1

Cgrc Jobs in Baltimore, MD (NOW HIRING)

DoD Manual 8140.03 approved Cybersecurity Certification such as ISC2 CC, ISC2 CGRC, CompTIA CASP+, CompTIA, or GAIC GSEC * 3 years of experience in cybersecurity documentation, policy development, or ...

CGRC (ISC2 Certified Governance, Risk And Compliance) * GSLC (GIAC Security Leadership Certification) * CISM (Certified Information Security Manager) * CISSP (Associate or Full) * CASP+ (CompTIA ...

Current DoD 8570/8140 IAM Level II or IAM Level III certification (SecurityX/CASP+ CE, CGRC/CAP, CISM, CISSP or Associate of ISC2, GSLC, or CCISO, as applicable). * Bachelor's degree in Systems ...

next page

Showing results 1-20

Cgrc information

What is a CGRC professional?

CGRC professionals, or Certified in Governance, Risk and Compliance, are experts who help organizations manage risk, ensure regulatory compliance, and establish effective governance frameworks. They analyze processes, identify potential risks, and develop policies to maintain compliance with laws and industry standards. CGRC certification, previously known as CAP (Certified Authorization Professional), is offered by (ISC)² and validates knowledge in governance, risk management, and compliance best practices. These professionals often work in cybersecurity, IT, or regulatory roles across various industries.

What are the key skills and qualifications needed to thrive as a Cybersecurity Governance, Risk, and Compliance (CGRC) professional?

To thrive as a CGRC professional, you need a solid understanding of cybersecurity frameworks, risk management, and regulatory compliance, typically supported by a relevant degree and certifications such as CISSP, CISA, or CGRC (formerly CAP). Familiarity with GRC platforms like Archer, ServiceNow GRC, or RSA, as well as knowledge of NIST, ISO, or HIPAA standards, is commonly required. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for interpreting regulations and collaborating across teams. These competencies ensure organizations remain secure and compliant, minimizing risk and avoiding costly penalties.

What are some common challenges CGRC professionals face when managing compliance across multiple frameworks?

CGRC (Cybersecurity Governance, Risk, and Compliance) professionals often encounter the challenge of aligning organizational policies with the requirements of various regulatory frameworks, such as NIST, ISO 27001, and GDPR. This can involve interpreting overlapping or conflicting controls and ensuring consistent documentation and reporting. Additionally, they must facilitate communication and collaboration between IT, legal, and business teams to ensure all stakeholders understand and meet compliance obligations. Keeping up with the evolving regulatory landscape and adapting internal processes accordingly is also a key aspect of the role.

What is the difference between Cgrc vs Compliance Analyst?

AspectCgrcCompliance Analyst
CertificationsCertifications like CFE, CISA, or CMMC often preferredCertifications such as CCEP, CISA, or CIA common
Work EnvironmentTypically in cybersecurity, risk management, or compliance teams within organizationsUsually in corporate compliance departments, auditing firms, or regulatory agencies
Industry UsageUsed in industries like finance, healthcare, and government for cybersecurity and risk managementCommon across various industries for regulatory compliance and risk assessment

The Cgrc (Certified Government Risk Compliance) focuses on government-specific regulations and cybersecurity risk management, while a Compliance Analyst generally handles broader regulatory compliance across industries. Both roles require understanding of compliance frameworks, but Cgrc emphasizes government standards and cybersecurity, making it more specialized in those areas.

What cities near Baltimore, MD are hiring for Cgrc jobs?

Cities near Baltimore, MD with the most Cgrc job openings:

Infographic showing various Cgrc job openings in Baltimore, MD as of August 2026, with employment types broken down into 88% Full Time, 8% Part Time, and 4% Contract. Highlights an 80% Physical, 4% Hybrid, and 16% Remote job distribution.

Cybersecurity Analyst with Security Clearance

Blue Sky Innovative Solutions LLC

Fort George G Meade, MD • On-site

Other

Re-posted 17 days ago


Job description

Cybersecurity Analyst — RMF / A&A (TS/SCI) Join the team that authorizes the DoD's commercial cloud. You will assess Cloud Service Provider offerings
against the DoD Cloud Computing SRG at Impact Levels 4, 5, and 6, supporting the Government's assessment and authorization (A&A) mission under the Risk Management Framework. Five openings — a rare chance to join a full cyber team at stand-up. How You'll Make an Impact • Evaluate CSP deliverables and Provisional Authorization documentation for compliance with DoD CSP SRG IL4/IL5/IL6. • Analyze A&A packages against contract security requirements and draft compliance assessment methodologies. • Coordinate verification of CSP requirements in Government tracking tools (eMASS, ACAS, CMRS, and related systems). • Facilitate authorization process syncs, user community round tables, and CSP engagement on compliance status. • Research cloud security trends, validate system configurations and logs, and support CSSP and network defense troubleshooting. What You'll Need to Join the Team • Bachelor's degree + 4 years of experience, OR 8 years total in cybersecurity assessment and authorization (RMF, NIST SP 800-53, DoD compliance). • Active TS/SCI clearance • Meets DoD 8140 requirements for Work Role 612, Security Control Assessor (Intermediate); alternate Work Role 722, ISSM. What Sets You Apart • Hands-on eMASS package development and workflow management experience. • Experience assessing CSPs or cloud systems under the DoD Cloud Computing SRG or FedRAMP. • Working knowledge of STIGs, ACAS/Nessus scanning, and POA&M management. Certifications (examples of approved options)
DoD 8140 WRC 612 (Intermediate) examples: ISC2 CGRC (formerly CAP), ISACA CISA, CompTIA SecurityX
(formerly CASP+), CISSP.