GRC Analyst
$75k - $95kNextgenID
Location: Onsite - Fairfax, VA · U.S. Citizen Required (FedRAMP / Federal Customer) Type: Full Time NextgenID is hiring a GRC Analyst to do the hands‑on work that keeps our compliance program running. We verify and credential identity at the highest assurance level (IAL3) for federal agencies and enterprises, so evidence, documentation, and audit support are constant, real work. You maintain our control documentation and evidence, run the operational side of our FedRAMP, Kantara, and UK digital‑identity efforts, keep the POA&M and vulnerability tracking current, and complete the security questionnaires our customers send. You report to the GRC Lead. Salary Range: $75,000-$95,000 Role Fit & Non‑Negotiables Onsite at our Fairfax, VA headquarters. This role is hands‑on and evidence‑heavy. U.S. citizen, required for FedRAMP and federal‑customer obligations. Two or more years in GRC, security compliance, audit support, or a closely related role. Comfortable owning documentation, evidence, and trackers to a deadline. Detail‑oriented and discreet with sensitive security information. What You Will Own (90 to 180 Day Outcomes) Current, well‑organized control documentation and evidence repositories, moving from SharePoint into Vanta. The operational FedRAMP evidence effort: control documentation, gap‑finding tracking, and Trust Center content drafts. A monthly POA&M produced from Qualys findings using the FedRAMP template, with remediation tracked to closure. Completed, consistent security questionnaires delivered on time for GRC Lead review. The UK DVS documentation package and Kantara assessment materials kept current and submission‑ready. Core Responsibilities Compliance Documentation & Evidence — keep the record current and audit‑ready. Maintain control documentation, policies, and procedures, and migrate evidence into Vanta. Gather and organize evidence from engineering, DevSecOps, and operations leads. Convert implemented controls into machine‑readable (OSCAL / JSON) format for FedRAMP submission. Authorization & Assessment Support — run the operational side of our certifications. Refine and maintain the UK DVS / DIATF documentation package and scoping forms. Prepare Kantara assessment materials (SoCA, S3A, KAR) and the Rev 4 gap working draft. Coordinate assessment and pentest logistics, scheduling, and evidence with assessors and leads. Vulnerability & POA&M Tracking — keep the remediation record honest. Produce the monthly POA&M from Qualys findings using the FedRAMP template. Track vulnerability remediation and compensating controls with the RedTeam / DevSecOps leads. Maintain vulnerability and vendor‑risk evidence logs (for example, the BeyondTrust remediation log). Customer & Vendor Assurance Support — answer the questionnaires and support vendor risk. Complete security questionnaires (for example, CCRA and customer InfoSec assessments) consistent with prior responses. Support third‑party and vendor risk assessments and evidence requests. Route completed responses to the GRC Lead and management for review before submission. Research & Program Support — support the wider compliance effort. Provide compliance and privacy research to the document and product teams. Support ADA / Section 508 assessments and international import certification documentation (BIS, WPC, ATA Carnet). Help configure and maintain GRC tooling (Vanta) and keep the compliance calendar updated. What You Must Have Already Done Gathered and organized audit evidence and maintained compliance documentation to a deadline. Worked with a control framework (NIST 800-53, 800-63, ISO 27001, or SOC 2) on real evidence or gap work. Tracked vulnerabilities or POA&M items and coordinated remediation with technical teams. Completed a customer or vendor security questionnaire using documented evidence. Kept a tracker, repository, or evidence log accurate across many moving items. Required Qualifications Two or more years in GRC, security compliance, audit support, or a closely related role. Working knowledge of NIST SP 800-53 and/or NIST SP 800-63, ISO 27001, or SOC 2. Experience gathering evidence and maintaining compliance documentation. Experience with vulnerability or POA&M tracking and remediation coordination. Familiarity with vulnerability tooling (Qualys or Nessus) and evidence / GRC platforms (Vanta or similar). Strong writing and documentation skills for policies, procedures, and questionnaire responses. Highly organized and detail‑oriented, able to manage many concurrent items. Discreet and reliable with sensitive security and compliance information. Must be able to work onsite in Fairfax, VA; U.S. citizen (FedRAMP / federal customer). Preferred Qualifications Security+, GRCP, CySA+, or progress toward CISA. Exposure to FedRAMP or FISMA continuous monitoring (ConMon) and 3PAO assessments. Experience with Kantara / NIST 800-63 identity assurance or UK DIATF / DVS. Familiarity with OSCAL or machine‑readable control formats. Experience with security questionnaires (CAIQ, CCRA, customer InfoSec assessments). Background in an IDaaS, cloud, or federal‑contractor environment. You keep trackers and evidence current without