1

Cgrc Jobs in Ohio (NOW HIRING)

Configuration Manager

Dayton, OH · On-site

$80 - $120/hr

CGRC * Microsoft Endpoint Administrator * SAFe Agile Certification Preferred Experience * Experience supporting Air Force enterprise systems * Experience supporting AFFSO or Financial Management ...

Cgrc information

What is a CGRC professional?

CGRC professionals, or Certified in Governance, Risk and Compliance, are experts who help organizations manage risk, ensure regulatory compliance, and establish effective governance frameworks. They analyze processes, identify potential risks, and develop policies to maintain compliance with laws and industry standards. CGRC certification, previously known as CAP (Certified Authorization Professional), is offered by (ISC)² and validates knowledge in governance, risk management, and compliance best practices. These professionals often work in cybersecurity, IT, or regulatory roles across various industries.

What are the key skills and qualifications needed to thrive as a Cybersecurity Governance, Risk, and Compliance (CGRC) professional?

To thrive as a CGRC professional, you need a solid understanding of cybersecurity frameworks, risk management, and regulatory compliance, typically supported by a relevant degree and certifications such as CISSP, CISA, or CGRC (formerly CAP). Familiarity with GRC platforms like Archer, ServiceNow GRC, or RSA, as well as knowledge of NIST, ISO, or HIPAA standards, is commonly required. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for interpreting regulations and collaborating across teams. These competencies ensure organizations remain secure and compliant, minimizing risk and avoiding costly penalties.

What are some common challenges CGRC professionals face when managing compliance across multiple frameworks?

CGRC (Cybersecurity Governance, Risk, and Compliance) professionals often encounter the challenge of aligning organizational policies with the requirements of various regulatory frameworks, such as NIST, ISO 27001, and GDPR. This can involve interpreting overlapping or conflicting controls and ensuring consistent documentation and reporting. Additionally, they must facilitate communication and collaboration between IT, legal, and business teams to ensure all stakeholders understand and meet compliance obligations. Keeping up with the evolving regulatory landscape and adapting internal processes accordingly is also a key aspect of the role.

What is the difference between Cgrc vs Compliance Analyst?

AspectCgrcCompliance Analyst
CertificationsCertifications like CFE, CISA, or CMMC often preferredCertifications such as CCEP, CISA, or CIA common
Work EnvironmentTypically in cybersecurity, risk management, or compliance teams within organizationsUsually in corporate compliance departments, auditing firms, or regulatory agencies
Industry UsageUsed in industries like finance, healthcare, and government for cybersecurity and risk managementCommon across various industries for regulatory compliance and risk assessment

The Cgrc (Certified Government Risk Compliance) focuses on government-specific regulations and cybersecurity risk management, while a Compliance Analyst generally handles broader regulatory compliance across industries. Both roles require understanding of compliance frameworks, but Cgrc emphasizes government standards and cybersecurity, making it more specialized in those areas.

Infographic showing various Cgrc job openings in Ohio as of August 2026, with employment types broken down into 84% Full Time, 11% Part Time, and 5% Contract. Highlights an 67% Physical, 10% Hybrid, and 23% Remote job distribution.

Cybersecurity Specialist - Helicopter Program Office (Dayton)

Alpha, OH

DCS Corporation
Guided Missile and Space Vehicle Manufacturing • 1 - 5K employees

Full-time

Posted 12 days ago


Job description

The applicant will provide Cybersecurity technical expertise to the AFLCMC PEO Intelligence, Surveillance, Reconnaissance (ISR) and Special Operations Forces (SOF) Helicopter Program Office.

Essential Job Functions:

The applicant will assist with providing technical expertise and draft documentation required by all policies and decision levels for development, integration, implementation, and sustainment of systems' cybersecurity Assessment and Authorization (A&A) through the appropriate decision accreditation authority.

The applicant will support all cybersecurity audits and required testing events.

The applicant will have working knowledge of threat assessment process, embedded computer systems, software applications, and networking systems.

The applicant will assist in acquiring and maintaining program accounts for Enterprise Mission Assurance Support Service (EMASS) and Information Technology Investment Portfolio Suite (ITIPS).

The applicant will attend program engineering milestone reviews.

The applicant will follow the DoD Risk Management Framework (RMF) and/or PIT process, System Security Plan (SSP) development.

The applicant will participate in a program's Assessment and Authorization Working Group.

The applicant will assist in developing/coordinating presentations, Cyber Impact Evaluation Recommendations (CIER), Interim Authority to Test (IATT) and Authority to Operate (ATO) packages with program office personnel, Certification Authority (CA), Authorizing Official (AO), Subordinate Authorizing Official (SAO), Security Control Assessor (SCA), Security Control Assessor Representative, (SCAR), Air Force Operational Test and Evaluation Command (AFOTEC) and operational command personnel.

The applicant will assist in reviewing/developing/updating applicable program documentation for security relevant requirements/issues. Examples include anti-tamper plans, SS, Information Support Plan (ISP), PPP, Information Assurance Strategy (IAS), RMF, Initial Capabilities Document (ICD), Operational Requirements Document (ORD)/ Capability Development Document (CDD), Concept of Operations (CONOPS), and Security Classification Guide (SCG).

Required Skills:

Due to the sensitivity of customer related requirements, U.S. Citizenship is required.

Platform Cybersecurity (Cybersecurity on military equipment or military subsystems).

A High School Diploma plus 20 years of directly related experience with proper certifications as described in the PWS labor category performance requirements, 8 of which must be in the DoD, a bachelor's degree in a related field ( or industry certification is required in lieu of bachelor's degree) and 12 years of experience in the respective technical/professional discipline being performed, 5 of which must be in the DoD OR a Master's or Doctorate Degree in a related field and 10 years of experience in the respective technical / professional discipline being performed, 5years of which must be in the DoD.

Requires an active TS security clearance.

The applicant must meet the requirements identified in DAFMAN 17-1303 and detailed in DoD Manual 8140.03.  It is required for the applicant to have Certified in Governance, Risk, & Compliance (CGRC) and it is highly recommended to have Certified Information Systems Security Professional (CISSP) certification. remainder of employment.

Employment Type: Full Time

DCS logo

About DCS

Sourced by ZipRecruiter

DCS Corp is a renowned name in the technology industry, headquartered in Alexandria, VA, US. Found in the late 1970s, DCS Corp provides a broad spectrum of advanced technology, engineering, and analytic solutions for national security clients. The firm specializes in delivering sophisticated systems and technology for land, air, and maritime platforms. They are known for being deeply committed to their mission of enhancing national security.

Industry

Guided missile and space vehicle manufacturing

Company size

1,001 - 5,000 Employees

Headquarters location

Alexandria, VA, US

Year founded

1977

Social media