1

Cgrc Jobs in Virginia (NOW HIRING)

Relevant cybersecurity or IT certifications (e.g., Security+, CISA, NIST CSF, PMP, CGRC, CISSP or CISM) * Experience partnering with Risk, Compliance, Legal, and Internal Audit teams * Familiarity ...

CBROPS, CCISO, CCSP, CEH, CGRC/CAP, Cloud+, CySA+, FITSP-O, GCIH, GICSP, GISF, GFACT, GCED, GSEC, PenTest+, Security+, SecurityX/CASP+, and/or SSCP cerification (for Junior / Journeyman roles) * CCE ...

Showing results 21-40

Cgrc information

What is a CGRC professional?

CGRC professionals, or Certified in Governance, Risk and Compliance, are experts who help organizations manage risk, ensure regulatory compliance, and establish effective governance frameworks. They analyze processes, identify potential risks, and develop policies to maintain compliance with laws and industry standards. CGRC certification, previously known as CAP (Certified Authorization Professional), is offered by (ISC)² and validates knowledge in governance, risk management, and compliance best practices. These professionals often work in cybersecurity, IT, or regulatory roles across various industries.

What are the key skills and qualifications needed to thrive as a Cybersecurity Governance, Risk, and Compliance (CGRC) professional?

To thrive as a CGRC professional, you need a solid understanding of cybersecurity frameworks, risk management, and regulatory compliance, typically supported by a relevant degree and certifications such as CISSP, CISA, or CGRC (formerly CAP). Familiarity with GRC platforms like Archer, ServiceNow GRC, or RSA, as well as knowledge of NIST, ISO, or HIPAA standards, is commonly required. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for interpreting regulations and collaborating across teams. These competencies ensure organizations remain secure and compliant, minimizing risk and avoiding costly penalties.

What are some common challenges CGRC professionals face when managing compliance across multiple frameworks?

CGRC (Cybersecurity Governance, Risk, and Compliance) professionals often encounter the challenge of aligning organizational policies with the requirements of various regulatory frameworks, such as NIST, ISO 27001, and GDPR. This can involve interpreting overlapping or conflicting controls and ensuring consistent documentation and reporting. Additionally, they must facilitate communication and collaboration between IT, legal, and business teams to ensure all stakeholders understand and meet compliance obligations. Keeping up with the evolving regulatory landscape and adapting internal processes accordingly is also a key aspect of the role.

What is the difference between Cgrc vs Compliance Analyst?

AspectCgrcCompliance Analyst
CertificationsCertifications like CFE, CISA, or CMMC often preferredCertifications such as CCEP, CISA, or CIA common
Work EnvironmentTypically in cybersecurity, risk management, or compliance teams within organizationsUsually in corporate compliance departments, auditing firms, or regulatory agencies
Industry UsageUsed in industries like finance, healthcare, and government for cybersecurity and risk managementCommon across various industries for regulatory compliance and risk assessment

The Cgrc (Certified Government Risk Compliance) focuses on government-specific regulations and cybersecurity risk management, while a Compliance Analyst generally handles broader regulatory compliance across industries. Both roles require understanding of compliance frameworks, but Cgrc emphasizes government standards and cybersecurity, making it more specialized in those areas.

What cities in Virginia are hiring for Cgrc jobs?

Cities in Virginia with the most Cgrc job openings:

Infographic showing various Cgrc job openings in Virginia as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution.

Senior Cybersecurity Integration Engineer

BaseCamp Consulting & Solutions

Reston, VA • On-site

$112K - $152K/yr

Full-time

Posted 18 days ago


Job description

POSITION OVERVIEW

The Senior Cybersecurity Integration Engineer secures and integrates the Customer's enterprise API gateway, drives it through the Risk Management Framework to a signed Authority to Operate (ATO), and keeps it authorized. The role pairs hands-on security engineering at the API boundary with ownership of the System Security Plan and the continuous monitoring that sustains it. Requires an active Moderate Background Investigation (MBI) at start.


RESPONSIBILITIES

  • Design and enforce API security policy — authentication, authorization, token validation, rate limiting, payload validation, threat protection
  • Manage TLS, mutual TLS, and certificate and key lifecycle across all environments and trust relationships
  • Onboard applications, vendors, and SaaS services, coordinating firewall, proxy, DNS, and load balancer changes with owning teams
  • Integrate the gateway with enterprise identity and federation services
  • Harden gateway and hosts to STIG/SCAP and feed security telemetry to the enterprise SIEM
  • Promote configuration through the Customer's environments under Government change control
  • Author and maintain the SSP and control narratives against NIST 800-53 Rev 5, covering boundary, inventory, inheritance, and tailoring
  • Run the RMF package to ATO: evidence, assessor walkthroughs, finding resolution
  • Sustain ConMon: recurring scans, false positive validation, remediation and retest, POA&M closure, deviation requests, monthly reporting
  • Perform security impact analysis on changes and troubleshoot across gateway, network, identity, and application layers


REQUIRED QUALIFICATIONS

  • Active MBI, current and transferable as of your start date
  • U.S. citizenship, as required for Customer contractor staff
  • Eight years of hands-on cybersecurity or integration engineering on enterprise API gateway, IAM, or boundary security platforms in production, including three years in a Federal FISMA environment
  • Production ownership of an enterprise API gateway or comparable platform: policy authoring, upgrades, certificate lifecycle, environment promotion, and production support
  • Depth in API and web security protocols: OAuth 2.0, OpenID Connect, JWT validation, SAML 2.0 federation, mutual TLS, PKI, and the OWASP API Security Top 10
  • Experience integrating services across network and security boundaries, coordinating changes with separate firewall, proxy, and identity teams
  • Authorship of a System Security Plan for a Federal system, writing control narratives from actual configuration and documenting inherited, hybrid, and tailored controls
  • Experience carrying a system or major component through RMF to a signed ATO, then sustaining it under continuous monitoring
  • Command of FISMA and NIST 800-37, 800-53 Rev 5, 800-53A, and 800-137
  • End-to-end vulnerability management: scanning, validating false positives, remediating, retesting, and documenting closure
  • Linux administration on RHEL or CentOS, shell scripting, and SIEM log integration such as Splunk
  • Technical writing strong enough that control narratives hold up under assessor review
  • Bachelor's degree in Engineering, Computer Science, Cybersecurity, or Information Systems, or equivalent hands-on experience


PREFERRED QUALIFICATIONS

  • An active professional security certification such as CISSP, CISA, CISM, CAP or CGRC, GIAC, or Security+
  • Time as an ISSO or ISSM, or directly supporting one, on a FISMA-reportable system
  • Hands-on authoring inside a GRC or RMF tool of record such as eMASS, Xacta, or CSAM
  • An active vendor certification on the program's gateway platform, or willingness to earn it within 90 days; training provided
  • Prior support to a Federal financial or tax administration program
  • Experience with configuration-as-code, separated control and data planes, and API-driven gateway administration
  • Depth in a federation platform such as Ping Federate, Ping Access, or CA SiteMinder