1

Cgrc Certification Jobs in Virginia (NOW HIRING)

Certified in Governance Risk and Compliance (CGRC) * Certified Information Systems Security Officer (C)ISSO-A) * CompTIA Cloud+ * CompTIA PenTest+ * CompTIA Security+ * CompTIA SecurityX (formerly ...

Certified in Governance Risk and Compliance (CGRC) * Certified Information Systems Security Officer (C)ISSO-A) * CompTIA Cloud+ * CompTIA PenTest+ * CompTIA Security+ * CompTIA SecurityX (formerly ...

Certified in Governance Risk and Compliance (CGRC) * Certified Information Systems Security Officer (C)ISSO-A) * CompTIA Cloud+ * CompTIA PenTest+ * CompTIA Security+ * CompTIA SecurityX (formerly ...

Certifications: One of PMP, DAWIA PM, CISSP, CISM, CCISO, CASP+, or CGRC/CAP. * Experience: ≥10 years program/contract management, with ≥5 years IT/Network Ops leadership. Technical Screening ...

Certifications: One of PMP, DAWIA PM, CISSP, CISM, CCISO, CASP+, or CGRC/CAP. * Experience: ≥10 years program/contract management, with ≥5 years IT/Network Ops leadership. Technical Screening ...

... CGRC), Certified Information Systems Auditor (CISA) What Would Be Nice To Have: * Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department ...

... CGRC), Certified Information Systems Auditor (CISA) What Would Be Nice To Have: * Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department ...

next page

Showing results 1-20

Cgrc Certification information

See Virginia salary details

$16

$28

$94

How much do cgrc certification jobs pay per hour?

As of Aug 20, 2026, the average hourly pay for cgrc certification in Virginia is $28.24, according to ZipRecruiter salary data. Most workers in this role earn between $19.09 and $26.68 per hour, depending on experience, location, and employer.

What is a CGRC certification?

A CGRC (Certified in Governance, Risk, and Compliance) Certification job involves managing IT risk, ensuring regulatory compliance, and implementing governance frameworks within an organization. Professionals in this role assess security controls, develop risk management strategies, and support compliance efforts with industry standards. They often work in cybersecurity, auditing, or regulatory roles, helping organizations mitigate risks and maintain secure systems.

What are the common responsibilities of someone holding a CGRC certification in a cybersecurity team?

A professional with a CGRC Certification typically oversees the implementation and management of Governance, Risk, and Compliance (GRC) strategies within an organization. Daily tasks often include assessing and documenting security risks, ensuring compliance with industry regulations, coordinating audits, and collaborating with IT and legal teams to address vulnerabilities. You may also lead training sessions to promote security awareness and assist in the continuous improvement of security policies. This collaborative role is vital in building a resilient cybersecurity posture and ensuring that regulatory requirements are consistently met.

What are the key skills and qualifications needed to thrive in the CGRC certification position, and why are they important?

To thrive in a CGRC Certification role, you need a solid understanding of cybersecurity principles, risk management frameworks, and regulatory compliance, typically supported by relevant degrees and industry certifications like (ISC)² CGRC. Familiarity with tools such as GRC platforms, NIST frameworks, and information security management systems is crucial. Strong analytical thinking, attention to detail, and effective communication skills help professionals convey complex regulatory requirements and security findings to diverse teams. These capabilities are essential to ensuring organizations maintain compliance, safeguard sensitive data, and minimize cybersecurity risks.

Is the Cgrc certification worth it?

The Cgrc (Certified Governance and Risk Compliance) certification is valuable for professionals in governance, risk management, and compliance roles, demonstrating knowledge of regulatory frameworks and best practices. It can enhance job prospects and credibility in fields such as cybersecurity, audit, and compliance management. However, its worth depends on individual career goals and the relevance of governance and risk skills to the specific job market.

What experience do you need for Cgrc certification?

To obtain a Cgrc certification, candidates typically need relevant experience in governance, risk management, and compliance, often including knowledge of cybersecurity frameworks and policies. While specific requirements vary by certifying body, practical experience in information security or compliance roles is highly valued. Some certifications may also require passing an exam and demonstrating understanding of control frameworks like NIST or ISO.

