Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

GRC Analyst - Public Sector

Socure

Why Socure?Socure is building the identity trust infrastructure for the digital economy — verifying 100% of good identities in real time and stopping fraud before it starts. The mission is big, the problems are complex, and the impact is felt by businesses, governments, and millions of people every day.We hire people who want that level of responsibility. People who move fast, think critically, act like owners, and care deeply about solving customer problems with precision. If you want predictability or narrow scope, this won’t be your place. If you want to help build the future of identity with a team that holds a high bar for itself — keep reading.OverviewSocure is seeking an Analyst, GRC – Public Sector to own the hands-on execution of the company’s governance, risk, and compliance operations for its public sector business. Reporting to the Director of GRC – Public Sector, this role is responsible day-to-day for running FedRAMP/GovRAMP continuous monitoring, building and maintaining the POA&M and compliance trackers that keep the program audit-ready, and coordinating access reviews, vulnerability remediation, and evidence collection with Security, Engineering, IT, DevOps, Product, Legal, and other teams. As the Analyst builds fluency in these operational fundamentals, the role grows to include drafting customer-facing compliance and RFP response content that makes Socure’s security posture compelling to public sector buyers, and pursuing automation-first, system-driven improvements, including machine-readable formats like OSCAL and AI-enabled workflows, that reduce manual effort and challenge how the team has traditionally done this work.Role and ResponsibilitiesCompliance & Certification ManagementDay-to-day coordination and execution of externalThird Party Assessment Organization (3PAO) assessments and responding to auditor requests for evidence and documentation.Maintain and update FedRAMP and GovRAMP controls and documentation in alignment with organizational and regulatory requirements, including controls aligned with NIST SP 800-53 rev 5 and other related frameworks.Prepare certification and authorization packages and maintain related documentation such as the System Security Plan (SSP) and associated appendices.Replace manual evidence collection with system-generated, API-driven, or continuously validated evidence where possible. Build and maintain the trackers, procedures, and status-reporting artifacts that operationalize this work, structured so other stakeholders can use them directly.Continuous Monitoring & Vulnerability ManagementDesign and evolve an automation-first continuous monitoring program leveraging system integrations, telemetry, and real-time data pipelinesLead the day-to-day FedRAMP continuous monitoring process including vulnerability management lifecycle, from identification through remediation and verification, coordinating with Security, Engineering, and DevOps teams to address issues identified with tools such as Wiz, Burp Suite, AWS native services, and other platforms and resolve issues within FedRAMP and GovRAMP timelines.Coordinate recurring continuous monitoring compliance activities such as access reviews, incident response exercises, and contingency plan testing.Access Management & TrainingDesign scalable and automated access validation mechanisms integrated with identity and infrastructure systemsDesign, implement and deliver FedRAMP training programs to promote compliance awarenessCreate and manage automated workflows to improve efficiency.Audit & Assessment ReadinessTransform compliance evidence from static repositories into dynamic, system-driven evidence models supporting real-time audit readinessConduct internal reviews of logged events and control activities, escalating issues or gaps to the Director of GRC and provide status updates and reports highlighting trends, risks, and remediation progress.Process Improvement & CollaborationCollaborate with the Director of GRC to design automation-first and AI-enabled workflows that reduce manual effort and enable scalable compliance operationsSupport the development, rollout, and maintenance of machine-readable compliance documentation (e.g., OSCAL or comparable structured formats) to facilitate interoperabilityPartner with automation and engineering teams to integrate structured compliance data into Socure’s broader risk management and monitoring ecosystem including vulnerability remediation, access requests, and compliance reporting.Monitor regulatory and industry trends for potential impacts to compliance strategy.Public Sector Sales & Customer EngagementServe as a security subject matter expert for public sector sales activities, translating compliance controls and system capabilities into clear, accurate, and compelling customer-facing narratives. The Analyst is expected to learn the difference between writing that confirms Socure meets a requirement and writing that persuades a public sector buyer that Socure’s approach is comfortable and superior to competitors’, with the Director retaining final review and approval given the contractual and sales stakes.Support development of external communications such as press releases and customer-facing materials related to security certifications and authorizations.Build and maintain scalable response frameworks (e.g., answer libraries, structured content, or AI-assisted tools) to provide consistency, accuracy, and speed across RFP and RFx responsesMonitor Evolving RequirementsMonitor new and evolving requirements and perform gap analyses includingUpdates to applicable NIST Special Publications and other government standardsContract security requirements from new customersUpdates to the FedRAMP Program requirements and processes as the program evolvesProvide input to standards bodies on evolving standards when applicableRequired Qualifications4+ years of hands-on cybersecurity, compliance, or identity-management experience, including demonstrated personal execution of FedRAMP, GovRAMP, or comparable continuous-monitoring work — running scans, building or maintaining a POA&M, and preparing deviation requests. Public sector experience is a plus but not required.Direct experience with FedRAMP, GovRAMP, and NIST frameworks (800-53, 800-63, 800-171).Proven ability to personally execute continuous monitoring, vulnerability remediation, and compliance reporting.Proven ability to design and improve repeatable compliance processes - identifying inefficiencies, defining clear steps, and building structure where none exists; experience using AI tools (e.g., ChatGPT, Glean, Gemini) and machine-readable formats (e.g., OSCAL) to accelerate that work is a strong plus.Strong communication, organization, and collaboration skills with the ability to manage multiple priorities, including strong written communication and the ability to write persuasively for a customer audience — distinct from writing that is merely compliance-accurate.Ability to adapt to changing requirementsDemonstrated customer-facing experience and enough exposure to product or sales positioning to distinguish compliance-accurate writing from writing that persuades a buyer; prior RFP-specific experience is not required.Must be a U.S. Person (U.S. Citizens or U.S. Permanent Residents) residing in the United States and be able to obtain a U.S. OPM NACI clearance.Preferred QualificationsExperience in regulated industries (e.g., financial services, healthcare) and knowledge of privacy and compliance frameworks such as GDPR, CCPA, and key NIST standards.Professional certifications preferred (CISSP, CISM, CISA, IAPP).Proven hands-on contribution to certification and compliance initiatives (FedRAMP, GovRAMP, NIST 800-63/171).Skilled in continuous monitoring, vulnerability management, policy updates, and audit coordination across cross-functional teams. Also valued: a demonstrated track record of identifying and closing process gaps proactively, without waiting for direction.Strong understanding of evolving cybersecurity standards and digital identity regulations, with the ability to translate them into practical risk and compliance improvements.Socure

