GRC Analyst
$75k - $95kNextgenID
Location: Onsite - Fairfax, VA · U.S. Citizen Required (FedRAMP / Federal Customer) Type: Full Time NextgenID is hiring a GRC Analyst to do the hands‑on work that keeps our compliance program running. We verify and credential identity at the highest assurance level (IAL3) for federal agencies and enterprises, so evidence, documentation, and audit support are constant, real work. You maintain our control documentation and evidence, run the operational side of our FedRAMP, Kantara, and UK digital‑identity efforts, keep the POA&M and vulnerability tracking current, and complete the security questionnaires our customers send. You report to the GRC Lead. Salary Range: $75,000-$95,000 Role Fit & Non‑Negotiables Onsite at our Fairfax, VA headquarters. This role is hands‑on and evidence‑heavy. U.S. citizen, required for FedRAMP and federal‑customer obligations. Two or more years in GRC, security compliance, audit support, or a closely related role. Comfortable owning documentation, evidence, and trackers to a deadline. Detail‑oriented and discreet with sensitive security information. What You Will Own (90 to 180 Day Outcomes) Current, well‑organized control documentation and evidence repositories, moving from SharePoint into Vanta. The operational FedRAMP evidence effort: control documentation, gap‑finding tracking, and Trust Center content drafts. A monthly POA&M produced from Qualys findings using the FedRAMP template, with remediation tracked to closure. Completed, consistent security questionnaires delivered on time for GRC Lead review. The UK DVS documentation package and Kantara assessment materials kept current and submission‑ready. Core Responsibilities Compliance Documentation & Evidence — keep the record current and audit‑ready. Maintain control documentation, policies, and procedures, and migrate evidence into Vanta. Gather and organize evidence from engineering, DevSecOps, and operations leads. Convert implemented controls into machine‑readable (OSCAL / JSON) format for FedRAMP submission. Authorization & Assessment Support — run the operational side of our certifications. Refine and maintain the UK DVS / DIATF documentation package and scoping forms. Prepare Kantara assessment materials (SoCA, S3A, KAR) and the Rev 4 gap working draft. Coordinate assessment and pentest logistics, scheduling, and evidence with assessors and leads. Vulnerability & POA&M Tracking — keep the remediation record honest. Produce the monthly POA&M from Qualys findings using the FedRAMP template. Track vulnerability remediation and compensating controls with the RedTeam / DevSecOps leads. Maintain vulnerability and vendor‑risk evidence logs (for example, the BeyondTrust remediation log). Customer & Vendor Assurance Support — answer the questionnaires and support vendor risk. Complete security questionnaires (for example, CCRA and customer InfoSec assessments) consistent with prior responses. Support third‑party and vendor risk assessments and evidence requests. Route completed responses to the GRC Lead and management for review before submission. Research & Program Support — support the wider compliance effort. Provide compliance and privacy research to the document and product teams. Support ADA / Section 508 assessments and international import certification documentation (BIS, WPC, ATA Carnet). Help configure and maintain GRC tooling (Vanta) and keep the compliance calendar updated. What You Must Have Already Done Gathered and organized audit evidence and maintained compliance documentation to a deadline. Worked with a control framework (NIST 800-53, 800-63, ISO 27001, or SOC 2) on real evidence or gap work. Tracked vulnerabilities or POA&M items and coordinated remediation with technical teams. Completed a customer or vendor security questionnaire using documented evidence. Kept a tracker, repository, or evidence log accurate across many moving items. Required Qualifications Two or more years in GRC, security compliance, audit support, or a closely related role. Working knowledge of NIST SP 800-53 and/or NIST SP 800-63, ISO 27001, or SOC 2. Experience gathering evidence and maintaining compliance documentation. Experience with vulnerability or POA&M tracking and remediation coordination. Familiarity with vulnerability tooling (Qualys or Nessus) and evidence / GRC platforms (Vanta or similar). Strong writing and documentation skills for policies, procedures, and questionnaire responses. Highly organized and detail‑oriented, able to manage many concurrent items. Discreet and reliable with sensitive security and compliance information. Must be able to work onsite in Fairfax, VA; U.S. citizen (FedRAMP / federal customer). Preferred Qualifications Security+, GRCP, CySA+, or progress toward CISA. Exposure to FedRAMP or FISMA continuous monitoring (ConMon) and 3PAO assessments. Experience with Kantara / NIST 800-63 identity assurance or UK DIATF / DVS. Familiarity with OSCAL or machine‑readable control formats. Experience with security questionnaires (CAIQ, CCRA, customer InfoSec assessments). Background in an IDaaS, cloud, or federal‑contractor environment. You keep trackers and evidence current without being chased. You read a control and know what evidence proves it. You write clearly enough that your draft needs little rework