1

Cgrc Jobs in Virginia (NOW HIRING)

Cybersecurity Risk Analyst

Mclean, VA · On-site

$100K - $150K/yr

Relevant cybersecurity certification, such as CISSP, CISM, CGRC, Security+, or CASP+. Company Overview Ops Tech Alliance (OTA) was founded by former National Security and Special Operations ...

... CGRC), Certified Information Systems Auditor (CISA) What Would Be Nice To Have: * Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department ...

... CGRC), Certified Information Systems Auditor (CISA) What Would Be Nice To Have: * Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department ...

Relevant cybersecurity or IT certifications (e.g., Security+, CISA, NIST CSF, PMP, CGRC, CISSP or CISM) * Experience partnering with Risk, Compliance, Legal, and Internal Audit teams * Familiarity ...

Relevant cybersecurity or IT certifications (e.g., Security+, CISA, NIST CSF, PMP, CGRC, CISSP or CISM) * Experience partnering with Risk, Compliance, Legal, and Internal Audit teams * Familiarity ...

Showing results 41-60

Cgrc information

What is a CGRC professional?

CGRC professionals, or Certified in Governance, Risk and Compliance, are experts who help organizations manage risk, ensure regulatory compliance, and establish effective governance frameworks. They analyze processes, identify potential risks, and develop policies to maintain compliance with laws and industry standards. CGRC certification, previously known as CAP (Certified Authorization Professional), is offered by (ISC)² and validates knowledge in governance, risk management, and compliance best practices. These professionals often work in cybersecurity, IT, or regulatory roles across various industries.

What are the key skills and qualifications needed to thrive as a Cybersecurity Governance, Risk, and Compliance (CGRC) professional?

To thrive as a CGRC professional, you need a solid understanding of cybersecurity frameworks, risk management, and regulatory compliance, typically supported by a relevant degree and certifications such as CISSP, CISA, or CGRC (formerly CAP). Familiarity with GRC platforms like Archer, ServiceNow GRC, or RSA, as well as knowledge of NIST, ISO, or HIPAA standards, is commonly required. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for interpreting regulations and collaborating across teams. These competencies ensure organizations remain secure and compliant, minimizing risk and avoiding costly penalties.

What are some common challenges CGRC professionals face when managing compliance across multiple frameworks?

CGRC (Cybersecurity Governance, Risk, and Compliance) professionals often encounter the challenge of aligning organizational policies with the requirements of various regulatory frameworks, such as NIST, ISO 27001, and GDPR. This can involve interpreting overlapping or conflicting controls and ensuring consistent documentation and reporting. Additionally, they must facilitate communication and collaboration between IT, legal, and business teams to ensure all stakeholders understand and meet compliance obligations. Keeping up with the evolving regulatory landscape and adapting internal processes accordingly is also a key aspect of the role.

What is the difference between Cgrc vs Compliance Analyst?

AspectCgrcCompliance Analyst
CertificationsCertifications like CFE, CISA, or CMMC often preferredCertifications such as CCEP, CISA, or CIA common
Work EnvironmentTypically in cybersecurity, risk management, or compliance teams within organizationsUsually in corporate compliance departments, auditing firms, or regulatory agencies
Industry UsageUsed in industries like finance, healthcare, and government for cybersecurity and risk managementCommon across various industries for regulatory compliance and risk assessment

The Cgrc (Certified Government Risk Compliance) focuses on government-specific regulations and cybersecurity risk management, while a Compliance Analyst generally handles broader regulatory compliance across industries. Both roles require understanding of compliance frameworks, but Cgrc emphasizes government standards and cybersecurity, making it more specialized in those areas.

What cities in Virginia are hiring for Cgrc jobs?

Cities in Virginia with the most Cgrc job openings:

Infographic showing various Cgrc job openings in Virginia as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution.

Senior Information System Security Officer (ISSO) - Remote

Yakshna Solutions, Inc.

