... or CGRC certification. ● Prior ISSO or ISSM appointment on a Federal or Department of Defense system. ● Experience with compliance as code, where control evidence is generated by automation ...
... or CGRC certification. ● Prior ISSO or ISSM appointment on a Federal or Department of Defense system. ● Experience with compliance as code, where control evidence is generated by automation ...
Security Control Assessor
Springfield, VA · On-site
Certified in Governance Risk and Compliance (CGRC) * Certified Information Systems Security Officer (C)ISSO-A) * CompTIA Cloud+ * CompTIA PenTest+ * CompTIA Security+ * CompTIA SecurityX (formerly ...
Security Control Assessor
Springfield, VA · On-site
Certified in Governance Risk and Compliance (CGRC) * Certified Information Systems Security Officer (C)ISSO-A) * CompTIA Cloud+ * CompTIA PenTest+ * CompTIA Security+ * CompTIA SecurityX (formerly ...
Professional Certification: Holding one of these certifications: * SecurityX / CASP+ * CGRC/CAP * GSEC * GSNA * Security+ * SSCP * 4 years of experience with IT audit/compliance experience
Professional Certification: Holding one of these certifications: * SecurityX / CASP+ * CGRC/CAP * GSEC * GSNA * Security+ * SSCP * 4 years of experience with IT audit/compliance experience
Certified in Governance Risk and Compliance (CGRC) * Certified Information Systems Security Officer (C)ISSO-A) * CompTIA Cloud+ * CompTIA PenTest+ * CompTIA Security+ * CompTIA SecurityX (formerly ...
Certified in Governance Risk and Compliance (CGRC) * Certified Information Systems Security Officer (C)ISSO-A) * CompTIA Cloud+ * CompTIA PenTest+ * CompTIA Security+ * CompTIA SecurityX (formerly ...
Certified Authorization Professional (CAP) / Certified in Governance, Risk and Compliance (CGRC) * Certified Information Systems Auditor (CISA) * Familiarity with scripting or automation (PowerShell ...
Certified Authorization Professional (CAP) / Certified in Governance, Risk and Compliance (CGRC) * Certified Information Systems Auditor (CISA) * Familiarity with scripting or automation (PowerShell ...
Program Manager
Quantico, VA · On-site
Certifications: One of PMP, DAWIA PM, CISSP, CISM, CCISO, CASP+, or CGRC/CAP. * Experience: ≥10 years program/contract management, with ≥5 years IT/Network Ops leadership. Technical Screening ...
Program Manager
Quantico, VA · On-site
Certifications: One of PMP, DAWIA PM, CISSP, CISM, CCISO, CASP+, or CGRC/CAP. * Experience: ≥10 years program/contract management, with ≥5 years IT/Network Ops leadership. Technical Screening ...
Certified in Governance Risk and Compliance (CGRC) * Certified Information Systems Security Officer (C)ISSO-A) * CompTIA Cloud+ * CompTIA PenTest+ * CompTIA Security+ * CompTIA SecurityX (formerly ...
Certified in Governance Risk and Compliance (CGRC) * Certified Information Systems Security Officer (C)ISSO-A) * CompTIA Cloud+ * CompTIA PenTest+ * CompTIA Security+ * CompTIA SecurityX (formerly ...
Security Control Assessor
Springfield, VA · On-site
Certified in Governance Risk and Compliance (CGRC) * Certified Information Systems Security Officer (C)ISSO-A) * CompTIA Cloud+ * CompTIA PenTest+ * CompTIA Security+ * CompTIA SecurityX (formerly ...
Security Control Assessor
Springfield, VA · On-site
Certified in Governance Risk and Compliance (CGRC) * Certified Information Systems Security Officer (C)ISSO-A) * CompTIA Cloud+ * CompTIA PenTest+ * CompTIA Security+ * CompTIA SecurityX (formerly ...