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the GRC Analyst - Public Sector in Tysons, VA vacancy
  •  ...Job Description Job Description JUNIOR GRC ANALYST ROCKVILLE, MD - HYBRID LONG TERM CONTRACT SEEKING SOMEONE WHO HAS WORKED WITH THE SERVICENOW GRC APPLICATION Overview: ~ The GRC Analyst supports the administration of Information Security Governance, Risk,... 
    Suggested
    Long term contract
    Internship

    System One

    Rockville, MD
    18 days ago
  • $69.7k - $115.2k

     ...wherever you want it to go.  Join EY and help to build a better working world. From strategy to execution, the Government & Public Sector practice of Ernst & Young LLP provides a full range of consulting and audit services to help our Federal, State, Local and Education... 
    Suggested
    Summer holiday
    Work at office
    Local area
    Flexible hours

    Ernst & Young

    McLean, VA
    11 days ago
  • $151.9k - $173.4k

    Compliance Privacy Advisor, Manager The Capital One Privacy Compliance team is seeking a Manager, Compliance Privacy Advisor with a passion for mitigation privacy risks at a tech focused finance institution. They will join us to perform key privacy compliance activities...
    Suggested
    Full time
    Temporary work
    Part time
    Local area

    Capital One

    McLean, VA
    3 days ago
  • $99k - $225k

    Enterprise Cybersecurity GRC Governance AnalystThe Opportunity: The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance...  ...National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 revision 4 and 5, NIST SP 800-60, NIST SP 800-171,... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    4 days ago
  • $106.2k - $194.6k

     ...and help to build a better working world. Government and Public Sector – Technology Consulting – AI & Data – Data Analytics Senior Consultant...  ...your career. We’re seeking a highly motivated Senior Analyst to support a DOD client in the design, development, and... 
    Suggested
    For contractors
    Summer holiday
    Work at office
    Local area
    Flexible hours

    Ernst & Young

    McLean, VA
    22 days ago
  • $96.5k - $110.1k

     ...Overview Senior Risk Specialist, Compliance Governance Analyst The Compliance Governance, Oversight and Validation (CGOV) team within Compliance & Ethics is seeking a collaborative, analytically-focused risk management professional to support our well-managed governance... 
    Full time
    Part time
    Local area
    Immediate start

    Capital One

    McLean, VA
    4 days ago
  • $151.9k - $173.4k

    Overview Compliance Advisor Manager The Manager, Compliance performs a key risk management role in the second line of defense, providing primary compliance support to the Discover Personal Loans and ‘New to Credit’ credit card business segments. We are looking for...
    Full time
    Part time
    Local area

