Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

GRC Analyst, Federal & Customer Programs

$189k - $225k

Spire

Job Description

Job Description

About the Role:

The GRC Analyst, Federal & Customer Programs is responsible for the hands-on analysis, documentation, and operational execution of the company's security governance, risk, and compliance obligations. This role sits at the intersection of customer contracts, regulatory frameworks, and the company's security control environment — translating external requirements into clear, traceable internal commitments and evaluating how well current capabilities satisfy them. The GRC Analyst reviews incoming contractual security language, maps obligations to applicable frameworks and existing controls, produces compliance matrices and gap analyses, owns the operational risk assessment process, contributes to governance and policy lifecycle activities, and supports audit, assessment, and customer inquiry activities.

A meaningful portion of this role is dedicated to ongoing contract and requirements analysis as new programs are awarded and existing programs evolve. The GRC Analyst serves as the security function's primary reviewer of incoming contractual cybersecurity language and works directly with legal and sourcing on flow-down negotiation and redlines. Candidates who enjoy careful reading of contractual and regulatory text — and who want this to be a substantial part of their day-to-day work — will find this role a strong fit.

This is a detail-oriented, writing-intensive role requiring strong analytical judgment, fluency across multiple compliance frameworks, and the ability to work effectively with legal, sourcing, program management, engineering, and security operations stakeholders.

Key Responsibilities:

Contract & Requirements Analysis

  • Review customer contracts, statements of work, security annexes, CDRLs, data protection addenda, and flow-down clauses to identify cybersecurity, privacy, and information handling obligations applicable to the company.
  • Extract and catalog specific security requirements from contractual language, and translate them into structured, testable statements suitable for traceability and control mapping.
  • Compare identified requirements against the company's current product scope, control environment, and certification posture to determine where compliance is already met, partially met, or requires new implementation work.
  • Produce gap analyses, compliance matrices, and Requirements Traceability Matrix (RTM) artifacts that clearly communicate the state of compliance for a given contract, program, or system.
  • Serve as the security function's primary point of contact for legal and sourcing during contract review, redline cycles, and flow-down negotiation, including review of subcontractor and supplier flow-down language.

Framework Mapping & Interpretation

  • Maintain working proficiency across the frameworks relevant to the company's regulatory and contractual posture, including NIST SP 800-171, NIST SP 800-53, NIST CSF, CMMC, ISO 27001, FedRAMP, and applicable European frameworks such as NIS2 and GDPR.
  • Map controls across frameworks to minimize duplicated work and enable consistent responses to overlapping requirements; contribute to a shared control inventory used by compliance, security, and program teams.
  • Interpret framework language and authoritative guidance (NIST publications, DoD guidance, regulator FAQs) in the context of specific company systems and business scenarios and escalate ambiguity for formal risk decisions when appropriate.

Governance, Policy & ISMS Support

  • Contribute to the maintenance of the company's Information Security Management System (ISMS) documentation set, including keeping control descriptions, evidence references, and scope statements accurate and current.
  • Support the policy and standard lifecycle, including periodic review cycles, version control, exception governance, and clarification of control owner accountability.
  • Produce compliance posture reporting and audit readiness metrics for governance forums and leadership review, including framework coverage, finding aging, and remediation progress.

Deliverable Writing & Artifact Contribution

  • Draft and revise compliance deliverables including System Security Plans (SSP), Plans of Action & Milestones (POA&M), policy and standard content, control narratives, customer security questionnaire responses, and audit artifacts.
  • Author clear, concise written responses to customer, auditor, and regulator inquiries, calibrated to the technical level of the audience and consistent with approved company positioning.

Risk Assessment & Treatment

  • Own the operational risk assessment process and the supporting risk register, including conducting periodic and event-driven risk assessments, documenting current state, identifying deficiencies, and developing risk treatment recommendations.
  • Route risk acceptance and exception decisions to the appropriate decision authority with the underlying analysis and documentation prepared for review; track decisions and ensure follow-through on conditions or expirations.
  • Track open compliance findings and remediation activities, prepare status updates, and flag aging or high-severity items for escalation.