Certified Authorization Professional (CAP) / Certified in Governance, Risk and Compliance (CGRC) * Certified Information Systems Auditor (CISA) * Familiarity with scripting or automation (PowerShell ...
Certified Authorization Professional (CAP) / Certified in Governance, Risk and Compliance (CGRC) * Certified Information Systems Auditor (CISA) * Familiarity with scripting or automation (PowerShell ...
Security Control Assessor
Springfield, VA · On-site
Certified in Governance Risk and Compliance (CGRC) * Certified Information Systems Security Officer (C)ISSO-A) * CompTIA Cloud+ * CompTIA PenTest+ * CompTIA Security+ * CompTIA SecurityX (formerly ...
Security Control Assessor
Springfield, VA · On-site
Certified in Governance Risk and Compliance (CGRC) * Certified Information Systems Security Officer (C)ISSO-A) * CompTIA Cloud+ * CompTIA PenTest+ * CompTIA Security+ * CompTIA SecurityX (formerly ...
CISSP, CRICS, CCSP, CAP/CGRC. * Certifications in one or more of the following: AWS Certified Solutions Architect, AWS Certified Security, Microsoft Certified Solutions Architect, MCSE Cloud Platform ...
CISSP, CRICS, CCSP, CAP/CGRC. * Certifications in one or more of the following: AWS Certified Solutions Architect, AWS Certified Security, Microsoft Certified Solutions Architect, MCSE Cloud Platform ...
Program Manager
Quantico, VA · On-site
Certifications: One of PMP, DAWIA PM, CISSP, CISM, CCISO, CASP+, or CGRC/CAP. * Experience: ≥10 years program/contract management, with ≥5 years IT/Network Ops leadership. Technical Screening ...
Program Manager
Quantico, VA · On-site
Certifications: One of PMP, DAWIA PM, CISSP, CISM, CCISO, CASP+, or CGRC/CAP. * Experience: ≥10 years program/contract management, with ≥5 years IT/Network Ops leadership. Technical Screening ...
Cybersecurity Risk - Managing Consultant
Mclean, VA · On-site
$130K - $216K/yr
... CGRC), Certified Information Systems Auditor (CISA) What Would Be Nice To Have: * Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department ...
Cybersecurity Risk - Managing Consultant
Mclean, VA · On-site
$130K - $216K/yr
... CGRC), Certified Information Systems Auditor (CISA) What Would Be Nice To Have: * Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department ...
Cybersecurity Risk - Senior Consultant
$113K - $188K/yr
... CGRC), Certified Information Systems Auditor (CISA) What Would Be Nice To Have: * Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department ...
Cybersecurity Risk - Senior Consultant
$113K - $188K/yr
... CGRC), Certified Information Systems Auditor (CISA) What Would Be Nice To Have: * Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department ...
CISSP, CRICS, CCSP, CAP/CGRC. * Certifications in one or more of the following: AWS Certified Solutions Architect, AWS Certified Security, Microsoft Certified Solutions Architect, MCSE Cloud Platform ...
CISSP, CRICS, CCSP, CAP/CGRC. * Certifications in one or more of the following: AWS Certified Solutions Architect, AWS Certified Security, Microsoft Certified Solutions Architect, MCSE Cloud Platform ...
Cybersecurity Risk - Senior Consultant
Mclean, VA · On-site
$113K - $188K/yr
... CGRC), Certified Information Systems Auditor (CISA) What Would Be Nice To Have: * Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department ...
Cybersecurity Risk - Senior Consultant
Mclean, VA · On-site
$113K - $188K/yr
... CGRC), Certified Information Systems Auditor (CISA) What Would Be Nice To Have: * Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department ...
Cybersecurity Risk - Managing Consultant
$130K - $216K/yr
... CGRC), Certified Information Systems Auditor (CISA) What Would Be Nice To Have: * Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department ...
Cybersecurity Risk - Managing Consultant
$130K - $216K/yr
... CGRC), Certified Information Systems Auditor (CISA) What Would Be Nice To Have: * Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department ...