    Capital One

    McLean, VA
    a month ago
  •  ...Job Title: Risk and Compliance Systems Analyst (Oracle ERP Fusion and RMC) Location: Vienna, VA Pay Rate: open to W2 and established 1099's Work Model: Hybrid, onsite 3 days a week Position type: multiyear contract We are looking for an Oracle ERP Fusion... 
    Contract work
    Temporary work
    For contractors
    Local area
    3 days per week

    System One

    Vienna, VA
    more than 2 months ago
  • $117.2k - $176.7k

     ...does not hold dual citizenship and agrees to complete a U.S. federal government Minimum Background Investigation (MBI) for a Moderate Public Trust position.Unleash Your PotentialWhen you join Salesforce, you’ll be limitless in all areas of your life. Our benefits and... 
    Full time

    Salesforce

    McLean, VA
    6 days ago
  • $86k - $130k

     ...complex projects independently or contribute as a team member on projects of the utmost complexity.Employ research methods utilizing public records databases, social media platforms, credit reporting agencies, and other reporting services.Responsible for creating and... 
    Local area
    Flexible hours

    Freddie Mac

    Falls Church, VA
    1 day ago
  • Personal Risk Specialist The Personal Risk Specialist is an outside sales position focused on serving the unique insurance needs of affluent/high net worth clients. In addition to cross selling, as a primary focus for business development, this role is also expected...
    Local area

    USI Insurance Services

    Falls Church, VA
    19 hours ago
  •  ...Job Title: Risk Analyst – Control Testing Location: Vienna, VA or Pensacola, FL Type: Contract Work Model: Hybrid – onsite and remote Responsibilities • Execute design assessments on assigned controls. • Follow enterprise guidelines and accepted... 
    Contract work
    Temporary work
    Local area
    Remote work

    System One

    Merrifield, VA
    11 days ago
  • $131.3k - $149.8k

    Overview Principal Risk Specialist, Tech & Cyber Risk | Retail Bank As a Principal Associate of Tech & Cyber Risk within Capital One’s Business Risk Office, you will enable and drive end-to-end risk management of the portfolio by partnering directly with risk partners...
    Full time
    Part time
    Work at office
    Local area

    Capital One

    McLean, VA
    more than 2 months ago
  • $120.8k - $137.9k

    Overview Principal Risk Specialist | Enterprise Payments Do you like working in the spotlight? Are you ready to work on the front line of a top 10 Bank? Can you build relationships as well as develop and implement innovative solutions?  As a Principal Risk Specialist...
    Full time
    Part time
    Work at office
    Local area

    Capital One

    McLean, VA
    a month ago
  • $131.3k - $149.8k

     ...Overview Principal Analyst, Capital Markets & Risks Capital One’s Sarbanes-Oxley (SOX) Advisory team in Finance Risk Management...  ...in SOX controls at a Big Four Accounting Firm ~ Certified Public Accountant (CPA), Certified Internal Auditor (CIA), Certified Information... 
    Full time
    Part time
    Local area

    Capital One

    McLean, VA
    a month ago
  • $120.8k - $137.9k

    Overview Enterprise Risk Organization Governance & Reporting Specialist The Enterprise Risk Organization (ERO) Chief of Staff Team serves a critical role leading governance and oversight to multiple senior management committee and Board activities, while also leading...
    Full time
    Part time
    Local area

    Capital One

    McLean, VA
    23 days ago
  • $96.5k - $110.1k

    Overview Senior Risk Specialist | Retail Bank We’re looking for a strategic, forward thinking Senior Risk Specialist for our Retail Risk Office Control Testing Program, supporting Retail Bank and Premium Products + Shopping business divisions. In this role, you ...
    Full time
    Part time
    Work at office
    Local area

    Capital One

    McLean, VA
    19 days ago
  • $111.2k - $126.9k

     ...Overview Sr. Analyst, Capital Markets & Risk Capital One's Balance Sheet Management group is seeking a motivated professional for a Senior Analyst role on the Interest Rate Risk Management (IRR) Analytics team. The role provides an excellent opportunity to learn... 
    Full time
    Part time
    Local area

    Capital One

    McLean, VA
    a month ago
  • $120.8k - $137.9k

    Overview Principal Risk Associate - Business Continuity Management As a Commercial Risk Business Continuity Associate you will apply your skills to one of our highest profile Risk Management programs by partnering across the Commercial Bank’s Business, Technology...
    Full time
    Part time
    Work at office
    Local area

