
Junior Cybersecurity GRC Analyst
Posted Sep 4

Posted Sep 4
This is a fully remote position, open to applicants in District of Columbia, +1 more state.
• Assist in the implementation of the Risk Management Framework to authorize IT systems.
• Provide insights regarding whether information systems are functioning at an acceptable risk level for the organization.
• Aid in information system authorization decisions by conducting risk trade-off analyses.
• Play a role in developing risk mitigation strategies and solutions.
• Assist with technical analysis involving categorization, security control selection, implementation, and thorough evaluations of risk posture.
• Contribute to security control assessment activities in line with NIST SP 800-37 and NIST SP 800-53A.
• Support presentations and occasionally present to clients and decision-makers across both technical and non-technical audiences.
• Advise clients on technical designs, implementations, and solutions that safeguard against cybersecurity threats.
• Assist with POA&M tracking, maintenance of the cyber risk register, and monitoring of cybersecurity regulations, guidance, and data requests.
• Help develop cybersecurity dashboards and automate routine risk reporting and compliance tracking.
• A bachelor's degree in cybersecurity, information technology, or a related discipline.
• Experience with Assessment and Authorization (RMF) tasks, including testing or evaluating cybersecurity solutions, through coursework, internships, or professional experience.
• A working knowledge of the Risk Management Framework and the federal authorization process.
• Excellent written and verbal communication skills, with the ability to support or deliver presentations comfortably.
• Capability to work autonomously as well as collaboratively within a team.
• U.S. Citizenship or Permanent Residency, with all work conducted within the continental U.S.
• Ability to pass a federal agency suitability or background investigation.
• Preferred: Internship, co-op, or 1 to 2 years of professional experience in a Governance, Risk, and Compliance (GRC), audit, or compliance role.
• Preferred: Familiarity with NIST SP 800-53 control families and evidence expectations.
• Preferred: Experience with a GRC platform such as Xacta, eMASS, CSAM, Archer, or ServiceNow IRM.
• Preferred: Knowledge of FISMA reporting, Supply Chain Risk Management (SCRM), or Third-Party Risk Management (TPRM) concepts.
• Preferred: Interest in or experience with automation and AI-assisted compliance tools.
• Preferred: Security+ or CGRC (formerly CAP) certification, or actively pursuing one.
• Understanding of Risk Management Framework fundamentals as per NIST SP 800-37.
• Familiarity with security controls under NIST SP 800-53 and assessment fundamentals under 800-53A.
• Support for risk trade-off analysis and mitigation strategy development.
• Experience in POA&M tracking and evidence collection.
• Assistance with security documentation and authorization artifacts.
• Support for cyber risk register and regulatory monitoring.
• Skills in dashboard creation, reporting, and spreadsheet analysis.
• Experience with automation and AI-assisted compliance tools.
• Clear communication skills for both technical and non-technical audiences.
• Ability to work independently and as an effective member of a distributed team.
• Comfort in a fully remote environment with a culture of camera-on meetings.
• Good judgment regarding decision-making and escalation.
• Collaborative approach with system owners, business owners, developers, and assessors.
• Attention to detail in documentation quality and commitment follow-through.
• Medical: Multiple POS health plan options including an HSA-compatible plan.
• Dental: PPO coverage for preventive, basic, and major services.
• Vision: Annual exam, frames, lenses, and contact lens allowance.
• 401(k): Employer match up to 5% of eligible compensation.
• Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings.
• Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each.
• PTO: 15–25 days annually based on tenure.
• Paid Federal Holidays: All 11 federal holidays observed.
Penn Interactive
Penn Interactive
Freedom Mortgage
Get handpicked remote jobs straight to your inbox weekly.