Junior Cybersecurity GRC Analyst

Posted Sep 4

This is a fully remote position, open to applicants in District of Columbia, +1 more state.

📋 Description

• Assist in the implementation of the Risk Management Framework to authorize IT systems.

• Provide insights regarding whether information systems are functioning at an acceptable risk level for the organization.

• Aid in information system authorization decisions by conducting risk trade-off analyses.

• Play a role in developing risk mitigation strategies and solutions.

• Assist with technical analysis involving categorization, security control selection, implementation, and thorough evaluations of risk posture.

• Contribute to security control assessment activities in line with NIST SP 800-37 and NIST SP 800-53A.

• Support presentations and occasionally present to clients and decision-makers across both technical and non-technical audiences.

• Advise clients on technical designs, implementations, and solutions that safeguard against cybersecurity threats.

• Assist with POA&M tracking, maintenance of the cyber risk register, and monitoring of cybersecurity regulations, guidance, and data requests.

• Help develop cybersecurity dashboards and automate routine risk reporting and compliance tracking.


⛳️ Requirements

• A bachelor's degree in cybersecurity, information technology, or a related discipline.

• Experience with Assessment and Authorization (RMF) tasks, including testing or evaluating cybersecurity solutions, through coursework, internships, or professional experience.

• A working knowledge of the Risk Management Framework and the federal authorization process.

• Excellent written and verbal communication skills, with the ability to support or deliver presentations comfortably.

• Capability to work autonomously as well as collaboratively within a team.

• U.S. Citizenship or Permanent Residency, with all work conducted within the continental U.S.

• Ability to pass a federal agency suitability or background investigation.

• Preferred: Internship, co-op, or 1 to 2 years of professional experience in a Governance, Risk, and Compliance (GRC), audit, or compliance role.

• Preferred: Familiarity with NIST SP 800-53 control families and evidence expectations.

• Preferred: Experience with a GRC platform such as Xacta, eMASS, CSAM, Archer, or ServiceNow IRM.

• Preferred: Knowledge of FISMA reporting, Supply Chain Risk Management (SCRM), or Third-Party Risk Management (TPRM) concepts.

• Preferred: Interest in or experience with automation and AI-assisted compliance tools.

• Preferred: Security+ or CGRC (formerly CAP) certification, or actively pursuing one.

• Understanding of Risk Management Framework fundamentals as per NIST SP 800-37.

• Familiarity with security controls under NIST SP 800-53 and assessment fundamentals under 800-53A.

• Support for risk trade-off analysis and mitigation strategy development.

• Experience in POA&M tracking and evidence collection.

• Assistance with security documentation and authorization artifacts.

• Support for cyber risk register and regulatory monitoring.

• Skills in dashboard creation, reporting, and spreadsheet analysis.

• Experience with automation and AI-assisted compliance tools.

• Clear communication skills for both technical and non-technical audiences.

• Ability to work independently and as an effective member of a distributed team.

• Comfort in a fully remote environment with a culture of camera-on meetings.

• Good judgment regarding decision-making and escalation.

• Collaborative approach with system owners, business owners, developers, and assessors.

• Attention to detail in documentation quality and commitment follow-through.


🏝️ Benefits

• Medical: Multiple POS health plan options including an HSA-compatible plan.

• Dental: PPO coverage for preventive, basic, and major services.

• Vision: Annual exam, frames, lenses, and contact lens allowance.

• 401(k): Employer match up to 5% of eligible compensation.

• Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings.

• Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each.

• PTO: 15–25 days annually based on tenure.

• Paid Federal Holidays: All 11 federal holidays observed.

People also viewed

Fiserv1 day ago

Cyber Governance Senior Advisor

BR flagBrazil OnlyFull-timeRisk
ApplyView job
Penn Interactive1 day ago

Risk & Trading Associate

US flagUnited States OnlyFull-timeRisk$50k – $55k/year
ApplyView job
Penn Interactive1 day ago

Risk & Trading Associate

CA flagCanada OnlyFull-timeRiskC$50k – C$65k/year
ApplyView job
Freedom Mortgage1 day ago

High Risk Specialist

US flagUnited States OnlyFull-timeRisk
ApplyView job
Michels Corporation1 day ago

Project Risk Controls Analyst

US flagTexas OnlyFull-timeRisk
ApplyView job
Michels Corporation1 day ago

Project Risk Controls Analyst

US flagIllinois OnlyFull-timeRisk$68k – $145k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers