1

Cgrc Jobs in Springfield, VA (NOW HIRING)

RMF and Authorization Lead

Bethesda, MD · Hybrid

$165K - $185K/yr

CISSP, CAP/CGRC, CISM, Security+, or an applicable cloud security certification. Compensation Salary Range: $165,000 - $185,000 annually (commensurate with experience) Benefits: Health, dental, and ...

ISC2 CC or CGRC * CompTIA Security+, CySA+, PenTest+, CASP+ * CEH * Microsoft SC-900 * System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced ...

ISC2 CC or CGRC * CompTIA Security+, CySA+, PenTest+, CASP+ * CEH * Microsoft SC-900 * System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced ...

ISC2 CC or CGRC * CompTIA Security+, CySA+, PenTest+, CASP+ * CEH * Microsoft SC-900 * System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced ...

ISC2 CC or CGRC * CompTIA Security+, CySA+, PenTest+, CASP+ * CEH * Microsoft SC-900 * System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced ...

CAP/CGRC * CISSP * CISM * Knowledge, Skills, and Abilities Strong analytical, organizational, and communication skills with knowledge of RMF processes, documentation, and federal cybersecurity ...

ISC2 CC or CGRC * CompTIA Security+, CySA+, PenTest+, CASP+ * CEH * Microsoft SC-900 * System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced ...

CAP/CGRC * CISSP * CISM * Knowledge, Skills, and Abilities Strong analytical, organizational, and communication skills with knowledge of RMF processes, documentation, and federal cybersecurity ...

Showing results 41-60

Cgrc information

What is a CGRC professional?

CGRC professionals, or Certified in Governance, Risk and Compliance, are experts who help organizations manage risk, ensure regulatory compliance, and establish effective governance frameworks. They analyze processes, identify potential risks, and develop policies to maintain compliance with laws and industry standards. CGRC certification, previously known as CAP (Certified Authorization Professional), is offered by (ISC)² and validates knowledge in governance, risk management, and compliance best practices. These professionals often work in cybersecurity, IT, or regulatory roles across various industries.

What are the key skills and qualifications needed to thrive as a Cybersecurity Governance, Risk, and Compliance (CGRC) professional?

To thrive as a CGRC professional, you need a solid understanding of cybersecurity frameworks, risk management, and regulatory compliance, typically supported by a relevant degree and certifications such as CISSP, CISA, or CGRC (formerly CAP). Familiarity with GRC platforms like Archer, ServiceNow GRC, or RSA, as well as knowledge of NIST, ISO, or HIPAA standards, is commonly required. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for interpreting regulations and collaborating across teams. These competencies ensure organizations remain secure and compliant, minimizing risk and avoiding costly penalties.

What are some common challenges CGRC professionals face when managing compliance across multiple frameworks?

CGRC (Cybersecurity Governance, Risk, and Compliance) professionals often encounter the challenge of aligning organizational policies with the requirements of various regulatory frameworks, such as NIST, ISO 27001, and GDPR. This can involve interpreting overlapping or conflicting controls and ensuring consistent documentation and reporting. Additionally, they must facilitate communication and collaboration between IT, legal, and business teams to ensure all stakeholders understand and meet compliance obligations. Keeping up with the evolving regulatory landscape and adapting internal processes accordingly is also a key aspect of the role.

What is the difference between Cgrc vs Compliance Analyst?

AspectCgrcCompliance Analyst
CertificationsCertifications like CFE, CISA, or CMMC often preferredCertifications such as CCEP, CISA, or CIA common
Work EnvironmentTypically in cybersecurity, risk management, or compliance teams within organizationsUsually in corporate compliance departments, auditing firms, or regulatory agencies
Industry UsageUsed in industries like finance, healthcare, and government for cybersecurity and risk managementCommon across various industries for regulatory compliance and risk assessment

The Cgrc (Certified Government Risk Compliance) focuses on government-specific regulations and cybersecurity risk management, while a Compliance Analyst generally handles broader regulatory compliance across industries. Both roles require understanding of compliance frameworks, but Cgrc emphasizes government standards and cybersecurity, making it more specialized in those areas.

What are popular job titles related to Cgrc jobs in Springfield, VA?

For Cgrc jobs in Springfield, VA, the most frequently searched job titles are:

What cities near Springfield, VA are hiring for Cgrc jobs?

Cities near Springfield, VA with the most Cgrc job openings:

Infographic showing various Cgrc job openings in Springfield, VA as of July 2026, with employment types broken down into 82% Full Time, 6% Part Time, and 12% Contract. Highlights an 89% Physical, 4% Hybrid, and 7% Remote job distribution.

Security Controls Assessor

Tyger Solutions Corporation

Washington, DC • On-site

Other

This job post has expired today. Applications are no longer accepted.


Job description

Security Controls Assessor (SCA)


Location: Hybrid (Washington, DC)

Employment Type: Full-time


Company Description

Tyger Solutions Corporation (TSC) is an Information Technology (IT) consulting firm specializing in Information Security, custom technology designs, systems integration, and systems architecture. TSC provides expertise for IT projects of all sizes and complexity and the ability to lead from project initiation through completion. Our services are aimed at protecting the confidentiality, integrity, availability, and ensuring accountability for our clients' data and assets.


Role Description

This is a full-time hybrid role for a Security Controls Assessor (SCA). The SCA will independently assess the security and privacy controls of federal information systems under the NIST Risk Management Framework (RMF), determine whether controls are implemented correctly, operating as intended, and producing the desired outcome, and document results that support risk-based authorization decisions. The role works closely with system owners, ISSOs, ISSMs, engineers, and Authorizing Officials across the assessment and authorization (A&A) lifecycle.


Responsibilities

- Develop Security Assessment Plans (SAPs) that define assessment scope, control selection, methods (examine, interview, test), and evidence requirements in accordance with NIST SP 800-53A

- Assess NIST SP 800-53 security and privacy controls by reviewing System Security Plans (SSPs), policies, procedures, configuration baselines, and supporting artifacts

- Validate technical evidence

- Interview system owners, ISSOs, administrators, and developers to confirm control implementation

- Document findings, risk ratings, and recommended remediation in Security Assessment Reports (SARs)

- Review Plans of Action and Milestones (POA&Ms) and validate remediation evidence for closure

- Support initial authorizations, annual assessments, significant-change assessments, and continuous monitoring activities

- Maintain assessment records in GRC platforms (e.g., eMASS, CSAM, Xacta, or similar)

- Brief assessment results to system stakeholders and Authorizing Officials


Qualifications

- 2+ years of technical experience in cybersecurity, including hands-on experience performing security control assessments for federal information systems

- Working knowledge of the NIST RMF (SP 800-37), SP 800-53/53A, FIPS 199/200, SP 800-30, and FISMA/OMB requirements

- Experience developing SAPs and SARs and reviewing SSPs and POA&Ms

- Experience interpreting vulnerability scan results

- Experience assessing controls in one or more GRC platforms (eMASS, CSAM, Xacta, or similar)

- Ability to write clear, well-supported findings and defend them with stakeholders

- Excellent written and verbal communication skills

- Ability to work independently and remotely


Preferred Qualifications

- CISSP, CISA, CGRC (formerly CAP), or Security+ (DoD 8140 compliant)

- Experience assessing cloud-hosted systems (AWS GovCloud, Azure Government) or FedRAMP-authorized services

- Experience with NIST SP 800-171

- Experience applying privacy controls and control overlays


Requirements

U.S. citizenship and T3 clearance are required.