What job categories do people searching Cgrc Certification jobs in Virginia look for?

The top searched job categories for Cgrc Certification jobs in Virginia are:

What cities in Virginia are hiring for Cgrc Certification jobs?

Cities in Virginia with the most Cgrc Certification job openings:

Infographic showing various Cgrc Certification job openings in Virginia as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $58,748 per year, or $28.2 per hour.

Security Authorization Lead (RMF and ATO) with Security Clearance

D9Tech Resources, LLC

Arlington, VA • On-site

Contractor

Posted yesterday

New


Job description

SECURITY COMPLIANCE | ACTIVE SECRET CLEARANCE REQUIRED, TS/SCI PREFERRED | U.S. CITIZENSHIP REQUIRED | REMOTE OR HYBRID (CONUS) ABOUT THE ROLE
An Authority to Operate is won or lost long before the package reaches the Authorizing Official. It is won in how the control narratives are written, how the evidence is gathered, and how honestly the residual risk is described. This seat owns that work end to end, from the first System Security Plan draft through sustained continuous monitoring after the signature.
You will need to be bilingual. Engineers will tell you what they built, and you will have to translate it into control language that an assessor accepts; assessors will hand back findings, and you will have to translate those into engineering work that actually closes the gap. Compliance professionals who can only do one half of that translation struggle in this role. WHAT YOU WILL DO
● Author the package. Write and maintain System Security Plans, control implementation statements, and the supporting artifacts an assessor will actually read.
● Own the POA&M lifecycle. Open, prioritize, track, and close Plans of Action and Milestones, with realistic milestones and evidence that stands up to review.
● Drive the ATO to signature. Manage the accreditation timeline, coordinate assessment activities, prepare risk acceptance narratives, and brief the ISSM and Authorizing Official.
● Work the tooling. Maintain the package in eMASS or XACTA, keeping control status, artifacts, and assessment procedures linked and current.
● Translate scan output into action. Review ACAS, STIG, and cloud configuration findings, then work with engineers to remediate rather than simply reporting the count.
● Sustain continuous monitoring. Run the recurring control assessments, configuration change reviews, and reporting cadence that keep an ATO from decaying quietly.
● Advise early. Get into architecture conversations before the build is finished, so controls are designed in rather than retrofitted. REQUIRED QUALIFICATIONS
● Active Secret clearance or higher.
● U.S. citizenship.
● Demonstrated ownership of at least one system through a full ATO, from documentation through authorization decision.
● Hands-on authorship of System Security Plans and control implementation statements, not just review of documents written by others.
● Working proficiency in eMASS or XACTA.
● Command of NIST SP 800-53 and the Risk Management Framework lifecycle.
● POA&M management experience, including milestone development, evidence collection, and closure.
● Ability to communicate clearly with engineers, ISSOs, ISSMs, and Authorizing Officials. PREFERRED QUALIFICATIONS
● Cloud accreditation experience, particularly AWS or AWS GovCloud.
● Familiarity with the DoD Cloud Computing Security Requirements Guide at IL4, IL5, or IL6, and with CNSSI 1253 categorization.
● DISA STIG and ACAS experience.
● CISSP, CISM, CAP, or CGRC certification.
● Prior ISSO or ISSM appointment on a Federal or Department of Defense system.
● Experience with compliance as code, where control evidence is generated by automation rather than assembled by hand. WORKING ENVIRONMENT
The seat is remote or hybrid within the continental United States, with periodic on-site presence for assessment and accreditation activities depending on the supported program.
This role pairs with a Cloud Security Guardrails Engineer, who owns the technical enforcement layer. The split is deliberate: authorization depth and hands-on policy engineering are different skills, and asking one person to do both tends to shortchange whichever half they enjoy less.
ABOUT D9TECH RESOURCES
D9Tech Resources is a Service-Disabled Veteran-Owned Small Business and SBA 8(a) participant delivering cleared cloud, cybersecurity, network, data, and AI engineering to Federal and Department of Defense customers. Bench engineers are interviewed, verified, and kept ready, so that when a billet opens we place a known quantity instead of starting a search. HOW TO APPLY
Submit your resume to with the position title in the subject line. Applicants selected for screening will be contacted directly to verify clearance status before any interview is scheduled.