Third-Party & Supply Chain Risk

  • Contribute to vendor and supplier security review activities, including evaluating vendor security questionnaires, reviewing supplier control attestations, and assessing residual risk for inclusion in procurement and program decisions.
  • Support assessment of subcontractor and supplier flow-down compliance, including coordinating with sourcing and program management on supplier security obligations and remediation.

Audit & Assessment Support

  • Support internal and external audit, assessment, and certification activities, including C3PAO engagements, ISO 27001 surveillance audits, customer assessments, and regulator inquiries.
  • Coordinate evidence collection with system owners and control operators; validate that evidence is accurate, complete, and appropriately scoped before submission.
  • Participate in assessor and auditor interviews as a subject matter contributor on specific controls and artifacts.

Cross-Functional Collaboration

  • Partner with legal and sourcing on contract review, redlines, and flow-down language; with security program management on milestones, schedules, and audit coordination; and with security engineering and IT on evidence, control implementation detail, and remediation planning.
  • Serve as a knowledgeable point of contact for internal teams seeking to understand what a given regulatory or contractual requirement means in practice.

What Success Looks Like in Year One

  • Established a repeatable contract review intake process with legal and sourcing, including a maintained library of standard cybersecurity flow-down clauses and review turnaround expectations.
  • Produced an end-to-end Requirements Traceability Matrix for at least one active federal program, traceable from contract clauses through framework controls to evidence sources.
  • Stood up the operational risk register and routine risk reporting cadence, with at least one full assessment cycle completed and risk treatment decisions documented.
  • Maintained the ISMS documentation set in audit-ready condition through at least one external assessment or surveillance cycle.

Required Qualifications:

  • Five or more years of progressive experience in cybersecurity governance, risk, and compliance; IT audit; or a closely related discipline, with substantial hands-on exposure to framework interpretation and contract requirement analysis.
  • Demonstrated working knowledge of NIST SP 800-171 and NIST SP 800-53, including control families, assessment procedures, and common implementation patterns.
  • Experience contributing to SSP and POA&M artifacts, compliance matrices, or Requirements Traceability Matrices in a regulated environment.
  • Practical experience supporting at least one formal audit, certification, or assessment cycle (for example CMMC, ISO 27001, SOC 2, FedRAMP, or comparable).
  • Strong technical writing skills, including the ability to produce accurate, concise, and audience-appropriate compliance documentation. Writing samples may be requested as part of the interview process.
  • Demonstrated comfort and interest in reading contractual and regulatory language carefully and translating it into specific, actionable internal requirements. This is a core part of the role, not an occasional task.
  • Comfort working across multiple stakeholder groups — legal, sourcing, engineering, IT, security operations, and program management — and adjusting communication style accordingly.
  • Bachelor's degree in Information Security, Information Systems, Business, a related field, or equivalent practical experience.

Preferred Qualifications:

  • Direct experience with CMMC 2.0 assessment preparation, including familiarity with DFARS View phone number on ziprecruiter.com and 48 CFR Part 204.
  • Familiarity with ISO 27001, FedRAMP, SOC 2, NIS2, GDPR data security obligations, or EU dual-use export control regimes.
  • Experience handling Controlled Unclassified Information (CUI) in accordance with NARA and DoD requirements.
  • Exposure to aerospace, defense, space, or other regulated technology environments.
  • Experience reviewing or negotiating cybersecurity flow-down language in customer or supplier contracts.
  • Working familiarity with Governance, Risk, and Compliance (GRC) tooling such as ServiceNow GRC, Archer, Hyperproof, Drata, Vanta, or equivalent.
  • Industry certifications such as CISA, CRISC, CISSP, CGRC (formerly CAP), ISO 27001 Lead Implementer / Lead Auditor, CMMC Registered Practitioner (RP), or CMMC Certified Professional / Certified Assessor (CCP / CCA).
  • Active US security clearance, or eligibility to obtain one.

Spire operates a hybrid work model, and this position will require you to work a minimum of three days per week in the office.