    Capital One

    McLean, VA
    12 days ago
  • $200.7k - $229.1k

    Overview Sr Manager, Wage & Hour Compliance and Risk We are excited to announce an opening for a talented Senior Manager, Wage & Hour Compliance and Risk to drive strategy and execute on high priority projects for the Compensation Delivery team. We are a team of...
    Full time
    Part time
    Casual work
    Local area
    Flexible hours
    Shift work

    Capital One

    McLean, VA
    a month ago
  •  ...Risk Business Analyst Location: Vienna, VA (Hybrid) Pay Rate: Open to Both C2C and W2 options Position Type: Contract The Analyst will serve in an Asset Based Testing role that will help plan, scope, execute, and report testing of IT and Information Security... 
    Contract work
    Temporary work
    Local area

    System One

    Merrifield, VA
    11 days ago
  • $187.3k - $213.7k

    Overview Compliance Director, Fair & Responsible Banking Compliance (Regulatory Consumer Center of Excellence) The Fair and Responsible Banking (F&RB) function, part of the Enterprise Risk Organization's Compliance & Ethics department, is seeking a highly experienced...
    Full time
    Part time
    Work at office
    Local area

    Capital One

    McLean, VA
    9 days ago
  • $101.1k - $115.4k

     ...Overview Senior Business Analyst - Third Party Risk Management (TPRM) About the Role: Capital One is seeking a highly motivated, strategic and analytically adept Senior Business Analyst to join our Third Party Risk Management (TPRM) team. Sitting within the Operational... 
    Full time
    Part time
    Local area

    Capital One

    McLean, VA
    20 days ago
  • $64.2k - $105.9k

     ...working world. From strategy to execution, the Government & Public Sector practice of Ernst & Young LLP provides a full range of...  ...Sector Assurance practice is growing exponentially, and as an analyst, you'll play a key role in that growth. Together with our substantial... 
    For contractors
    Work experience placement
    Summer holiday
    Work at office
    Local area
    Flexible hours

    Ernst & Young

    McLean, VA
    25 days ago
  • $70k - $80k

     ...Montage Marketing Group is seeking a Data Analyst to support client-facing projects in a growing marketing and communications environment. This role serves commercial, nonprofit, and public sector clients, including federal, state, and local government organizations... 
    Full time
    Temporary work
    Work at office
    Local area
    Home office
    Flexible hours

    Montage Marketing Group

    Rockville, MD
    a month ago
  •  ...Job Title Resource Management Analyst Why IDS? IDS believes in resolving conflict and building innovative approaches to do...  ...solutions for a diverse range of government, military, nonprofit, and public-sector clients. Locations Gov Site (NCR) Please note,... 
    Full time
    Local area
    Flexible hours

    IDS International

    Arlington, VA
    a month ago
  • $200.7k - $229.1k

     ...Overview Sr. Manager, Data Analyst - Network Compliance The Network Compliance Senior Manager Data Analyst will perform a key risk management role in the second line of defense for Capital One’s network and merchant businesses to help implement the framework for... 
    Full time
    Temporary work
    Part time
    Local area
    Worldwide

    Capital One

    McLean, VA
    a month ago
  • $182.5k - $208.3k

     ...Overview Sr. Manager, Data Analyst - Compliance Risk At Capital One, data is at the center of everything we do. When we launched as a startup we disrupted the credit card industry by individually personalizing every credit card offer using statistical modeling and... 
    Full time
    Part time
    Work at office
    Local area

    Capital One

    McLean, VA
    10 days ago
  • $100k - $150k

     ...Cybersecurity Risk Analyst Salary Range: $100,000 – $150,000 Clearance: TS/SCI + CI Poly Location: 50 miles of McLean, Virginia Position is contingent upon contract award Ops Tech Alliance is seeking a Cybersecurity Risk Analyst to support enterprise cybersecurity... 
    Full time
    Contract work

    Ops Tech Alliance

    McLean, VA
    a month ago
  • $106.9k - $176.5k

     ...diverse teams and take your career wherever you want it to go.  Join EY and help to build a better working world. Government and Public Sector – Technology Consulting - AI & Data – Ontology Senior Consultant From strategy to execution, the Government and Public Sector... 
    For contractors
    Summer holiday
    Work at office
    Local area
    Flexible hours

    Ernst & Young

    McLean, VA
    8 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to GRC Analyst - Public Sector. Be the first to apply!