1

Cgrc Jobs in Silver Spring, MD (NOW HIRING)

RMF and Authorization Lead

Bethesda, MD · Hybrid

$165K - $185K/yr

CISSP, CAP/CGRC, CISM, Security+, or an applicable cloud security certification. Compensation Salary Range: $165,000 - $185,000 annually (commensurate with experience) Benefits: Health, dental, and ...

ISC2 CC or CGRC * CompTIA Security+, CySA+, PenTest+, CASP+ * CEH * Microsoft SC-900 * System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced ...

Showing results 21-40

Cgrc information

What is a CGRC professional?

CGRC professionals, or Certified in Governance, Risk and Compliance, are experts who help organizations manage risk, ensure regulatory compliance, and establish effective governance frameworks. They analyze processes, identify potential risks, and develop policies to maintain compliance with laws and industry standards. CGRC certification, previously known as CAP (Certified Authorization Professional), is offered by (ISC)² and validates knowledge in governance, risk management, and compliance best practices. These professionals often work in cybersecurity, IT, or regulatory roles across various industries.

What are the key skills and qualifications needed to thrive as a Cybersecurity Governance, Risk, and Compliance (CGRC) professional?

To thrive as a CGRC professional, you need a solid understanding of cybersecurity frameworks, risk management, and regulatory compliance, typically supported by a relevant degree and certifications such as CISSP, CISA, or CGRC (formerly CAP). Familiarity with GRC platforms like Archer, ServiceNow GRC, or RSA, as well as knowledge of NIST, ISO, or HIPAA standards, is commonly required. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for interpreting regulations and collaborating across teams. These competencies ensure organizations remain secure and compliant, minimizing risk and avoiding costly penalties.

What are some common challenges CGRC professionals face when managing compliance across multiple frameworks?

CGRC (Cybersecurity Governance, Risk, and Compliance) professionals often encounter the challenge of aligning organizational policies with the requirements of various regulatory frameworks, such as NIST, ISO 27001, and GDPR. This can involve interpreting overlapping or conflicting controls and ensuring consistent documentation and reporting. Additionally, they must facilitate communication and collaboration between IT, legal, and business teams to ensure all stakeholders understand and meet compliance obligations. Keeping up with the evolving regulatory landscape and adapting internal processes accordingly is also a key aspect of the role.

What is the difference between Cgrc vs Compliance Analyst?

AspectCgrcCompliance Analyst
CertificationsCertifications like CFE, CISA, or CMMC often preferredCertifications such as CCEP, CISA, or CIA common
Work EnvironmentTypically in cybersecurity, risk management, or compliance teams within organizationsUsually in corporate compliance departments, auditing firms, or regulatory agencies
Industry UsageUsed in industries like finance, healthcare, and government for cybersecurity and risk managementCommon across various industries for regulatory compliance and risk assessment

The Cgrc (Certified Government Risk Compliance) focuses on government-specific regulations and cybersecurity risk management, while a Compliance Analyst generally handles broader regulatory compliance across industries. Both roles require understanding of compliance frameworks, but Cgrc emphasizes government standards and cybersecurity, making it more specialized in those areas.

What are popular job titles related to Cgrc jobs in Silver Spring, MD?

For Cgrc jobs in Silver Spring, MD, the most frequently searched job titles are:

What job categories do people searching Cgrc jobs in Silver Spring, MD look for?

The top searched job categories for Cgrc jobs in Silver Spring, MD are:

What cities near Silver Spring, MD are hiring for Cgrc jobs?

Cities near Silver Spring, MD with the most Cgrc job openings:

Infographic showing various Cgrc job openings in Silver Spring, MD as of August 2026, with employment types broken down into 89% Full Time, 7% Part Time, and 4% Contract. Highlights an 73% Physical, 9% Hybrid, and 18% Remote job distribution.

Senior Information System Security Officer (ISSO)

C3EL

Washington, DC • On-site

Full-time

Posted 9 days ago


Job description

**CONTINGENT UPON CONTRACT AWARD**
Overview:
Job Title: Senior Information System Security Officer (ISSO)
Security Clearance: Ability to Obtain Tier 4 High-Risk Public Trust
Location: Washington, D.C.
(Due to the nature of the work and contract requirements, U.S. Citizenship is required.)
Description:
C3EL is seeking a Senior Information System Security Officer (ISSO) to provide on-site cybersecurity and Risk Management Framework (RMF) sustainment support in Washington, D.C., for a new contract. This role will serve as Operational Specialist for Splunk, ServiceNow, ConMon, vulnerability management, POA&M, and incident and change coordination, as well as being workstream lead and secondary backup for Lead ISSO duties.
Responsibilities will include, but not be limited to:
  • Provide on-site cybersecurity and RMF sustainment support.
  • Maintain traceability between ServiceNow remediation tickets and CSAM POA&M records.
  • Analyze findings, validate false positives, and prioritize remediation using CVSS, CISA KEV, exposure, exploitability, and mission impact.
  • Support notification, triage, CSAM context retrieval, Splunk verification, SitReps, RCA, corrective actions, and post-incident updates.
  • Support CAB/CCB/ERB reviews, security impact analysis, artifact updates, and post-change verification.
  • Track audit, penetration-test, and assessment findings through corrective action and evidence-supported closure.
  • Maintain incident-response plans and support tabletop or functional exercises.
  • Produce accurate, concise, and audit-ready Government cybersecurity documentation.
  • Support team coverage from 7:00 a.m. to 6:00 p.m. ET (M-F) and participate in after-hours incident coverage as needed.

Minimum Qualifications:
  • U.S. Citizenship.
  • Eligibility to obtain a Tier 4 High-Risk Public Trust.
  • Minimum seven (7) years of cybersecurity.
  • Minimum five (5) years in federal ISSO, ConMon, vulnerability, security operations, or compliance work.
  • Working knowledge of NIST SP 800-37, 800-53, 800-53B, FIPS 199, FISMA, and applicable CISA/OMB guidance.
  • Familiarity with GRC, ITSM, SIEM, scanner, identity, endpoint, and cloud-security platforms.
  • Direct experience with Splunk searches, dashboards, ingestion verification, log coverage, and incident timeline support.
  • Direct experience with ServiceNow incidents, problems, changes, remediation tickets, and reporting.
  • Direct experience with Tenable Nessus, Qualys, ACAS, or comparable Government-approved scanners.
  • Experience with Defender, Intune, BigFix, or equivalent endpoint and configuration platforms.

Preferred Qualifications:
  • At least one current cybersecurity certification such as CISSP, CGRC, CISM, CRISC, Security+, SecurityX, CCSP, or GIAC.

Education:
  • Associate's degree in Cybersecurity, Information Technology, or related field. (Relevant experience may be considered in lieu of formal education.)