1

Contract Grc Analyst Jobs in Silver Spring, MD (NOW HIRING)

JUNIOR GRC ANALYST ROCKVILLE, MD - HYBRID LONG TERM CONTRACT SEEKING SOMEONE WHO HAS WORKED WITH THE SERVICENOW GRC APPLICATION Overview: * The GRC Analyst supports the administration of Information ...

JUNIOR GRC ANALYST ROCKVILLE, MD - HYBRID LONG TERM CONTRACT SEEKING SOMEONE WHO HAS WORKED WITH THE SERVICENOW GRC APPLICATION Overview: * The GRC Analyst supports the administration of Information ...

Business Analyst

Merrifield, VA · On-site

$47 - $58/hr

Initial 6 Month Contract With Extensions Compensation: $47-58/HR W2 Work Requirements: US Citizen ... Analyze risk data from ServiceNow, SharePoint, SQL Server, GRC platforms, and audit/issue ...

NIST 800-53, RMF, FedRAMP, ICD 503, ServiceNow GRC, Splunk, Azure Sentinel, Nessus, ACAS, AWS ... contract. Core One is an Equal Opportunity Employer. All qualified applicants will receive ...

Security Analyst

Mclean, VA · On-site

$150K - $200K/yr

NIST 800-53, RMF, FedRAMP, ICD 503, ServiceNow GRC, Splunk, Azure Sentinel, Nessus, ACAS, AWS ... contract. Core One is an Equal Opportunity Employer. All qualified applicants will receive ...

next page

Showing results 1-20

Contract Grc Analyst information

See Silver Spring, MD salary details

$37.7K

$101K

$236.2K

How much do contract grc analyst jobs pay per year?

As of Aug 11, 2026, the average yearly pay for contract grc analyst in Silver Spring, MD is $100,958.00, according to ZipRecruiter salary data. Most workers in this role earn between $56,900.00 and $114,700.00 per year, depending on experience, location, and employer.

What is a contract GRC analyst?

A Contract GRC (Governance, Risk, and Compliance) Analyst is a professional who specializes in evaluating, managing, and ensuring compliance with contractual obligations within an organization. They focus on identifying risks, implementing controls, and maintaining adherence to regulatory standards related to contracts. Their work helps organizations avoid legal issues, reduce risk exposure, and maintain good governance practices. Contract GRC Analysts often collaborate with legal, procurement, and compliance teams to ensure contracts meet all internal and external requirements.

What is the difference between Contract Grc Analyst vs Contract Risk Analyst?

AspectContract Grc AnalystContract Risk Analyst
Required CertificationsGRC certifications, such as CISA or CRISCRisk management certifications, like FRM or CRM
Work EnvironmentCorporate compliance, audit, and governance teamsRisk assessment, mitigation, and analysis teams
Employer & Industry UsageFinancial services, healthcare, and tech companiesFinancial institutions, consulting firms, and corporations

Contract Grc Analysts focus on governance, risk, and compliance frameworks within organizations, ensuring adherence to policies and regulations. Contract Risk Analysts primarily evaluate and mitigate potential risks affecting business operations. While both roles involve risk assessment, GRC Analysts emphasize compliance and governance, whereas Risk Analysts concentrate on identifying and managing specific risks. Both roles often require similar certifications and are used across industries like finance and healthcare.

What are some common challenges faced by contract GRC analysts when managing third-party risk assessments?

Contract GRC Analysts often encounter challenges such as incomplete or inconsistent documentation from vendors, varying compliance standards, and tight deadlines for contract reviews. Collaborating with cross-functional teams—including legal, procurement, and IT security—can also require strong communication skills to ensure all risk factors are addressed. Staying updated on regulatory requirements and adapting assessment frameworks accordingly is essential for success in this dynamic role.

What are the key skills and qualifications needed to thrive as a contract GRC analyst?

To thrive as a Contract GRC Analyst, you need expertise in governance, risk management, and compliance processes, often supported by a bachelor's degree in a related field and experience with contract review. Familiarity with GRC tools like RSA Archer, compliance management systems, and certifications such as CISA or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you interpret complex regulations and collaborate with cross-functional teams. These skills and qualifications ensure robust risk mitigation, regulatory adherence, and efficient contract management within organizations.
What are the most commonly searched types of Grc Analyst jobs in Silver Spring, MD? The most popular types of Grc Analyst jobs in Silver Spring, MD are:
What are popular job titles related to Contract Grc Analyst jobs in Silver Spring, MD? For Contract Grc Analyst jobs in Silver Spring, MD, the most frequently searched job titles are:
What job categories do people searching Contract Grc Analyst jobs in Silver Spring, MD look for? The top searched job categories for Contract Grc Analyst jobs in Silver Spring, MD are:
What cities near Silver Spring, MD are hiring for Contract Grc Analyst jobs? Cities near Silver Spring, MD with the most Contract Grc Analyst job openings:
Infographic showing various Contract Grc Analyst job openings in Silver Spring, MD as of August 2026, with employment types broken down into 59% Full Time, and 41% Contract. Highlights an 83% In-person, and 17% Remote job distribution, with an average salary of $100,958 per year, or $48.5 per hour.

Jr. GRC Analyst

System One

Rockville, MD • On-site

Contractor

Posted 13 days ago


Job description

JUNIOR GRC ANALYST ROCKVILLE, MD - HYBRID LONG TERM CONTRACT SEEKING SOMEONE WHO HAS WORKED WITH THE SERVICENOW GRC APPLICATION Overview:
  • The GRC Analyst supports the administration of Information Security Governance, Risk, and Compliance programs, including policy exception management and enterprise risk register activities using ServiceNow Integrated Risk Management (IRM).
Working under the guidance of Information Security leadership, the analyst will apply established risk assessment methodologies, workflows, and reporting processes to support enterprise cybersecurity governance and risk management initiatives. This role provides hands-on experience in information security governance, risk analysis, policy exception management, enterprise risk management, and ServiceNow IRM. Key Responsibilities: Policy Exception Management
  • Review policy exception requests for completeness and required documentation.
  • Validate business justifications and request additional information as needed.
  • Maintain exception records and track approvals in ServiceNow.
  • Monitor expiration dates, coordinate renewals, and produce status reports.
Risk Analysis
  • Conduct risk evaluations using established methodologies and templates.
  • Assess business impact, likelihood, and overall risk.
  • Identify compensating controls and document risk analyses.
  • Prepare risk-based recommendations for management review.
  • Maintain analysis records in ServiceNow.
Enterprise Risk Register Administration
  • Create, update, and maintain risk records.
  • Track risks identified through assessments, penetration tests, vulnerability scans, security incidents, and other approved sources.
  • Monitor mitigation activities, due dates, and risk status.
  • Maintain supporting documentation and generate reports.
ServiceNow IRM Administration
  • Process policy exceptions.
  • Maintain risk register records.
  • Track approvals and workflows.
  • Generate reports and dashboards.
Stakeholder Support
  • Communicate with IT staff, business stakeholders, system owners, managers, and security teams.
  • Provide professional customer service and clear written and verbal communication.
Education
  • Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, Business Information Systems, or a related field.
Preferred Certifications - at least one
  • CompTIA Security+
  • ISACA IT Risk Fundamentals
  • NIST Cybersecurity Framework (NCSF) Practitioner
  • CISM Fundamentals
  • Cybersecurity, audit, or compliance-related certifications
Experience: Required
  • One (1) year of experience in Information Security, IT Governance, Risk Management, Compliance, Audit, Information Technology, or a related field; or
  • Recent graduate with relevant internship or equivalent experience.
Preferred
  • ServiceNow experience
  • Microsoft 365 proficiency
  • GRC program experience
  • Technical documentation experience
  • Customer service and project coordination experience
Knowledge & Skills:
  • Basic understanding of cybersecurity, risk management, information security, NIST Cybersecurity Framework, and compliance concepts.
  • Strong analytical, organizational, and critical-thinking skills.
  • Excellent written and verbal communication skills.
  • Attention to detail and ability to manage multiple priorities.
  • Ability to work independently and learn new technologies quickly.
Deliverables:
  • Policy exception reviews and tracking records
  • Risk analyses and recommendations
  • Risk register entries and updates
  • Monthly metrics and quarterly reports
  • Executive dashboards
  • ServiceNow documentation and reporting artifacts
#M1 #LI-CB3 Ref: #851-Rockville-S1