Access to US export-controlled software and/or technology may be required for this role. If needed, Spire will arrange the necessary licenses—this is not something candidates need to have before applying. #LI-DC1

The anticipated base salary range for this position is listed below. Final base salary for this role will be based on the location, skills, experience and qualifications. In addition to base compensation, this role may be eligible for annual equity awards and our employee benefits program, including vacation, sick, and personal time off; optional medical, dental, vision, life, and disability coverage; a 401(K) plan; health and wellness reimbursement program; and participation in Spire's Employee Stock Purchase Plan.

Salary Range

$189,000—$225,000 USD


Global Perks

️ Name Your Satellite Program (NYSP)
Launch Attendance
Generous Time Off Policy
Education Assistance Program
Employee Assistance Program (EAP)
Employee Stock Purchase Program (ESPP)
Family Leave
Fitness Reimbursement
Employee Referral Program
Healthy snacks & beverages in every office

About Spire

We improve life on Earth with data from space.

Spire Global is a space-to-cloud analytics company that owns and operates the largest multi-purpose constellation of satellites. Its proprietary data and algorithms provide the most advanced maritime, aviation, and weather tracking in the world. In addition to its constellation, Spire's data infrastructure includes a global ground station network and 24/7 operations that provide real-time global coverage of every point on Earth.


Spire is Global and our success draws upon the diverse viewpoints, skills and experiences of our employees. We are proud to be an equal opportunity employer and are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, marital status, disability, gender identity or veteran status.

To help maintain a safe and secure workplace for Spire employees, all candidates who receive a conditional offer will be required to complete a background check. This may include criminal history and employment verification.

Please take a moment to review Spire's Global Data Privacy Notice for Employees, Contractors, Candidates and Visitors, as well as Spire's Privacy Policy.


Kindly be advised that communication regarding your application may come from @spire.com, @recruiting.spire.com, or from Candidate.fyi (our scheduling tool).

Vacancy posted a month ago
Similar jobs that could be interesting for youBased on the GRC Analyst, Federal & Customer Programs in Washington DC vacancy
  • GoTo Meeting is seeking a GRC Analyst, Federal & Customer Programs, to manage security governance, risk, and compliance obligations. Responsibilities include analyzing contracts, mapping obligations to compliance frameworks, and producing compliance matrices. The ideal... 
    Customer

    GoTo Meeting

    Washington DC
    4 days ago
  •  ...most important component: its people. "Love Thy Customer; Love Thy Work; Love Thy System" BMA is seeking a Program Analyst to support agency management of vaccine...  ...sexual orientation in accordance with applicable federal, state and local laws. BMA complies with applicable... 
    Customer
    For contractors
    Local area

    Business Management Associates, Inc

    Washington DC
    5 days ago
  •  ...Humane World for Animals, a global leader in animal advocacy and protection, is seeking a Program Manager, Regulatory, Federal Affairs. In this position you will encourage the development, implementation and proper enforcement of regulations designed to bolster animal... 
    Suggested
    Remote work
    Flexible hours

    Alaska Department of Law

    Washington DC
    2 days ago
  •  ...The Alaska Department of Law is seeking a Program Manager for Regulatory, Federal Affairs in Washington, DC. This hybrid position includes responsibilities such as collaborating with program staff on regulatory compliance, drafting media materials, and developing relationships... 
    Suggested

    Alaska Department of Law

    Washington DC
    1 day ago
  • Crowned Grace International seeks a seasoned Program Manager to oversee critical procurement activities for Federal clients. With a requirement of over 10 years in program management within federal contexts, the role centers on expertise in Federal Records Management and... 
    Suggested

    Crowned Grace International

    Washington DC
    5 days ago
  • 3M Consultancy is seeking a Program Manager / Compliance Manager in Washington, D.C. to oversee a federal IDIQ contract. The successful candidate will ensure compliance with federal regulations and manage contract execution as the primary liaison with government officials... 
    Contract work

    3M Consultancy

    Washington DC
    3 days ago
  • $160k - $180k

    Chevo LLC is hiring a Federal Program Manager to manage significant client interactions and oversee federal IT projects. The ideal candidate will have at least 7 years of experience in federal IT portfolio management and hold a bachelor’s degree. This fully remote position... 
    Remote job

