1

Cgrc Jobs (NOW HIRING)

$110 - $160/hr

SecurityX / CASP+ CISM CCISO CISSO CCSP CISSP CGRC/CAP CISSP-ISSMP Cloud+ FITSP-M GSEC GCIA Security+ GCIH SSCP GCSA GICSP GSLC Additional Information: This position will require security clearance ...

Showing results 41-60

Cgrc information

What is a CGRC professional?

CGRC professionals, or Certified in Governance, Risk and Compliance, are experts who help organizations manage risk, ensure regulatory compliance, and establish effective governance frameworks. They analyze processes, identify potential risks, and develop policies to maintain compliance with laws and industry standards. CGRC certification, previously known as CAP (Certified Authorization Professional), is offered by (ISC)² and validates knowledge in governance, risk management, and compliance best practices. These professionals often work in cybersecurity, IT, or regulatory roles across various industries.

What are the key skills and qualifications needed to thrive as a Cybersecurity Governance, Risk, and Compliance (CGRC) professional?

To thrive as a CGRC professional, you need a solid understanding of cybersecurity frameworks, risk management, and regulatory compliance, typically supported by a relevant degree and certifications such as CISSP, CISA, or CGRC (formerly CAP). Familiarity with GRC platforms like Archer, ServiceNow GRC, or RSA, as well as knowledge of NIST, ISO, or HIPAA standards, is commonly required. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for interpreting regulations and collaborating across teams. These competencies ensure organizations remain secure and compliant, minimizing risk and avoiding costly penalties.

What are some common challenges CGRC professionals face when managing compliance across multiple frameworks?

CGRC (Cybersecurity Governance, Risk, and Compliance) professionals often encounter the challenge of aligning organizational policies with the requirements of various regulatory frameworks, such as NIST, ISO 27001, and GDPR. This can involve interpreting overlapping or conflicting controls and ensuring consistent documentation and reporting. Additionally, they must facilitate communication and collaboration between IT, legal, and business teams to ensure all stakeholders understand and meet compliance obligations. Keeping up with the evolving regulatory landscape and adapting internal processes accordingly is also a key aspect of the role.

What is the difference between Cgrc vs Compliance Analyst?

AspectCgrcCompliance Analyst
CertificationsCertifications like CFE, CISA, or CMMC often preferredCertifications such as CCEP, CISA, or CIA common
Work EnvironmentTypically in cybersecurity, risk management, or compliance teams within organizationsUsually in corporate compliance departments, auditing firms, or regulatory agencies
Industry UsageUsed in industries like finance, healthcare, and government for cybersecurity and risk managementCommon across various industries for regulatory compliance and risk assessment

The Cgrc (Certified Government Risk Compliance) focuses on government-specific regulations and cybersecurity risk management, while a Compliance Analyst generally handles broader regulatory compliance across industries. Both roles require understanding of compliance frameworks, but Cgrc emphasizes government standards and cybersecurity, making it more specialized in those areas.

More about Cgrc jobs

What cities are hiring for Cgrc jobs?

Cities with the most Cgrc job openings:

What states have the most Cgrc jobs?

States with the most job openings for Cgrc jobs include:

Infographic showing various Cgrc job openings in the United States as of August 2026, with employment types broken down into 90% Full Time, 6% Part Time, and 4% Contract. Highlights an 76% Physical, 5% Hybrid, and 19% Remote job distribution.

Information System Security Manager with Security Clearance

Insight Global, Inc.

Bedford, MA • On-site

Contractor

Posted 26 days ago


Job description

Required Skills & Experience:
10 years of experience performing ISSM or senior ISSO functions supporting DoD or Air Force systems
Bachelor's degree or equivalent experience
Strong hands‑on experience with Risk Management Framework (RMF) and A&A activities
Experience conducting security risk, vulnerability, and security impact assessments
Experience maintaining RMF artifacts (SSP, POA&Ms, SARs, control documentation)
Ability to assess and document security impacts of system changes and configuration updates
Experience supporting continuous monitoring, audits, and compliance reviews
Strong written and verbal communication skills for technical documentation and leadership briefings
Knowledge of cybersecurity policies, NIST publications, and cryptographic fundamentals
Certification: CISSP, CISM, or CGRC (DoDI 8140‑approved, Basic or Intermediate) Nice to Have Skills & Experience:
Experience supporting cyber inspections, penetration tests, or external assessments
Experience with Air Force cybersecurity tools and systems (e.g., eMASS, ACAS, STIGs)
Experience participating in CCBs, working groups, and system design reviews
Experience supporting mission‑critical or classified environments (e.g., NC3 or weapons systems)
Prior experience serving as a cybersecurity subject‑matter expert to program leadership Job Description:
The Information System Security Manager (ISSM) is responsible for ensuring systems and applications comply with National, DoD, and Department of the Air Force cybersecurity requirements. This role leads Risk Management Framework (RMF) activities, assesses security risks and vulnerabilities, evaluates the security impact of system changes, and ensures the confidentiality, integrity, and availability of information systems throughout the system lifecycle. The ISSM works closely with technical teams and leadership to maintain authorization, support continuous monitoring, and uphold system cybersecurity posture.