being chased. You read a control and know what evidence proves it. You write clearly enough that your draft needs little rework before sign‑off. You chase the last 10 percent of detail that makes evidence audit‑ready. You handle sensitive information with discretion and never submit without review. What Success Looks Like Control documentation and evidence are current, organized, and audit‑ready in Vanta. The monthly POA&M is produced on time and remediation is tracked to closure. UK DVS and Kantara materials are submission‑ready ahead of each deadline. Security questionnaires are completed accurately and on time for GRC Lead review. Inherited workstreams from the departing analyst and intern continue without gaps. Why NextgenID NextgenID builds the compliance‑grade identity infrastructure that federal agencies and enterprises rely on to verify and credential identity at IAL3. Compliance is the product’s license to operate, and the evidence you produce is what makes it real. As GRC Analyst, you will see your work in every certification we hold and every customer questionnaire we clear, and you will grow into deeper risk and program ownership. For the right person, this is the path to a senior GRC or GRC Lead role. NextgenID focuses on improving the efficiency and speed of mission‑critical, high assurance identity enrollment and credentialing operations that are essential to hundreds of millions of users worldwide. Our technologies are engineered to dramatically reduce the time and cost of capturing accurate data when creating a digital identity. Our industry‑neutral solutions revolve around "Supervised Remote‑Identity Proofing" to automatically, securely and "remotely" perform all proofing, enrollment and credentialing processes and workflows for our customers. The industry is taking notice as we are now working with some of the largest agencies in the US Defense, intelligence, Civil, State and Local government markets, as well as other national governments and commercial organizations throughout the world. #J-18808-Ljbffr NextgenID
$70k - $88k
...presence across various U.S. locations and offer co-managed IT solutions as well. Job Overview Coretelligent is seeking a diligent GRC Analyst to join our team. This role will serve as a key contributor to Coretelligent's holistic cybersecurity solutions by managing...SuggestedRemote workFlexible hours$134k - $202k
...customers, growing our community, or shaping our story, you’ll help define what comes next. About the role: We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with...SuggestedWork at officeRemote workWork from homeWorldwideMonday to FridayFlexible hours$100.8k - $168k
McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being...Suggested$55 - $80 per hour
IT GRC Analyst Remote, USA Compensation: $55 - $80 per hour Contract Length: 6-month Contract to Hire Hours: Standard full-time schedule, 8 hours/day, 5 days/week; potential for extended hours under heavy audit or incident response activity. Start Date: ASAP ABOUT...SuggestedHourly payFull timeContract workWork at officeImmediate startRemote workFlexible hours- Governance, Risk & Compliance (GRC) Analyst Washington D.C. CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage domain dominance. The company's products are powered by Coherent Distributed Networks (CDN), empowering...SuggestedContract workFor subcontractorCasual workRelocation package
- ...simulations, analysis, and decision-making, accelerating discovery and driving faster innovation. THE POSITION NMC² is hiring a GRC Analyst to join the Information Security team, reporting to the GRC & Privacy Manager and based at our Dallas, TX offices at Victory Commons...
- Yahoo is seeking a Senior Security GRC Analyst to join The Paranoids Cyber Risk team in a fast-moving security landscape. You will collaborate with business leaders, engineers, and security teams to identify, assess, document, and communicate security risks, guiding risk...
$120k - $150k
...Custody And Digital Assets Risk Analyst At BBH, partnership is more than a form of ownership—it's our approach to business and relationships. We know that supporting your professional and personal goals is the best way to help our clients and advance our business. We...Work experience placementLocal area- Crédit Agricole Group in New York is seeking a role within the Advisory group of the Financial Security team, focusing on reviewing high-risk KYC files and providing AML and sanctions guidance to Bank staff on proposed transactions. The position requires knowledge of current...Bank staff
- ...Information Security (OIT/OIS) program covering enterprise cybersecurity architecture and engineering. We are seeking Risk and Compliance Analysts to own the risk, compliance, and supply chain reporting spine of the program. Program: VA Cybersecurity Architecture and...Full timeContract workInterim roleWork at officeRemote work
- Capital One is seeking a Compliance Advisor Principal Associate to assess regulatory alignment of code/script logic in CoDIR reviews and collaborate across lines of defense. You will advise businesses on applying compliance requirements to scripting activities and support...
