1

Cgrc Jobs in Silver Spring, MD (NOW HIRING)

CGRC or CEH. Direct CSAM experience. Prior support to a federal civilian CISO organization. Existing federal background investigation eligible for reciprocity under PWS 5.4.

Lead ISSO

Washington, DC · On-site

$130 - $180/hr

CISSP, CISM, CGRC, or equivalent certification preferred * U.S. Citizenship required * Tier 4 High-Risk Public Trust is required E-Logic Inc. is an Equal Opportunity Employer.All qualified applicants ...

Lead ISSO

Washington, DC · Remote

$130K/yr

CISSP, CISM, CGRC, or equivalent certification preferred * U.S. Citizenship required * Tier 4 High-Risk Public Trust is required E-Logic Inc. is an Equal Opportunity Employer. All qualified ...

Senior Information Security Engineer

Reston, VA · Remote

$110K - $150K/yr

Certified in Governance, Risk and Compliance (CGRC) or Certified Cloud Security Professional (CCSP) Preferred Qualifications * Experience supporting U.S. federal civilian agencies, preferably the ...

Senior Information Security Engineer

Reston, VA · Remote

$110K - $150K/yr

Certified in Governance, Risk and Compliance (CGRC) or Certified Cloud Security Professional (CCSP) Preferred Qualifications * Experience supporting U.S. federal civilian agencies, preferably the ...

Cybersecurity Program Manager

Reston, VA · Remote

$115K - $156K/yr

Certified in Governance, Risk and Compliance (CGRC) or Certified Cloud Security Professional (CCSP) Preferred Qualifications * Experience supporting U.S. federal civilian agencies, preferably the ...

next page

Showing results 1-20

Cgrc information

What is a CGRC professional?

CGRC professionals, or Certified in Governance, Risk and Compliance, are experts who help organizations manage risk, ensure regulatory compliance, and establish effective governance frameworks. They analyze processes, identify potential risks, and develop policies to maintain compliance with laws and industry standards. CGRC certification, previously known as CAP (Certified Authorization Professional), is offered by (ISC)² and validates knowledge in governance, risk management, and compliance best practices. These professionals often work in cybersecurity, IT, or regulatory roles across various industries.

What are the key skills and qualifications needed to thrive as a Cybersecurity Governance, Risk, and Compliance (CGRC) professional?

To thrive as a CGRC professional, you need a solid understanding of cybersecurity frameworks, risk management, and regulatory compliance, typically supported by a relevant degree and certifications such as CISSP, CISA, or CGRC (formerly CAP). Familiarity with GRC platforms like Archer, ServiceNow GRC, or RSA, as well as knowledge of NIST, ISO, or HIPAA standards, is commonly required. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for interpreting regulations and collaborating across teams. These competencies ensure organizations remain secure and compliant, minimizing risk and avoiding costly penalties.

What are some common challenges CGRC professionals face when managing compliance across multiple frameworks?

CGRC (Cybersecurity Governance, Risk, and Compliance) professionals often encounter the challenge of aligning organizational policies with the requirements of various regulatory frameworks, such as NIST, ISO 27001, and GDPR. This can involve interpreting overlapping or conflicting controls and ensuring consistent documentation and reporting. Additionally, they must facilitate communication and collaboration between IT, legal, and business teams to ensure all stakeholders understand and meet compliance obligations. Keeping up with the evolving regulatory landscape and adapting internal processes accordingly is also a key aspect of the role.

What is the difference between Cgrc vs Compliance Analyst?

AspectCgrcCompliance Analyst
CertificationsCertifications like CFE, CISA, or CMMC often preferredCertifications such as CCEP, CISA, or CIA common
Work EnvironmentTypically in cybersecurity, risk management, or compliance teams within organizationsUsually in corporate compliance departments, auditing firms, or regulatory agencies
Industry UsageUsed in industries like finance, healthcare, and government for cybersecurity and risk managementCommon across various industries for regulatory compliance and risk assessment

The Cgrc (Certified Government Risk Compliance) focuses on government-specific regulations and cybersecurity risk management, while a Compliance Analyst generally handles broader regulatory compliance across industries. Both roles require understanding of compliance frameworks, but Cgrc emphasizes government standards and cybersecurity, making it more specialized in those areas.

What are popular job titles related to Cgrc jobs in Silver Spring, MD?

For Cgrc jobs in Silver Spring, MD, the most frequently searched job titles are:

What job categories do people searching Cgrc jobs in Silver Spring, MD look for?

The top searched job categories for Cgrc jobs in Silver Spring, MD are:

What cities near Silver Spring, MD are hiring for Cgrc jobs?

Cities near Silver Spring, MD with the most Cgrc job openings:

Infographic showing various Cgrc job openings in Silver Spring, MD as of August 2026, with employment types broken down into 89% Full Time, 7% Part Time, and 4% Contract. Highlights an 73% Physical, 9% Hybrid, and 18% Remote job distribution.

Senior ISSO

RJIT Solutions

Washington, DC • Remote

Full-time

Re-posted 8 days ago


Job description

Purpose. Carry continuous monitoring, incident response coordination, and audit and assessment support; serve as second-line backup to the Lead ISSO.

Reports to: Lead ISSO for task direction.

Core responsibilities.

  • Execute continuous monitoring and security posture management, producing outputs that support Government risk decisions, audit readiness, and ongoing authorization.
  • Coordinate incident response with the DFC SOC, meeting the acknowledgement and notification timeframes in the PWS, and maintain incident documentation and after-action records.
  • Support audits and assessments: maintain audit-ready evidence, sustain traceability between requirements and artifacts, reduce evidence-collection burden on Government staff, and identify documentation gaps before assessors do.
  • Support vulnerability analysis and POA&M lifecycle activities in coordination with remediation teams, recognizing that closure approval, schedule extensions, and risk acceptance are reserved to Government officials.
  • Maintain proficiency in CSAM, ServiceNow, Splunk, and the vulnerability scanning platforms in use.

Required qualifications. Ten or more years of federal cybersecurity experience. Hands-on authorization package development and security control assessment. Operational experience with a federal GRC platform and an enterprise SIEM. Demonstrated coordination with an agency security operations center during live incidents. Active CISSP.

Preferred. CGRC or CEH. Direct CSAM experience. Prior support to a federal civilian CISO organization. Existing federal background investigation eligible for reciprocity under PWS 5.4.