before sign‑off. You chase the last 10 percent of detail that makes evidence audit‑ready. You handle sensitive information with discretion and never submit without review. What Success Looks Like Control documentation and evidence are current, organized, and audit‑ready in Vanta. The monthly POA&M is produced on time and remediation is tracked to closure. UK DVS and Kantara materials are submission‑ready ahead of each deadline. Security questionnaires are completed accurately and on time for GRC Lead review. Inherited workstreams from the departing analyst and intern continue without gaps. Why NextgenID NextgenID builds the compliance‑grade identity infrastructure that federal agencies and enterprises rely on to verify and credential identity at IAL3. Compliance is the product’s license to operate, and the evidence you produce is what makes it real. As GRC Analyst, you will see your work in every certification we hold and every customer questionnaire we clear, and you will grow into deeper risk and program ownership. For the right person, this is the path to a senior GRC or GRC Lead role. NextgenID focuses on improving the efficiency and speed of mission‑critical, high assurance identity enrollment and credentialing operations that are essential to hundreds of millions of users worldwide. Our technologies are engineered to dramatically reduce the time and cost of capturing accurate data when creating a digital identity. Our industry‑neutral solutions revolve around "Supervised Remote‑Identity Proofing" to automatically, securely and "remotely" perform all proofing, enrollment and credentialing processes and workflows for our customers. The industry is taking notice as we are now working with some of the largest agencies in the US Defense, intelligence, Civil, State and Local government markets, as well as other national governments and commercial organizations throughout the world. #J-18808-Ljbffr NextgenID
- ...Experience Experience in Financial Services domain expertise in one or more of the following areas - Governance, Risk & Compliance (GRC), Regulatory Reporting, Financial Risk. Experience in requirement gathering, process mapping, functional analysis, and Data validation...SuggestedFull timeTemporary workRelocation
- ...IT Security GRC Analyst (2 Openings) Location: Charlotte, NC (Hybrid Schedule) 2 days onsite / 3 days remote Employment Type: 3-Month Contract-to-Hire (W2 through Everforth Apex Systems) About the Opportunity Everforth Apex Systems is seeking 2 IT Security GRC Analysts...SuggestedPermanent employmentContract workImmediate startRemote work
- ...Role- GRC Analyst Duration: Contract to Perm Location: Norwalk CT, New York, Houston, TX Must Haves: GRC Nice to Haves: SOC2, IT Controls ~3 days on site. ~ Open to recent college grads with IT or accounting/finance degrees. ~ Values...SuggestedPermanent employmentContract work
$134k - $202k
...customers, growing our community, or shaping our story, you’ll help define what comes next. About the role: We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with...SuggestedWork at officeRemote workWork from homeWorldwideMonday to FridayFlexible hours- ...simulations, analysis, and decision-making, accelerating discovery and driving faster innovation. THE POSITION NMC² is hiring a GRC Analyst to join the Information Security team, reporting to the GRC & Privacy Manager and based at our Dallas, TX offices at Victory Commons...Suggested
$183k - $205k
...security governance, risk and compliance initiatives. This person will guide the company from foundational Governance, Risk & Compliance (GRC) maturity through to steady-state operations, leveraging AI to automate and improve old practices and tools, ensuring ongoing...Full timeWork at officeLocal area2 days per week3 days per week$55 - $80 per hour
IT GRC Analyst Remote, USA Compensation: $55 - $80 per hour Contract Length: 6-month Contract to Hire Hours: Standard full-time schedule, 8 hours/day, 5 days/week; potential for extended hours under heavy audit or incident response activity. Start Date: ASAP ABOUT...Hourly payFull timeContract workWork at officeImmediate startRemote workFlexible hours- Medasource is seeking an IT GRC Analyst to join our IT Security and Governance team on a 6-month contract-to-hire basis, working remotely within the USA. The role focuses on security governance, regulatory compliance, risk management, audit readiness, policy administration...Remote jobContract work
- Medasource is seeking an IT GRC Analyst to join the IT Security and Governance team on a 6-month contract-to-hire basis, remote within the USA. The role focuses on governance, risk, and compliance across HIPAA, SOC 2, and NIST, collaborating with IT, Security, Privacy,...Remote jobContract work
- Stanley Black & Decker is seeking a Senior Analyst Cyber Security to join our IT - Cyber Security team on a hybrid schedule in the United... ..., assess, and report on cybersecurity controls, maintain IT GRC documentation, and support external audits while staying current...
- New American Funding in Santa Ana, CA seeks a Cybersecurity GRC Analyst I, II, or III to support TPCRM through risk assessments, monitoring, and reporting across the vendor ecosystem. The role scales by experience, offering hands-on assessments, SARs, AI risk reviews, and...