    Chevo LLC

    Washington DC
    4 days ago
  • $160k - $180k

    Chevo Consulting is hiring an experienced Federal Program Manager to join their team. This remote position allows significant client interaction while ensuring compliance with farm governance and management processes. Candidates must have a bachelor's degree and 7+ years... 
    Remote job

    Chevo Consulting

    Washington DC
    4 days ago
  • Alaska Department of Law is looking for a Program Manager to enhance animal protection regulations in Washington, D.C. This hybrid role emphasizes collaboration with various federal agencies and external coalition partners. Candidates should possess a law degree and a minimum... 
    Remote job

    Alaska Department of Law

    Washington DC
    4 days ago
  • Medium is seeking a remote Senior Program Analyst with significant experience in federal financial management. This role supports the Department of Veterans Affairs through the implementation of Momentum Financials in a modernizing environment. The ideal candidate will... 
    Remote job

    Medium

    Washington DC
    6 days ago
  • A decision analytics company in Arlington, VA, is seeking a Program Analyst with expertise in financial and cost analysis to support federal programs. The role requires a bachelor's degree in a quantitative field and involves responsibilities such as budget execution,... 

    Technomics, Inc.

    Arlington, VA
    4 days ago
  • Arc Aspicio is seeking a Business Analyst for Federal Programs in Washington, DC. The ideal candidate will have over 8 years of experience developing strategies for Federal programs, particularly in the immigration sector. This role involves collaborating with clients... 

    Arc Aspicio

    Washington DC
    4 days ago
  • Ibility is seeking a remote Senior Program Analyst skilled in federal financial management using Momentum Financials to support the Department of Veterans Affairs (VA). This role is integral to modernizing financial management across VA via a multi-wave deployment. The... 
    Remote job

    Ibility

    Washington DC
    5 days ago
  • BLH Technologies, Inc., is hiring a Program Analyst to deliver on-site administrative and programmatic support for a federal contract with HHS. The role involves coordinating activities, supporting grant operations, and ensuring documentation quality. Ideal candidates... 
    Contract work

    BLH Technologies, Inc.

    Washington DC
    5 days ago
  • Program Manager / Compliance Manager Location: Washington, D.C. / Baltimore Metro Area...  ...Baltimore area and be willing to attend weekly customer meetings at the Ft. Meade complex....  ...Compliance Manager to oversee all aspects of a federal IDIQ contract. The ideal candidate will... 
    Customer
    Full time
    Contract work
    Live in
    Work at office

    3M Consultancy

    Washington DC
    4 days ago
  • $84k - $100k

     ...GRC Analyst Uplight is creating a new category of energy. We make...  ...energy and save money for energy customers. We are looking for a GRC...  ...learning and development programs, and a supportive team environment...  ...characteristic protected by federal, state or local laws.... 
    Customer
    Local area
    Flexible hours
    Shift work

    Uplight

    Washington DC
    4 days ago
  • Ll Oefentherapie in Arlington, Virginia is seeking a Federal Business Analyst to lead program activities aimed at process optimization and data analysis. Ideal candidates will possess a solid understanding of federal contracting rules and be experienced in cross-functional... 

    Ll Oefentherapie

    Arlington, VA
    3 days ago
  • Description Job Title: Federal Student Aid Regulatory Case Analyst Department: Operations - Services Reports To: RavenTek Program Manager Location: Remote Schedule: Monday - Friday Hours...  ...RavenTek’s mission to support the customer. Requirements Essential Duties and Responsibilities... 
    Customer
    Hourly pay
    Full time
    Contract work
    Work experience placement
    Work at office
    Remote work
    Home office
    Monday to Friday

    Raventek Solution Partners LLC

    Washington DC
    3 days ago
  • A defense technology company based in Washington is looking for a Program Manager to lead strategic engagements with federal customers such as the Department of Defense and NASA. This role requires strong program management and customer relationship skills, alongside a... 
    Customer