Herndon, VA • On-site

$125 - $150/hr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 20 days ago


Key responsibilities

  • Perform senior ISSO duties for assigned systems as directed by the Lead ISSO.

  • Support consistent execution of ISSO activities across assigned systems.

  • Lead assigned RMF, continuous monitoring, vulnerability management, POA&M, audit-support, and compliance workstreams.


Job description

We strive to attract and retain the brightest people and offer different job experiences with a full range of challenges and rewards.

We help companies realize and implement IT solutions strategically. Yakshna Solutions supports our client’s mission and goals by sharing our know-how, skills and knowledge. We strive to attract and retain the brightest people and offer different job experiences with a full range of challenges and rewards. We take pride in being an equal opportunity employer.

Working with Yakshna gives you the opportunity to develop your knowledge, skills, and abilities. Additionally, you can build a network of peers, mentors and advance your career! We offer exciting opportunities to work with leading industry experts, business consultants and IT specialists across large government and private sector companies. The people who work in Yakshna are as diverse as our services. We recognize the crucial importance of each individual to our success and offer competitive compensation, comprehensive benefits and innovative training.

Opportunities here exist across many services and across many US states. Don’t forget to refer your friends to earn cash for qualified referrals! Based on your relevant profile and our current requirements, our recruitment team will contact you as soon as possible.

Open Jobs

Jul 22 2026

ID

Job Title

888712 Senior Information System Security Officer (ISSO)

Yakshna Solutions, Inc ., YSI is a CMMI Level 3 assessed, ISO 9001, 20000:1, 27001 certified, woman-owned small business enterprises, headquartered in Herndon, Virginia, USA. YSI provides professional IT solutions and services to business corporations and government organizations. YSI is committed to serve its business communities as a leading IT vendor providing innovative, quality, and cost-effective IT business solutions and services.

We offer a competitive benefits package that includes the following:
  • 401(k)
  • health insurance
  • dental insurance
  • vision insurance
  • Life insurance
  • short-term disability insurance
  • long-term disability insurance
  • paid time off
  • training
  • professional development assistance

YSI is seeking a Senior ISSO. The Senior ISSO shall be qualified to assume Lead ISSO duties during scheduled or unscheduled absences and shall maintain continuity of ISSO operations.

Job Responsibilities
  • Shall perform senior ISSO duties for assigned systems as directed by the Lead ISSO.
  • Support consistent execution of ISSO activities across assigned systems
  • Lead assigned RMF, continuous monitoring, vulnerability management, POA&M, audit-support, and compliance workstreams
  • Maintain proficiency in DFC authoritative tools, including ServiceNow, CSAM, Splunk, and vulnerability scanning platforms in use.
Required Skills & Experience
  • Education: BS Degree in Computer Science, Cybersecurity, or IT related field.
  • 8 years of relevant experience as an ISSO or in the IT field.
  • Shall demonstrate working familiarity with cybersecurity-relevant tools and platforms used to support DFC ISSO, RMF, continuous monitoring, vulnerability management, audit readiness, and security operations activities. These tools and platforms include, without limitation
    • CSAM as the authoritative GRC and authorization-package platform
    • Splunk as the authoritative SIEM and log-analytics platform
    • ServiceNow ITSM modules
    • Tenable Nessus or Qualys vulnerability scanners
    • Microsoft Defender for Endpoint, Identity, Cloud, and Microsoft 365
    • Microsoft Intune and BigFix for endpoint configuration
    • Microsoft Azure and Microsoft 365 security and compliance centers
    • Microsoft Entra ID; Okta; Palo Alto Panorama; and Zscaler administration consoles.
  • Preferred certifications: CISSP or CISM, plus CGRC. Additional certs to consider: CRISC, CISA, CCSP, CISSP-ISSMP, CySA+
Location: Remote Clearance: Tier 4 Public Trust Salary: $120,000-$130,000 annually with benefits US Citizen or Green card holder only

YSI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.

#J-18808-Ljbffr