$70k - $95k
...lawyers in offices throughout the United States, Europe, Asia and the Middle East. We are currently seeking a Risk and Compliance Analyst in the Risk and Compliance Services Department, reporting to the Risk and Compliance Managers. The Risk and Compliance Services department...Remote jobHourly payFull timeContract workWork at officeWorldwideWeekend work- TIB Consulting Solutions has provided sophisticated, independent credit risk services to community banks across the nation for more than 35 years. Our team of credit risk professionals leverages their extensive experience to communicate effective risk management practices...Full timePart timeWork at officeLocal areaRemote workWork from homeFlexible hours
$54k - $60k
Responsibilities: Deliver outstanding player support on Risk & Fraud matters, including account issues, verification, and document reviews. Review alerts and player activity to detect and prevent fraud across our sportsbook and casino platforms. Conduct...- Everforth Apex Systems in Pensacola, FL and Winchester, VA operate a hybrid model and seek a dedicated Business Channel Support Specialist. You will conduct risk assessments of new business memberships, verify legitimacy, and perform due diligence to prevent fraud. You ...
$145k - $180k
About Futu US Inc. Futu US Inc. stands at the forefront of financial services, housing two SEC registered broker-dealers alongside a cryptocurrency brokerage — all operating under the reputable wing of Futu Holdings Limited (Nasdaq: FUTU). Our core mission revolves...Contract workWork at officeLocal areaRemote work$163.5k - $200.3k
Senior Manager, Compliance Jersey City, NJ Bluevine is the largest small business banking platform in the U.S., redefining how entrepreneurs manage their money. We create modern financial solutions, from checking and lending to payments and beyond, designed to help...Immediate startWork from homeFlexible hours- ...Risk Management Analyst One of the leading financial institutions is seeking a Risk Management Analyst who will be analyzing risk management activities and creating various reports related risks. Responsibilities: Prepare various reports for Control Self-Assessment,...
- ...backbone of DTCC, leaders who stand at the forefront of DTCC’s competitive endeavors across the globe. From accountants and financial analysts to internal consultants and workplace designers, the CFO Organization employs diverse individuals who work together to help make...Full timeRemote workFlexible hours
- At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a...Work experience placementWork at officeFlexible hoursShift workDay shift
- Position Title: Cybersecurity Risk & Compliance Analyst Location : HOUSTON, TX FLSA Class : EXEMPT Responsible to : Senior Manager of Technical... ...needs. The ideal candidate brings a strong understanding of GRC principles, paired with the ability to translate complex...Local area
- Job Description Bring your Expertise to JPMorgan Chase. As part of Risk Management and Compliance, you are at the center of keeping JPMorgan Chase strong and resilient. You help the firm grow its business in a responsible way by anticipating new and emerging risks, ...
- ...spirit of a startup, we’re hiring. SageSure, a leader in catastrophe-exposed property insurance, is seeking a Senior Catastrophe Risk Analyst. In this role, you’ll play a critical part in advancing the scientific, statistical, and model-based understanding of catastrophe...Live in
- Acuity is seeking an experienced Risk Control Consultant to conduct surveys and prepare survey reports for the Commercial Underwriting department. This individual will provide loss control assistance and advice to policyholders and agents. In addition, this role will make...Local area
- Hubbell Incorporated in Shelton, CT seeks a Senior Analyst, Risk Management to shape enterprise risk strategies in a hybrid role. You will identify insurable exposures, manage global insurance programs, lead risk dashboards, and support captive operations while partnering...
- ...Daytona Beach, FL**### **Hybrid work schedule may be offered upon completion of training.**QXO is seeking a detail-oriented **Risk Analyst** to support the day-to-day administration and coordination of our Property/Casualty Insurance Programs. In this role, you will partner...Contract work
- Overview Bluehawk, LLC is a professional services firm providing intelligence, information technology, language, and training services to the U.S. Government and commercial entities. Our mission is to protect and defend our nation, citizens, natural resources, critical ...For contractorsWork at office
$85k - $110k
Amentum is seeking highly motivated, self-starting Risk Mitigation Specialist/Officer. Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Ability to maintain a Top Secret...Hourly payContract workFor contractorsWork experience placementWork at officeLocal areaRemote work- OnPoint Community Credit Union in Portland, OR is seeking a BSA/AML compliance professional to support the Credit Union’s regulatory program. You will assist the BSA Officer, investigate suspicious activity, review OFAC and 314a alerts, and help align policies with changing...
$88.6k - $110.7k
Your initial assignment will be on a 2.0+ million square foot healthcare facility at Mayo Clinic’s campus.This role is a critical part of the project team and support project and firm wide leadership and commercial teams in managing contractual, legal and business matters...Contract workFor contractorsWork experience placementWork at officeRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!