Cybersecurity Risk - Senior Consultant
$113K - $188K/yr
... CGRC), Certified Information Systems Auditor (CISA) What Would Be Nice To Have: * Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department ...
Cybersecurity Risk - Senior Consultant
$113K - $188K/yr
... CGRC), Certified Information Systems Auditor (CISA) What Would Be Nice To Have: * Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department ...
Cybersecurity Risk - Senior Consultant
Mclean, VA · On-site
$113K - $188K/yr
... CGRC), Certified Information Systems Auditor (CISA) What Would Be Nice To Have: * Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department ...
Cybersecurity Risk - Senior Consultant
Mclean, VA · On-site
$113K - $188K/yr
... CGRC), Certified Information Systems Auditor (CISA) What Would Be Nice To Have: * Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department ...
CISSP, CRICS, CCSP, CAP/CGRC. * Certifications in one or more of the following: AWS Certified Solutions Architect, AWS Certified Security, Microsoft Certified Solutions Architect, MCSE Cloud Platform ...
CISSP, CRICS, CCSP, CAP/CGRC. * Certifications in one or more of the following: AWS Certified Solutions Architect, AWS Certified Security, Microsoft Certified Solutions Architect, MCSE Cloud Platform ...
Cgrc Certification information
See Virginia salary details
$18.94 is the 25th percentile. Wages below this are outliers.
$16.44 - $23.57
71% of jobs
$25.35 is the 75th percentile. Wages above this are outliers.
$23.57 - $30.70
14% of jobs
$30.70 - $37.83
7% of jobs
$37.83 - $44.96
2% of jobs
$44.96 - $52.08
5% of jobs
$52.08 - $59.21
0% of jobs
$59.21 - $66.34
0% of jobs
$66.34 - $73.47
0% of jobs
$73.47 - $80.60
0% of jobs
$80.60 - $87.72
0% of jobs
$87.72 - $94.85
0% of jobs
$16
$28
$94
How much do cgrc certification jobs pay per hour?
What is a CGRC certification?
A CGRC (Certified in Governance, Risk, and Compliance) Certification job involves managing IT risk, ensuring regulatory compliance, and implementing governance frameworks within an organization. Professionals in this role assess security controls, develop risk management strategies, and support compliance efforts with industry standards. They often work in cybersecurity, auditing, or regulatory roles, helping organizations mitigate risks and maintain secure systems.
What are the common responsibilities of someone holding a CGRC certification in a cybersecurity team?
A professional with a CGRC Certification typically oversees the implementation and management of Governance, Risk, and Compliance (GRC) strategies within an organization. Daily tasks often include assessing and documenting security risks, ensuring compliance with industry regulations, coordinating audits, and collaborating with IT and legal teams to address vulnerabilities. You may also lead training sessions to promote security awareness and assist in the continuous improvement of security policies. This collaborative role is vital in building a resilient cybersecurity posture and ensuring that regulatory requirements are consistently met.
What are the key skills and qualifications needed to thrive in the CGRC certification position, and why are they important?
To thrive in a CGRC Certification role, you need a solid understanding of cybersecurity principles, risk management frameworks, and regulatory compliance, typically supported by relevant degrees and industry certifications like (ISC)² CGRC. Familiarity with tools such as GRC platforms, NIST frameworks, and information security management systems is crucial. Strong analytical thinking, attention to detail, and effective communication skills help professionals convey complex regulatory requirements and security findings to diverse teams. These capabilities are essential to ensuring organizations maintain compliance, safeguard sensitive data, and minimize cybersecurity risks.
Is the Cgrc certification worth it?
What experience do you need for Cgrc certification?
What are popular job titles related to Cgrc Certification jobs in Virginia?
For Cgrc Certification jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Cgrc Certification jobs in Virginia look for?
