
Cybersecurity GRC Analyst
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in District of Columbia, +1 more state.
• Assess whether the information systems are functioning at an acceptable risk level for the organization.
• Assist in authorizing information systems through technical analysis and supporting documentation.
• Conduct risk trade-off analyses and create strategies and solutions for risk mitigation.
• Evaluate Plans of Action and Milestones (POA&Ms) for information systems and monitor remediation efforts.
• Facilitate cybersecurity risk management tasks, including system categorization, selection and implementation of security controls, and comprehensive evaluations of the organization’s risk posture.
• Carry out Security Control Assessments in alignment with NIST SP 800-37 and NIST SP 800-53A.
• Prepare and present briefings on assessment findings and recommendations to support authorization processes.
• Aid in the implementation and upkeep of Integrated Risk Management (IRM) methodologies.
• Contribute to the agency’s Supply Chain Risk Management (SCRM) and Third-Party Risk Management (TPRM) initiatives.
• Manage the Cyber Risk Register and monitor cybersecurity regulations, guidance, and data requests.
• Enhance FISMA scores and maturity, normalizing and translating cyber risks for enterprise-wide visibility.
• Create and maintain cybersecurity dashboards that align with key performance indicators, utilizing Power BI.
• Employ automation and AI tools to improve risk reporting, compliance tracking, performance evaluation, and regulatory oversight.
• Share insights and recommendations with both technical and non-technical stakeholders.
• Provide guidance to stakeholders on cybersecurity-protective designs, implementations, and solutions.
• Bachelor’s degree in cybersecurity, information technology, or a related discipline.
• At least 4 years of experience in cyber governance, risk, and compliance.
• Subject matter expertise in Assessment and Authorization (RMF), including practical experience in testing and evaluating cybersecurity solutions.
• Proven experience in conducting risk trade-off analyses and developing risk mitigation plans.
• Background in reviewing POA&Ms and supporting authorization processes.
• Experience in presenting to clients or decision-makers, tailoring messages for both technical and non-technical audiences.
• Capability to work independently as well as collaboratively within a team.
• U.S. Citizenship or Permanent Residency, with all work conducted within the continental U.S.
• Must be able to pass a federal agency suitability or background check.
• Preferred: Previous federal contracting experience in supporting a civilian agency governance or compliance program.
• Preferred: Familiarity with Integrated Risk Management, Supply Chain Risk Management, or Third-Party Risk Management programs.
• Preferred: Experience in FISMA reporting and maturity enhancement.
• Preferred: Experience in creating or managing cybersecurity dashboards and KPI reporting.
• Preferred: Proficiency with JCAM, the agency’s GRC platform of record (previously known as CSAM).
• Preferred: Understanding of automation, low-code/no-code, or AI-assisted compliance tools.
• Preferred: Relevant certifications such as CGRC (formerly CAP), CISA, CRISC, CISM, or CISSP.
• Strong written and verbal communication skills suitable for both technical and non-technical audiences.
• Ability to work autonomously and as an integral part of a distributed team.
• Comfortable operating in a fully remote environment with a culture of video meetings.
• Sound judgment on when to make decisions and when to escalate issues.
• A collaborative approach when engaging with system owners, business owners, developers, and assessors.
• Commitment to maintaining high documentation quality and following through on commitments.
• Medical: Various POS health plan options, including an HSA-compatible option.
• Dental: PPO coverage for preventive, basic, and major services.
• Vision: Annual eye exam, frames, lenses, and allowance for contact lenses.
• 401(k): Employer matching up to 5% of eligible compensation.
• Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings.
• Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each.
• PTO: 15-25 days annually, depending on tenure.
• Paid Federal Holidays: Observance of all 11 federal holidays.
Super.com
L3Harris Technologies
phData
Get handpicked remote jobs straight to your inbox weekly.