to free up our specialists to focus on the problems they are best equipped to...Full timeWork experience placementWork at officeLocal areaImmediate startRemote workWork from homeRelocation package- Zermount, Inc is seeking an ISSO Program Manager to lead security governance and RMF activities for a federal client. This role combines project management with cybersecurity expertise to ensure secure, compliant operations across enterprise systems. The role requires strong...
- ...Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands-on experience in cybersecurity, compliance, and risk management. The internship...Full timeInternship
- ...partners within the client Corporate Center. Job Title: GRC Analyst II Location: Seattle,WA 98101 Duration: 3 Months... ...aligned and reflect ongoing changes to Nordstrom risk and compliance posture Identify opportunities for operational improvements...Temporary work
- ...Operations Consulting Services firm that focuses on providing value to clients through... ...services/solutions for Risk Management | Compliance | Business Process | IT Effectiveness |... ...DescriptionProSidian Seeks a Compliance Data Analyst | Human Capital Programmatic Evaluation...Full timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
- SkyePoint Decisions is seeking a Governance, Risk & Compliance (GRC) Analyst to support a cybersecurity program and compliance initiatives by managing governance processes, risk management activities, policy compliance efforts, and audit readiness programs. The GRC Analyst...Remote job
- A cybersecurity compliance consulting firm is looking for a GRC Analyst to help organizations manage cybersecurity compliance and risk. This fully remote position involves conducting assessments, developing security policies, supporting compliance audits, and collaborating...Remote job
- Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands‑on experience in cybersecurity, compliance, and risk management. The internship...Remote jobFull timeInternship
$78.9k - $123.3k
...seeking a detail-oriented cybersecurity compliance professional to support system authorization... ...will have experience working with NIST RMF, NIST SP 800-53 controls, security authorization... ..., and governance, risk, and compliance (GRC) platforms. Knowledge of cloud security...Permanent employmentFull timePart timeWork at officeLocal areaRemote work- ...Compliance Data Analyst ProSidian is a Management And Operations Consulting Services firm that focuses on providing value to clients through tailored solutions based on industry-leading practices. ProSidian provides enterprise services/solutions for Risk Management...Contract workH1bWork at office
- A consulting firm seeks a Security & Compliance Analyst to support various client environments, concentrating on security operations, compliance preparedness, and risk management. This hands-on position involves collaboration with IT leadership to ensure effective maintenance...Remote work
- ...services/solutions for Risk Management, Compliance, Business Process, IT Effectiveness, Engineering... ...Seeks a Contract Compliance Analyst | Compliance / Risk / Regulatory: Risk,... ...exposure preferred.Skills RequiredPrimarily focused on Management and Financial Consulting,...Full timeContract workTemporary workFor contractorsWork at officeRemote workFlexible hours
$86k - $114k
...ABOUT THE TEAMAnduril’s International Trade Compliance team is a resourceful and collaborative... ...seeks an experienced Export Compliance Analyst to help build our Compliance team... ...processes for complex rules, with a singular focus on helping Anduril deploy its path-making...Full timeFor contractorsWork experience placementImmediate start- SkyePoint Decisions is seeking an RMF/Assessment & Authorization (A&A) Analyst to support the implementation and maintenance of the... ...stakeholders to ensure ATO status in compliance with Federal requirements. The role focuses on developing and maintaining authorization...Remote job
- Federal Management Systems is seeking a detail-oriented Junior Compliance Officer in Washington, D.C. This role focuses on data management and compliance auditing, ensuring the integrity of immigration compliance and employment eligibility systems. Key responsibilities...
- At Nubank, Compliance is a strategic partner—not a tollgate. We view effective Risk Management... ...using a targeted friction approach: we focus on the most relevant regulatory risks... ...We are seeking an experienced Compliance Analyst with 5-8 years of dedicated compliance,...Fixed term contractWork experience placementLocal area
- Guidehouse is seeking a Management Analyst to support the National Cancer Institute, CCR, in Bethesda, Maryland. This is a full-time, on-site role focusing on administrative, analytical, and operational duties to sustain cGMP-regulated manufacturing and regulatory activities...Full time
- ...teamwork, and dependability. Our team delivers stakeholder-focused support in the areas of Acquisition & Procurement Support, (... ...Supply Chain Support. Visit us at Title: Senior Purchase Card Compliance Analyst Client: Federal Agency Location: Bethesda, MD/Remote (Must...Work at officeRemote workMonday to Friday
$28.5 per hour
...Job Description Job Description COMPLIANCE ANALYST Summary This position will support the Foundation’s conservation award-making activities by focusing on the areas of compliance and risk analysis relating to the Foundation and its subrecipients and for programmatically...Hourly payFull timeContract workFor contractorsLocal area- ...Systems, Inc. seeks a Principal Information Assurance Analyst to support the Headquarters Department of the... .... The successful candidate will manage RMF processes, prepare authorization packages, and ensure compliance with DoD 8510.01, ICD 503, AR 25-2, CNSSI 1253,...
$109.46k - $207.53k
...to join our growing International Tax practice! Must be located on the East Coast. This is primary consulting focused but also capable of leading compliance engagements. Our International Tax practice is comprised of a borderless team of professionals across the U.S,...Full timeLocal areaWorldwide$129k - $171k
...THE TEAM Anduril’s International Trade Compliance team is a resourceful and collaborative... ...seeks an experienced Export Compliance Analyst to help build our Compliance team supporting... ...for complex rules, with a singular focus on helping Anduril deploy its path-making...Full timeFor contractorsWork experience placement$205.9k - $270.3k
...every community we're in. As a company, we focus on creating positive change to build a... ...protect guest and company data, and ensure compliance with global regulatory requirements while... ...Director, Governance Risk & Compliance (GRC), you own end-to-end delivery for the GRC...Permanent employmentPart timeWork visa
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Compliance Analyst (GRC/RMF Focused). Be the first to apply!
- research compliance officer Washington DC
- trade compliance specialist Washington DC
- privacy compliance analyst Washington DC
- senior compliance analyst Washington DC
- regulatory compliance associate Washington DC
- risk compliance officer Washington DC
- regulatory officer Washington DC
- senior regulatory affairs specialist Washington DC
- legal compliance officer Washington DC
- cybersecurity policy and compliance analyst Washington DC