    Nominal

    Washington DC
    2 days ago
  •  ...mission results. With capabilities in management consulting, program management, strategic planning, data analysis, human capital,...  ...live in the Washington, DC area at time of employment. Business Analyst (Federal Programs) Responsibilities Expertise in requirements... 
    Contract work
    Live in
    Work at office
    Remote work
    Flexible hours

    Arc Aspicio

    Washington DC
    6 days ago
  • $35 - $38 per hour

    One Federal Solution is seeking a Senior Program Analyst to support the United States Marshals Service by providing essential analytical and program management assistance. The role involves program analysis, reporting, and process improvement activities in a dynamic federal... 
    Hourly pay

    One Federal Solution

    Arlington, VA
    4 days ago
  • $130k - $180k

     ...privacy. At Virtru, we equip our customers to take granular control of...  ...edge security compliance program aligned with FedRAMP, SOC 2,...  ...performant service. As a GRC Analyst at Virtru, you will be the primary...  ...protected by applicable national, federal, state, or local law.... 
    Customer
    Remote job
    Local area
    Flexible hours
    Shift work

    Virtru

    Washington DC
    more than 2 months ago
  • AnaVation LLC is looking for a Customer Success Program Manager to oversee GRC services for federal agencies in Washington DC. The role involves managing service delivery, developing new offerings, and ensuring client satisfaction. A strong background in cybersecurity... 
    Customer
    Remote job

    AnaVation LLC

    Washington DC
    4 days ago
  • $132k - $209k

     ...Federal Contracts & Subcontracts Manager - Compliance/Governance (Washington DC) The...  ...Capture, Legal, and Finance teams—and with customers as appropriate—to support effective...  ...implement quality control and tracking programs to meet defined quality objectives; working... 
    Customer
    Full time
    Contract work
    Work at office
    Immediate start
    Work visa
    3 days per week

    Philips

    Washington DC
    2 days ago
  •  ...Title: Senior Program Analyst Program Summary KBR’s Aviation & Ground Systems Directorate provides...  ...International focuses, while ensuring customer satisfaction and providing excellence...  ...any other characteristic protected by federal, state, or local law. #J-18808-Ljbffr... 
    Customer
    Full time
    Contract work
    Work at office
    Local area
    Flexible hours

    KBR

    Arlington, VA
    1 day ago
  •  ...Consulting is looking for an experienced Program Manager in Washington, DC to oversee...  ...conference planning and event logistics for federal programs. The role requires at least ten...  ...'ll manage teams, ensure high levels of customer satisfaction, and coordinate logistics... 
    Customer

    TeleSolv Consulting

    Washington DC
    4 days ago
  • Geospatial And Cloud Analytics Inc is looking for a Program Manager to oversee a federal IT modernization initiative. This role involves serving as the accountable interface to federal customers and ensuring deliverable oversight across multiple task orders, focusing on... 
    Customer

    Geospatial And Cloud Analytics Inc

    Washington DC
    5 days ago
  • $60.1k - $99.3k

     ...innovate with MANTECH! MANTECH seeks a motivated, career and customer‑oriented Program Analyst to join our team working in the Washington D.C. Navy Yard...  ...to project, program, or business analysis supporting the federal government Preferred Qualifications Familiarity with... 
    Customer
    Hourly pay
    Contract work
    Temporary work
    Work experience placement
    Work at office
    Local area
    Remote work
    2 days per week

    ManTech International Corporation

    Washington DC
    5 days ago
  • ECS is seeking a cleared Deputy Program Manager in Washington, DC to lead day-to-day delivery...  ...should have a minimum of 7 years of federal IT project/program support experience,...  ...involves operational management and ensures high-quality customer support. #J-18808-Ljbffr ECS
    Customer

    ECS

    Washington DC
    6 days ago
  • $99k - $225k

    Enterprise Cybersecurity GRC Governance Analyst The Enterprise Cybersecurity...  ...Management Framework (RMF), Federal Information Processing Standards...  ...Authorization Management Program (FedRAMP), and Federal...  ...person at a Booz Allen or customer facility. Hybrid: If this position... 
    Customer
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Mc Lean, VA
    6 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to GRC Analyst, Federal & Customer Programs. Be the first to apply!