1

Cgrc Jobs in Silver Spring, MD (NOW HIRING)

Senior ISSO

Washington, DC · Remote

$100K - $110K/yr

CGRC or CEH. Direct CSAM experience. Prior support to a federal civilian CISO organization. Existing federal background investigation eligible for reciprocity under PWS 5.4.

Lead ISSO

Washington, DC · Remote

$130K/yr

CISSP, CISM, CGRC, or equivalent certification preferred * U.S. Citizenship required * Tier 4 High-Risk Public Trust is required E-Logic Inc. is an Equal Opportunity Employer. All qualified ...

ISC2 CC or CGRC * CompTIA Security+, CySA+, PenTest+, CASP+ * CEH * Microsoft SC-900 * System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced ...

ISC2 CC or CGRC * CompTIA Security+, CySA+, PenTest+, CASP+ * CEH * Microsoft SC-900 * System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced ...

next page

Showing results 1-20

Cgrc information

What is a CGRC professional?

CGRC professionals, or Certified in Governance, Risk and Compliance, are experts who help organizations manage risk, ensure regulatory compliance, and establish effective governance frameworks. They analyze processes, identify potential risks, and develop policies to maintain compliance with laws and industry standards. CGRC certification, previously known as CAP (Certified Authorization Professional), is offered by (ISC)² and validates knowledge in governance, risk management, and compliance best practices. These professionals often work in cybersecurity, IT, or regulatory roles across various industries.

What are the key skills and qualifications needed to thrive as a Cybersecurity Governance, Risk, and Compliance (CGRC) professional?

To thrive as a CGRC professional, you need a solid understanding of cybersecurity frameworks, risk management, and regulatory compliance, typically supported by a relevant degree and certifications such as CISSP, CISA, or CGRC (formerly CAP). Familiarity with GRC platforms like Archer, ServiceNow GRC, or RSA, as well as knowledge of NIST, ISO, or HIPAA standards, is commonly required. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for interpreting regulations and collaborating across teams. These competencies ensure organizations remain secure and compliant, minimizing risk and avoiding costly penalties.

What is the difference between Cgrc vs Compliance Analyst?

AspectCgrcCompliance Analyst
CertificationsCertifications like CFE, CISA, or CMMC often preferredCertifications such as CCEP, CISA, or CIA common
Work EnvironmentTypically in cybersecurity, risk management, or compliance teams within organizationsUsually in corporate compliance departments, auditing firms, or regulatory agencies
Industry UsageUsed in industries like finance, healthcare, and government for cybersecurity and risk managementCommon across various industries for regulatory compliance and risk assessment

The Cgrc (Certified Government Risk Compliance) focuses on government-specific regulations and cybersecurity risk management, while a Compliance Analyst generally handles broader regulatory compliance across industries. Both roles require understanding of compliance frameworks, but Cgrc emphasizes government standards and cybersecurity, making it more specialized in those areas.

What are some common challenges CGRC professionals face when managing compliance across multiple frameworks?

CGRC (Cybersecurity Governance, Risk, and Compliance) professionals often encounter the challenge of aligning organizational policies with the requirements of various regulatory frameworks, such as NIST, ISO 27001, and GDPR. This can involve interpreting overlapping or conflicting controls and ensuring consistent documentation and reporting. Additionally, they must facilitate communication and collaboration between IT, legal, and business teams to ensure all stakeholders understand and meet compliance obligations. Keeping up with the evolving regulatory landscape and adapting internal processes accordingly is also a key aspect of the role.

What are popular job titles related to Cgrc jobs in Silver Spring, MD?

For Cgrc jobs in Silver Spring, MD, the most frequently searched job titles are:

What job categories do people searching Cgrc jobs in Silver Spring, MD look for?

The top searched job categories for Cgrc jobs in Silver Spring, MD are:

What cities near Silver Spring, MD are hiring for Cgrc jobs?

Cities near Silver Spring, MD with the most Cgrc job openings:

Infographic showing various Cgrc job openings in Silver Spring, MD as of August 2026, with employment types broken down into 38% Part Time, and 62% Contract. Highlights an 100% In-person job distribution.

Senior Consultant - Cybersecurity Risk

Jobtailor

Washington, DC • On-site

$140 - $180/hr

Other

Posted yesterday

New


Job description

  • Lead a cybersecurity risk management and risk governance workstream within an agency
  • Oversee, manage, and lead development and execution of cybersecurity risk governance
  • Maintain and improve the enterprise-level risk register
  • Oversee technology risk assessments, including Tier 1 assessments supporting Technology Review Board decisions
  • Prepare risk acceptance memoranda for CISO and CIO approval
  • Conduct limited FOCI-style assessments to support agency decision‐making
  • Interpret and adapt guidance for Tier 1 enterprise risk assessments
  • Scope technology risk assessments, confirm outputs and required elements, and prepare decision‑support deliverables
  • Prepare plans and goals to improve the cyber risk register and support agency cyber risk profiles
  • Prepare and implement corrective action plans addressing open GAO or OIG recommendations
  • Incorporate federal cybersecurity frameworks into evaluations and assessments
  • Prepare and update risk management plans, standard operating procedures, and project schedules
  • Present technology risk assessment findings and recommendations to technical and executive audiences
  • Prepare briefing materials for weekly reports and specific audiences
  • Advise on assessment severity and recommend courses of action to government stakeholders
  • Adapt guidance and technical assistance to resource constraints, knowledge variability, and government leadership direction
Requirements
  • Active and current Secret federal security clearance
  • Bachelor’s Degree from an accredited university
  • Minimum of five years of relevant cybersecurity experience
  • US Citizenship contractually required
  • Excellent verbal and written communication skills, specifically in report writing
  • Certified in CISSP, CRISC, CAP/CGRC, CISA, or another relevant field
  • Experience interpreting and applying federal cybersecurity requirements and frameworks
  • Ability to conduct and scope technology risk assessments
  • Ability to prepare risk acceptance memoranda, risk management plans, SOPs, schedules, briefings, and corrective action plans
  • Nice to have: consulting experience with large federal agencies such as the Department of State, Department of Justice, or Department of Homeland Security on cybersecurity audits and/or IT controls
  • Nice to have: external client‑facing management and/or consulting experience for large firms
Core Competencies

Demonstrates expertise in cybersecurity risk management, including the ability to conduct technology risk assessments, prepare risk management plans, and adapt federal cybersecurity frameworks. Strong communication skills are essential for presenting findings and recommendations to both technical and executive audiences.

Highest-signal resume keywords
  • Cybersecurity Risk Management
  • Technology Risk Assessments
  • Risk Governance Development
  • CISSP Certification
  • Federal Cybersecurity Frameworks
ATS Optimization KeywordsHard Skills
  • Risk Management Plans
  • Risk Acceptance Memoranda
  • Standard Operating Procedures
  • Corrective Action Plans
  • Technology Review Board Assessments
  • FOCI-Style Assessments
  • Decision-Support Deliverables
  • Cyber Risk Register Improvement
  • Report Writing
  • Project Schedules
Soft Skills
  • Excellent Verbal Communication
  • Excellent Written Communication
  • Advisory Skills
Certifications & Qualifications
  • CISSP
  • CRISC
  • CAP
  • CGRC
  • CISA
Industry Keywords
  • Federal Security Clearance
  • Cybersecurity Audits
  • IT Controls
  • Department of State
  • Department of Justice
  • Department of Homeland Security
#J-18808-Ljbffr