Cybersecurity GRC Analyst

Posted 1 day ago

This is a fully remote position, open to applicants in District of Columbia, +1 more state.

📋 Description

• Assess whether the information systems are functioning at an acceptable risk level for the organization.

• Assist in authorizing information systems through technical analysis and supporting documentation.

• Conduct risk trade-off analyses and create strategies and solutions for risk mitigation.

• Evaluate Plans of Action and Milestones (POA&Ms) for information systems and monitor remediation efforts.

• Facilitate cybersecurity risk management tasks, including system categorization, selection and implementation of security controls, and comprehensive evaluations of the organization’s risk posture.

• Carry out Security Control Assessments in alignment with NIST SP 800-37 and NIST SP 800-53A.

• Prepare and present briefings on assessment findings and recommendations to support authorization processes.

• Aid in the implementation and upkeep of Integrated Risk Management (IRM) methodologies.

• Contribute to the agency’s Supply Chain Risk Management (SCRM) and Third-Party Risk Management (TPRM) initiatives.

• Manage the Cyber Risk Register and monitor cybersecurity regulations, guidance, and data requests.

• Enhance FISMA scores and maturity, normalizing and translating cyber risks for enterprise-wide visibility.

• Create and maintain cybersecurity dashboards that align with key performance indicators, utilizing Power BI.

• Employ automation and AI tools to improve risk reporting, compliance tracking, performance evaluation, and regulatory oversight.

• Share insights and recommendations with both technical and non-technical stakeholders.

• Provide guidance to stakeholders on cybersecurity-protective designs, implementations, and solutions.


⛳️ Requirements

• Bachelor’s degree in cybersecurity, information technology, or a related discipline.

• At least 4 years of experience in cyber governance, risk, and compliance.

• Subject matter expertise in Assessment and Authorization (RMF), including practical experience in testing and evaluating cybersecurity solutions.

• Proven experience in conducting risk trade-off analyses and developing risk mitigation plans.

• Background in reviewing POA&Ms and supporting authorization processes.

• Experience in presenting to clients or decision-makers, tailoring messages for both technical and non-technical audiences.

• Capability to work independently as well as collaboratively within a team.

• U.S. Citizenship or Permanent Residency, with all work conducted within the continental U.S.

• Must be able to pass a federal agency suitability or background check.

• Preferred: Previous federal contracting experience in supporting a civilian agency governance or compliance program.

• Preferred: Familiarity with Integrated Risk Management, Supply Chain Risk Management, or Third-Party Risk Management programs.

• Preferred: Experience in FISMA reporting and maturity enhancement.

• Preferred: Experience in creating or managing cybersecurity dashboards and KPI reporting.

• Preferred: Proficiency with JCAM, the agency’s GRC platform of record (previously known as CSAM).

• Preferred: Understanding of automation, low-code/no-code, or AI-assisted compliance tools.

• Preferred: Relevant certifications such as CGRC (formerly CAP), CISA, CRISC, CISM, or CISSP.

• Strong written and verbal communication skills suitable for both technical and non-technical audiences.

• Ability to work autonomously and as an integral part of a distributed team.

• Comfortable operating in a fully remote environment with a culture of video meetings.

• Sound judgment on when to make decisions and when to escalate issues.

• A collaborative approach when engaging with system owners, business owners, developers, and assessors.

• Commitment to maintaining high documentation quality and following through on commitments.


🏝️ Benefits

• Medical: Various POS health plan options, including an HSA-compatible option.

• Dental: PPO coverage for preventive, basic, and major services.

• Vision: Annual eye exam, frames, lenses, and allowance for contact lenses.

• 401(k): Employer matching up to 5% of eligible compensation.

• Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings.

• Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each.

• PTO: 15-25 days annually, depending on tenure.

• Paid Federal Holidays: Observance of all 11 federal holidays.

People also viewed

Super.com1 day ago

Travel Risk Operations Intern

CA flagCanada OnlyInternshipRiskC$20 – C$31/hour
ApplyView job
Sedgwick1 day ago

Risk Service Consultant

US flagVirginia OnlyFull-timeRisk$90k – $95k/year
ApplyView job
L3Harris Technologies1 day ago

Senior Specialist, Data Governance

US flagFlorida, +1 more stateFull-timeRisk$84k – $178k/year
ApplyView job
phData1 day ago

Senior Advisory Consultant, Data Governance/MDM

US flagUnited States OnlyFull-timeRisk
ApplyView job
Pathward1 day ago

Data Governance Advisor

US flagArizona, +5 more statesFull-timeRisk$86k – $145k/year
ApplyView job
BeOne Medicines1 day ago

Senior Director, Portfolio Strategy and Governance – Hematology

US flagUnited States OnlyFull-timeRisk$214.5k – $284.5k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers