Cyber GRC Specialist
Baltimore, MD · On-site
Brown Advisory is currently seeking a Cyber GRC Specialist to support and mature the firm's governance, risk, compliance, and control-management routines. This blended role is designed for someone ...
Baltimore, MD · On-site
Brown Advisory is currently seeking a Cyber GRC Specialist to support and mature the firm's governance, risk, compliance, and control-management routines. This blended role is designed for someone ...
Baltimore, MD · On-site
Brown Advisory is currently seeking a Cyber GRC Specialist to support and mature the firm's governance, risk, compliance, and control-management routines. This blended role is designed for someone ...
Baltimore, MD · On-site
Brown Advisory is currently seeking a Cyber GRC Specialist to support and mature the firm's governance, risk, compliance, and control-management routines. This blended role is designed for someone ...
Baltimore, MD · On-site
Brown Advisory is currently seeking a Cyber GRC Specialist to support and mature the firm's governance, risk, compliance, and control-management routines. This blended role is designed for someone ...
Baltimore, MD · On-site
Cyber GRC support for policies, controls, cyber risk tracking, audit coordination, exceptions, and ... Serve as a key administrator and process contributor for ISO and security-risk management platforms ...
Baltimore, MD · On-site
Cyber GRC support for policies, controls, cyber risk tracking, audit coordination, exceptions, and ... Serve as a key administrator and process contributor for ISO and security-risk management platforms ...
Through solutions and managed services that simplify complexity, we help clients operate with resilience, grow with confidence, and proactively manage cyber, risk, and technology programs. Recruiting ...
Through solutions and managed services that simplify complexity, we help clients operate with resilience, grow with confidence, and proactively manage cyber, risk, and technology programs. Recruiting ...
Through solutions and managed services that simplify complexity, we help clients operate with resilience, grow with confidence, and proactively manage cyber, risk, and technology programs. Recruiting ...
Through solutions and managed services that simplify complexity, we help clients operate with resilience, grow with confidence, and proactively manage cyber, risk, and technology programs. Recruiting ...
... cyber strategy and governance, technology risk, IT audit, regulatory compliance, privacy, data protection, third-party risk management, cloud security, incident readiness, and managed risk services.
... cyber strategy and governance, technology risk, IT audit, regulatory compliance, privacy, data protection, third-party risk management, cloud security, incident readiness, and managed risk services.
Baltimore, MD · On-site
$95K - $170K/yr
... management, cyber threat intelligence, network security, IAM, change management, and other related areas. The ideal candidate will bring operational knowledge and experience paired with a strong risk ...
Baltimore, MD · On-site
$95K - $170K/yr
... management, cyber threat intelligence, network security, IAM, change management, and other related areas. The ideal candidate will bring operational knowledge and experience paired with a strong risk ...
Baltimore, MD · On-site
$95K - $170K/yr
... management, cyber threat intelligence, network security, IAM, change management, and other related areas. The ideal candidate will bring operational knowledge and experience paired with a strong risk ...
Baltimore, MD · On-site
$95K - $170K/yr
... management, cyber threat intelligence, network security, IAM, change management, and other related areas. The ideal candidate will bring operational knowledge and experience paired with a strong risk ...
Baltimore, MD · On-site
$95K - $170K/yr
... management, cyber threat intelligence, network security, IAM, change management, and other related areas. The ideal candidate will bring operational knowledge and experience paired with a strong risk ...
Baltimore, MD · On-site
$95K - $170K/yr
... management, cyber threat intelligence, network security, IAM, change management, and other related areas. The ideal candidate will bring operational knowledge and experience paired with a strong risk ...
Baltimore, MD · On-site
$95K - $170K/yr
... management, cyber threat intelligence, network security, IAM, change management, and other related areas. The ideal candidate will bring operational knowledge and experience paired with a strong risk ...
Baltimore, MD · On-site
$95K - $170K/yr
... management, cyber threat intelligence, network security, IAM, change management, and other related areas. The ideal candidate will bring operational knowledge and experience paired with a strong risk ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Contribute to the ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Contribute to the ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...
Lead and mentor global teams to ensure high-quality delivery of ServiceNow cyber risk management services. The team Our Cyber Strategy & Transformation offering develops and transforms cyber programs ...
Lead and mentor global teams to ensure high-quality delivery of ServiceNow cyber risk management services. The team Our Cyber Strategy & Transformation offering develops and transforms cyber programs ...
Sets and executes the enterprise information security strategy for DLA Piper, aligning cyber risk management with firm strategy, client obligations, professional responsibility requirements ...
Sets and executes the enterprise information security strategy for DLA Piper, aligning cyber risk management with firm strategy, client obligations, professional responsibility requirements ...
Baltimore, MD · On-site
$64.50 - $82.25/hr
Ability to mentor and provide clear guidance to others The team Deloitte's Cloud Cyber Risk team helps organizations pursue growth, innovation, and performance through proactive management of cyber ...
Baltimore, MD · On-site
$64.50 - $82.25/hr
Ability to mentor and provide clear guidance to others The team Deloitte's Cloud Cyber Risk team helps organizations pursue growth, innovation, and performance through proactive management of cyber ...
$64.50 - $82.25/hr
Ability to mentor and provide clear guidance to others The team Deloitte's Cloud Cyber Risk team helps organizations pursue growth, innovation, and performance through proactive management of cyber ...
$64.50 - $82.25/hr
Ability to mentor and provide clear guidance to others The team Deloitte's Cloud Cyber Risk team helps organizations pursue growth, innovation, and performance through proactive management of cyber ...
This role offers the opportunity to lead portions of client engagements, deliver cloud security solutions, and help organizations manage cyber risk while enabling innovation. Recruiting for this role ...
This role offers the opportunity to lead portions of client engagements, deliver cloud security solutions, and help organizations manage cyber risk while enabling innovation. Recruiting for this role ...
... management. * Experience supporting governance, risk, and compliance workflows, including risk reporting, audit data requests, controls monitoring, controls testing, compliance metrics, governance ...
... management. * Experience supporting governance, risk, and compliance workflows, including risk reporting, audit data requests, controls monitoring, controls testing, compliance metrics, governance ...
Baltimore, MD · On-site
Reporting directly to the Chief Information Officer, the Deputy CISO will be responsible for all cybersecurity operations, cyber risk management, security architecture, incident response, governance ...
Baltimore, MD · On-site
Reporting directly to the Chief Information Officer, the Deputy CISO will be responsible for all cybersecurity operations, cyber risk management, security architecture, incident response, governance ...
Our Cyber Risk practice helps organizations with the management of information and technology risks by delivering end-to-end solutions using proven methodologies and tools in a consistent manner. Our ...
Our Cyber Risk practice helps organizations with the management of information and technology risks by delivering end-to-end solutions using proven methodologies and tools in a consistent manner. Our ...
Baltimore, MD · On-site
$64.50 - $82.25/hr
This role offers the opportunity to lead portions of client engagements, deliver cloud security capabilities, and help organizations manage cyber risk while enabling innovation. Recruiting for this ...
Baltimore, MD · On-site
$64.50 - $82.25/hr
This role offers the opportunity to lead portions of client engagements, deliver cloud security capabilities, and help organizations manage cyber risk while enabling innovation. Recruiting for this ...
$18.72 is the 25th percentile. Wages below this are outliers.
$14 - $19.26
28% of jobs
The median wage is $22.40 / hr.
$19.26 - $24.52
37% of jobs
$24.52 - $29.78
6% of jobs
$33.07 is the 75th percentile. Wages above this are outliers.
$29.78 - $35.04
6% of jobs
$35.04 - $40.30
12% of jobs
$40.30 - $45.56
0% of jobs
$45.56 - $50.82
0% of jobs
$50.82 - $56.08
8% of jobs
$56.08 - $61.34
0% of jobs
$61.34 - $66.60
0% of jobs
$66.60 - $71.86
2% of jobs
$13
$29
$71
A Cyber Risk Management job involves identifying, assessing, and mitigating cybersecurity risks that could impact an organization. Professionals in this field develop risk management frameworks, implement security controls, and ensure compliance with industry regulations. They work closely with IT and business teams to minimize cyber threats, such as data breaches and ransomware attacks. Their goal is to protect sensitive information and maintain business continuity.
Professionals in Cyber Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, ensuring compliance with complex regulations, and balancing security needs with business objectives. Addressing these issues requires continuous learning, leveraging up-to-date threat intelligence, and collaborating closely with IT, legal, and management teams to develop effective risk mitigation strategies. Many organizations encourage ongoing training and participation in industry events to stay current, while fostering a culture of open communication to quickly identify and address vulnerabilities. Embracing a proactive and adaptable approach ensures that cyber risks are managed effectively while supporting the organization’s goals.
To thrive in Cyber Risk Management, you need a strong understanding of information security principles, risk assessment methodologies, and regulatory compliance, often supported by a degree in cybersecurity, information technology, or a related field. Familiarity with tools such as risk management software, vulnerability assessment platforms, and certifications like CISSP, CISM, or CRISC is highly valued. Excellent analytical thinking, communication, and problem-solving skills help professionals effectively advise stakeholders and coordinate incident response efforts. These skills are crucial for identifying, evaluating, and mitigating cyber risks to safeguard organizational assets and ensure business continuity.
For Cyber Risk Management jobs in Maryland, the most frequently searched job titles are:
The top searched job categories for Cyber Risk Management jobs in Maryland are:
Cities in Maryland with the most Cyber Risk Management job openings:

Baltimore, MD • On-site
Full-time
Medical, Dental, Vision, Life, Retirement
Re-posted 6 days ago
Support and mature core cyber governance routines, including policy management, control ownership, risk acceptance, exception handling, standards maintenance, and periodic leadership reporting.
Maintain the cyber risk register and partner with technology and business owners to document risk decisions, remediation plans, due dates, dependencies, and residual risk.
Coordinate vulnerability management governance, including scan-result intake, prioritization routines, remediation tracking, exception handling, and reporting.
Company Overview
Every firm has a culture - the values, beliefs, methodology, attitudes and standards that reflect an organization's DNA. But the truly inspiring firms - the game-changers, the industry leaders and the disruptors - have cultures that propel them to innovate and stand out. At Brown Advisory, we aim to be one of those inspired firms. Over the years, we have purposefully built and nurtured our client-first culture.
Brown Advisory is an independent investment management and strategic advisory firm committed to delivering a combination of first-class performance, strategic advice and the highest level of client service. The firm's clients-including individuals, families, family offices, endowments, foundations, charities, institutions, consultants, and financial intermediaries-are served by over 1,000 colleagues worldwide, all of whom are equity owners of the firm.
Brown Advisory is currently seeking a Cyber GRC Specialist to support and mature the firm's governance, risk, compliance, and control-management routines. This blended role is designed for someone who can translate security requirements into practical business processes, drive evidence and accountability, and communicate clearly with technical and non-technical stakeholders.
As part of a lean Information Security team within a mid-sized financial services organization, this individual will serve as a central coordinator for cyber risk, policy management, control testing, audit readiness, client and regulatory response support, and vulnerability remediation governance. The role is not intended to be a hands-on vulnerability engineering role; rather, it ensures the process, ownership, exceptions, reporting, and governance routines are working.
Blended Role CoveragePrimary emphasis: Cyber GRC support for policies, controls, cyber risk tracking, audit coordination, exceptions, and governance routines.
Blended coverage: Cyber Risk / Compliance Analyst work, ISO and risk-platform support, evidence coordination, client/regulatory response support, communications, and vulnerability governance.
Duties and Responsibilities
Support and mature core cyber governance routines, including policy management, control ownership, risk acceptance, exception handling, standards maintenance, and periodic leadership reporting.
Maintain the cyber risk register and partner with technology and business owners to document risk decisions, remediation plans, due dates, dependencies, and residual risk.
Serve as a key administrator and process contributor for ISO and security-risk management platforms such as Vanta or similar tools.