- Vercel is seeking a GRC Analyst to join the Governance, Risk & Compliance team. You will manage ongoing compliance across security and privacy frameworks (ISO 27001, SOC 2, HIPAA, PCI DSS) and collaborate with cross‑functional teams to promote accountability and ethical...Remote job
- VoltaGrid is seeking a Cybersecurity Risk & Compliance Analyst to formalize and scale our risk governance, compliance, and policy framework across IT and OT environments. You will drive structure in risk, controls, policies, and audit readiness, ensuring alignment with...
- ...Amicis Global is seeking a FCC KYC Support Analyst in Jersey City, NJ. This role involves assisting with KYC and AML processes to ensure compliance with FCC regulations. You will support onboarding, conduct risk assessments, and maintain client records. The ideal candidate...Work at office
- ...spirit of a startup, we’re hiring. SageSure, a leader in catastrophe-exposed property insurance, is seeking a Senior Catastrophe Risk Analyst. In this role, you’ll play a critical part in advancing the scientific, statistical, and model-based understanding of catastrophe...Live in
- Join our dynamic team to navigate complex risk landscapes and fortify technology governance, making a pivotal impact in our firm's robust risk strategy.As a Tech Risk & Controls Senior Associate in Cybersecurity & Tech Controls, you will contribute to the successful management...
- The Southern Company is hiring a Technology Organization Risk & Compliance Analyst to support risk management and compliance for the TO against NERC CIP, TSA SD and SOX. Location options include Birmingham, AL or Atlanta, GA with occasional overnight travel. You will assist...Night shift
- Akin Gump Strauss Hauer & Feld LLP is seeking a Risk and Compliance Analyst to support the Risk and Compliance Services department. The role involves conducting conflict checks, client due diligence, AML clearances, and coordinating with Ethics, Finance, HR, and Recruiting...Remote job
- Pacific Gas and Electric Company seeks a Senior Compliance and Risk Consultant to provide flexible support across Support Desk and Quality Control roles. The job involves data research, analysis, reporting, and ensuring confidentiality in data responses for internal and...Work at officeFlexible hours
$105k
Position Summary Position headquarters flexible throughout the PG&E service territory (Oakland preferred). This position is 'hybrid', with the expectation of being in the office 3x/week. The Senior Compliance and Risk Consultant provide flexible support across both Support...Work at officeFlexible hours- Capital One is seeking a Compliance Advisor Principal Associate to assess regulatory alignment of code/script logic in CoDIR reviews and collaborate across lines of defense. You will advise businesses on applying compliance requirements to scripting activities and support...
- Southern Company is seeking a Technology Organization Risk & Compliance Analyst to support risk management and compliance activities within the TO. The role ensures controls are in place and can demonstrate compliance with NERC CIP, TSA SD, and SOX, with occasional overnight...Night shift
$65k - $75k
Customs Compliance Risk Assessment Specialist Job Category : Compliance Requisition Number : COMPL002112 Posted : August 7, 2026 Full-Time Remote Locations Showing 1 location Remote United States Description At Deringer, we are committed to integrity, expertise,...Full timeWork at officeRemote work$82k - $100k
...experience and culture atweaver.com . Position Profile Weaver is seeking a Senior Associate to join our Governance, Risk, and Compliance (GRC) practice with a primary focus on IT controls and technology assurance. This role will support a balanced portfolio of System and...Full timeFlexible hours$70k - $95k
...lawyers in offices throughout the United States, Europe, Asia and the Middle East. We are currently seeking a Risk and Compliance Analyst in the Risk and Compliance Services Department, reporting to the Risk and Compliance Managers. The Risk and Compliance Services department...Remote jobHourly payFull timeContract workWork at officeWorldwideWeekend work$100k - $155k
As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn’t changed — we’re here to stop breaches, and we’ve redefined modern security with the world’s most advanced AI-...Remote jobWork experience placementWork at officeLocal area- F.N.B. Corporation in Pittsburgh, PA is seeking a Sanctions Compliance Program Analyst 2. The role supports the Risk - BSA/AML unit, reviewing sanctions alerts and maintaining compliant records. Hours are 9 AM - 6 PM, with a focus on regulatory obligation at the transactional...
- Crédit Agricole Group in New York is seeking a role within the Advisory group of the Financial Security team, focusing on reviewing high-risk KYC files and providing AML and sanctions guidance to Bank staff on proposed transactions. The position requires knowledge of current...Bank staff
- First Fed is seeking a BSA Specialist I to monitor and review alerts, conduct CDD/EDD reviews, and file CTRs to support regulatory compliance. The role involves gathering information from customers and internal systems, escalating complex cases, and maintaining accurate...
- Technology Organization Risk & Compliance Analyst This position will perform support functions in the Technology Organization (TO) risk... ...Technology controls and processes Compliance frameworks ServiceNow GRC Knowledge of power utility equipment and Cyber Assets...Full timeNight shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!