The top searched job categories for Cgrc Certification jobs in Virginia are:
What cities in Virginia are hiring for Cgrc Certification jobs?
Cities in Virginia with the most Cgrc Certification job openings:

Security Authorization Lead (RMF and ATO) with Security Clearance
Arlington, VA • On-site
Contractor
Posted 4 days ago
Job description
An Authority to Operate is won or lost long before the package reaches the Authorizing Official. It is won in how the control narratives are written, how the evidence is gathered, and how honestly the residual risk is described. This seat owns that work end to end, from the first System Security Plan draft through sustained continuous monitoring after the signature.
You will need to be bilingual. Engineers will tell you what they built, and you will have to translate it into control language that an assessor accepts; assessors will hand back findings, and you will have to translate those into engineering work that actually closes the gap. Compliance professionals who can only do one half of that translation struggle in this role. WHAT YOU WILL DO
● Author the package. Write and maintain System Security Plans, control implementation statements, and the supporting artifacts an assessor will actually read.
● Own the POA&M lifecycle. Open, prioritize, track, and close Plans of Action and Milestones, with realistic milestones and evidence that stands up to review.
● Drive the ATO to signature. Manage the accreditation timeline, coordinate assessment activities, prepare risk acceptance narratives, and brief the ISSM and Authorizing Official.
● Work the tooling. Maintain the package in eMASS or XACTA, keeping control status, artifacts, and assessment procedures linked and current.
● Translate scan output into action. Review ACAS, STIG, and cloud configuration findings, then work with engineers to remediate rather than simply reporting the count.
● Sustain continuous monitoring. Run the recurring control assessments, configuration change reviews, and reporting cadence that keep an ATO from decaying quietly.
● Advise early. Get into architecture conversations before the build is finished, so controls are designed in rather than retrofitted. REQUIRED QUALIFICATIONS
● Active Secret clearance or higher.
● U.S. citizenship.
● Demonstrated ownership of at least one system through a full ATO, from documentation through authorization decision.
● Hands-on authorship of System Security Plans and control implementation statements, not just review of documents written by others.
● Working proficiency in eMASS or XACTA.
● Command of NIST SP 800-53 and the Risk Management Framework lifecycle.
● POA&M management experience, including milestone development, evidence collection, and closure.
● Ability to communicate clearly with engineers, ISSOs, ISSMs, and Authorizing Officials. PREFERRED QUALIFICATIONS
● Cloud accreditation experience, particularly AWS or AWS GovCloud.
● Familiarity with the DoD Cloud Computing Security Requirements Guide at IL4, IL5, or IL6, and with CNSSI 1253 categorization.
● DISA STIG and ACAS experience.
● CISSP, CISM, CAP, or CGRC certification.
● Prior ISSO or ISSM appointment on a Federal or Department of Defense system.
● Experience with compliance as code, where control evidence is generated by automation rather than assembled by hand. WORKING ENVIRONMENT
The seat is remote or hybrid within the continental United States, with periodic on-site presence for assessment and accreditation activities depending on the supported program.
This role pairs with a Cloud Security Guardrails Engineer, who owns the technical enforcement layer. The split is deliberate: authorization depth and hands-on policy engineering are different skills, and asking one person to do both tends to shortchange whichever half they enjoy less.
ABOUT D9TECH RESOURCES
D9Tech Resources is a Service-Disabled Veteran-Owned Small Business and SBA 8(a) participant delivering cleared cloud, cybersecurity, network, data, and AI engineering to Federal and Department of Defense customers. Bench engineers are interviewed, verified, and kept ready, so that when a billet opens we place a known quantity instead of starting a search. HOW TO APPLY
Submit your resume to with the position title in the subject line. Applicants selected for screening will be contacted directly to verify clearance status before any interview is scheduled.
About D9Tech Resources
Sourced by ZipRecruiter
Industry
It services
Company size
1 - 10 Employees
Headquarters location
Virginia Beach, VA, US
Year founded
2014