Coordinate evidence collection, control testing, audit requests, client due diligence responses, regulatory requests, and recurring compliance deliverables.
Translate ISO 27001, regulatory, client, and internal security expectations into practical controls and operating procedures appropriate for Brown Advisory's size and risk profile.
Facilitate cross-functional communications for security change, SaaS inventory, policy enforcement, control adoption, and risk remediation.
Coordinate vulnerability management governance, including scan-result intake, prioritization routines, remediation tracking, exception handling, and reporting.
Partner with security engineers, infrastructure teams, application owners, Compliance, Legal, Operations, and Client Service to close control gaps in a business-aligned manner.
Develop clear metrics for control effectiveness, audit readiness, exceptions, overdue remediation, and recurring governance activities.
Identify process improvements that make security governance more repeatable, transparent, and useful without creating unnecessary bureaucracy.
Preferred Qualifications
Bachelor's degree in cyber security, information systems, risk management, business, or a relevant field preferred; equivalent professional experience will be considered.
3-6 years of experience in cyber GRC, information security, technology risk, IT audit, compliance, or related control-management work preferred.
Working knowledge of ISO 27001, SOC 2, NIST CSF, CIS Controls, SEC/FINRA expectations, privacy requirements, or comparable control frameworks.
Experience supporting audits, evidence collection, control testing, policy updates, issue tracking, or risk-register maintenance in a regulated environment; financial services experience preferred.
CISA, CRISC, CISM, Security+, ISO 27001 Foundation/Lead Implementer, or similar professional designation preferred but not required.
Technical Skills
Cyber risk registers, exception management, control testing, evidence management, policy lifecycle management, and audit coordination.
GRC or trust-management platforms such as Vanta, Archer, ServiceNow GRC, OneTrust, Drata, or similar tools.
Vulnerability management governance, including prioritization, remediation tracking, aging analysis, exception workflows, and executive reporting.
Strong knowledge of cyber security controls across identity, endpoint, cloud, network, data protection, application security, and third-party risk.
Excellent writing, facilitation, and stakeholder-management skills, including the ability to turn technical risk into clear business language.
Practical judgment about when to enforce, when to escalate, and when to help the business find a workable control path.
Demonstrates curiosity and a continuous improvement mindset by identifying opportunities to enhance processes, improve efficiency, and thoughtfully leverage new technologies and tools, including AI-enabled productivity solutions
Personal Attributes
Take ownership and move initiatives forward without constant oversight.
Balance technical depth, process discipline, and sound business judgment.
Approach risk management pragmatically rather than theoretically.
Thrive in collaborative, high-accountability environments.
Communicate clearly with technical and non-technical colleagues.
Bring an entrepreneurial mindset to building and improving security capabilities.
Applicants must be authorized to work in the United States without the need for current or future employer-sponsored work authorization (e.g., H-1B , O-1, F-1 (OPT), TN, or any other non-immigrant visa classifications that require employer support or sponsorship).
MD Salary: $95-$115k. Commensurate with experience and location. Does not include bonus or long term incentive eligibility (if applicable).
DC Salary: $104.5K-$126.5K. Commensurate with experience and location. Does not include bonus or long-term incentive eligibility (if applicable).
Benefits
At Brown Advisory we offer a competitive compensation package, including full benefits.
Medical
Dental
Vision
Wellness program participation incentive
Financial wellness program
Fitness event fee reimbursement
Gym membership discounts
Colleague Assistance Program
Telemedicine Program (for those enrolled in Medical)
Adoption Benefits
Daycare late pick-up fee reimbursement
Basic Life & Accidental Death & Dismemberment Insurance
Voluntary Life & Accidental Death & Dismemberment Insurance
Short Term Disability
Paid parental leave
Group Long Term Disability
Pet Insurance
401(k) (50% employer match up to IRS limit, 4 year vesting)
Brown Advisory is an Equal Employment Opportunity Employer.
Sourced by ZipRecruiter
Finance and insurance
201 - 500 Employees
Baltimore, MD, US
1993