1

Cgrc Jobs in Springfield, VA (NOW HIRING)

ISC2 CC or CGRC * CompTIA Security+, CySA+, PenTest+, CASP+ * CEH * Microsoft SC-900 * System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced ...

ISC2 CC or CGRC * CompTIA Security+, CySA+, PenTest+, CASP+ * CEH * Microsoft SC-900 * System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced ...

ISC2 CC or CGRC * CompTIA Security+, CySA+, PenTest+, CASP+ * CEH * Microsoft SC-900 * System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced ...

ISC2 CC or CGRC * CompTIA Security+, CySA+, PenTest+, CASP+ * CEH * Microsoft SC-900 * System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced ...

CAP/CGRC * CISSP * CISM * Knowledge, Skills, and Abilities Strong analytical, organizational, and communication skills with knowledge of RMF processes, documentation, and federal cybersecurity ...

CAP/CGRC * CISSP * CISM * Knowledge, Skills, and Abilities Strong analytical, organizational, and communication skills with knowledge of RMF processes, documentation, and federal cybersecurity ...

CAP/CGRC * CISSP * CISM * Knowledge, Skills, and Abilities Strong analytical, organizational, and communication skills with knowledge of RMF processes, documentation, and federal cybersecurity ...

CAP/CGRC * CISSP * CISM * Knowledge, Skills, and Abilities Strong analytical, organizational, and communication skills with knowledge of RMF processes, documentation, and federal cybersecurity ...

CGRC (formerly CAP) * CISSP * Experience supporting HHS or other Federal civilian agencies. * Experience supporting research, scientific, healthcare, or biomedical environments. * Knowledge of ...

CAP/CGRC * CISSP * CISM * Knowledge, Skills, and Abilities Strong analytical, organizational, and communication skills with knowledge of RMF processes, documentation, and federal cybersecurity ...

Showing results 21-40

Cgrc information

What is a CGRC professional?

CGRC professionals, or Certified in Governance, Risk and Compliance, are experts who help organizations manage risk, ensure regulatory compliance, and establish effective governance frameworks. They analyze processes, identify potential risks, and develop policies to maintain compliance with laws and industry standards. CGRC certification, previously known as CAP (Certified Authorization Professional), is offered by (ISC)² and validates knowledge in governance, risk management, and compliance best practices. These professionals often work in cybersecurity, IT, or regulatory roles across various industries.

What are the key skills and qualifications needed to thrive as a Cybersecurity Governance, Risk, and Compliance (CGRC) professional?

To thrive as a CGRC professional, you need a solid understanding of cybersecurity frameworks, risk management, and regulatory compliance, typically supported by a relevant degree and certifications such as CISSP, CISA, or CGRC (formerly CAP). Familiarity with GRC platforms like Archer, ServiceNow GRC, or RSA, as well as knowledge of NIST, ISO, or HIPAA standards, is commonly required. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for interpreting regulations and collaborating across teams. These competencies ensure organizations remain secure and compliant, minimizing risk and avoiding costly penalties.

What are some common challenges CGRC professionals face when managing compliance across multiple frameworks?

CGRC (Cybersecurity Governance, Risk, and Compliance) professionals often encounter the challenge of aligning organizational policies with the requirements of various regulatory frameworks, such as NIST, ISO 27001, and GDPR. This can involve interpreting overlapping or conflicting controls and ensuring consistent documentation and reporting. Additionally, they must facilitate communication and collaboration between IT, legal, and business teams to ensure all stakeholders understand and meet compliance obligations. Keeping up with the evolving regulatory landscape and adapting internal processes accordingly is also a key aspect of the role.

What is the difference between Cgrc vs Compliance Analyst?

AspectCgrcCompliance Analyst
CertificationsCertifications like CFE, CISA, or CMMC often preferredCertifications such as CCEP, CISA, or CIA common
Work EnvironmentTypically in cybersecurity, risk management, or compliance teams within organizationsUsually in corporate compliance departments, auditing firms, or regulatory agencies
Industry UsageUsed in industries like finance, healthcare, and government for cybersecurity and risk managementCommon across various industries for regulatory compliance and risk assessment

The Cgrc (Certified Government Risk Compliance) focuses on government-specific regulations and cybersecurity risk management, while a Compliance Analyst generally handles broader regulatory compliance across industries. Both roles require understanding of compliance frameworks, but Cgrc emphasizes government standards and cybersecurity, making it more specialized in those areas.

What cities near Springfield, VA are hiring for Cgrc jobs?

Cities near Springfield, VA with the most Cgrc job openings:

Infographic showing various Cgrc job openings in Springfield, VA as of July 2026, with employment types broken down into 82% Full Time, 6% Part Time, and 12% Contract. Highlights an 89% Physical, 4% Hybrid, and 7% Remote job distribution.

Junior Security Control Assessor

System One

Bethesda, MD • Remote

$100K - $115K/yr

Other

Medical, Dental, Vision, Life, Retirement

Posted 23 days ago


Job description

Location: Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation: $100,000–$115,000/year Target start: by end of August 2026 Clearance / Public Trust: Public Trust eligibility (Tier 2/3) required

About the role

We’re hiring a Junior Security Control Assessor to support independent security control assessments across the system authorization lifecycle. You’ll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800-53 Rev. 5, using JCAM practices.

This is a great fit for someone who enjoys cybersecurity compliance, evidence-based assessments, and strong technical writing—without being the person who authors the entire authorization package.

What you’ll do

  • Support independent Security Control Assessments (SCAs) across the authorization lifecycle
  • Review and validate security authorization documentation (SSP, SAP, SAR, POA&M, contingency plans, and supporting artifacts)
  • Assess security control implementation through documentation review, interviews, and technical validation
  • Help evaluate cloud security packages and inherited controls (as applicable)
  • Document findings, recommendations, and remediation activities clearly and professionally
  • Assist with evidence validation and remediation tracking
  • Partner with system owners and ISSOs while maintaining assessor independence

Required qualifications

  • Education: Bachelor’s in Cybersecurity, IT, Computer Science, Information Systems (or similar)
    • OR 4 additional years of relevant experience in lieu of a degree
  • Experience: 3–5 years supporting cybersecurity, information assurance, RMF, security assessments, compliance, or IT operations
  • Working knowledge of:
    • NIST RMF (800-37) and NIST SP 800-53 Rev. 5
    • JCAM methodology
  • Experience reviewing security documentation and assessment evidence/artifacts
  • Strong analytical skills and technical writing ability

Preferred (nice to have)

  • Experience with eMASS or similar GRC platforms
  • Familiarity with FedRAMP, cloud security concepts, C-SCRM, and related federal security frameworks
  • Experience supporting independent audits/assessments (e.g., external review organizations)

Tools/tech exposure (helpful)

  • JCAM
  • Tenable
  • CrowdStrike
  • Splunk / Splunk Enterprise
  • AWS
  • Python (plus)

Certifications (preferred, not all required)

  • ISC2 CC or CGRC
  • CompTIA Security+, CySA+, PenTest+, CASP+
  • CEH
  • Microsoft SC-900

  • System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.

    System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.

    #M-1 #LI-AJ1 Ref: #856-Baltimore-S1