Candidates must have 5+ years of experience in cybersecurity, architecture, cloud security, GRC, RMF, ATO, or federal compliance. Experience with federal programs, NIST RMF/CSF, FISMA, FedRAMP ...
Candidates must have 5+ years of experience in cybersecurity, architecture, cloud security, GRC, RMF, ATO, or federal compliance. Experience with federal programs, NIST RMF/CSF, FISMA, FedRAMP ...
Candidates must have 5+ years of experience in cybersecurity, architecture, cloud security, GRC, RMF, ATO, or federal compliance. Experience with federal programs, NIST RMF/CSF, FISMA, FedRAMP ...
Quick apply
Candidates must have 5+ years of experience in cybersecurity, architecture, cloud security, GRC, RMF, ATO, or federal compliance. Experience with federal programs, NIST RMF/CSF, FISMA, FedRAMP ...
Cloud Cybersecurity Specialist - Senior
Herndon, VA · Remote
$80K - $130K/yr
POA&M management and structured GRC environment experience * AWS security tooling: Security Hub ... Bachelor's degree in Cybersecurity, Information Technology, or related field Required Minimum ...
Quick apply
Cloud Cybersecurity Specialist - Senior
Herndon, VA · Remote
$80K - $130K/yr
POA&M management and structured GRC environment experience * AWS security tooling: Security Hub ... Bachelor's degree in Cybersecurity, Information Technology, or related field Required Minimum ...
Cloud Cybersecurity Specialist - Senior
Herndon, VA · On-site +1
$80K - $130K/yr
POA&M management and structured GRC environment experience * AWS security tooling: Security Hub ... Bachelor's degree in Cybersecurity, Information Technology, or related field Required Minimum ...
Cloud Cybersecurity Specialist - Senior
Herndon, VA · On-site +1
$80K - $130K/yr
POA&M management and structured GRC environment experience * AWS security tooling: Security Hub ... Bachelor's degree in Cybersecurity, Information Technology, or related field Required Minimum ...
SAP Security and GRC Manager / Engineering Manager II Our Deloitte Cyber team helps organizations address cybersecurity challenges across complex technology environments. Join the team to deliver ...
SAP Security and GRC Manager / Engineering Manager II Our Deloitte Cyber team helps organizations address cybersecurity challenges across complex technology environments. Join the team to deliver ...
Lead Software Developer
Washington, DC · On-site
$130K - $164K/yr
... cybersecurity GRC tools Company : AnaVation is a trusted partner that delivers high-value, cost-effective solutions to solve our customers' most complex technical and analytical problems. Founded in ...
Lead Software Developer
Washington, DC · On-site
$130K - $164K/yr
... cybersecurity GRC tools Company : AnaVation is a trusted partner that delivers high-value, cost-effective solutions to solve our customers' most complex technical and analytical problems. Founded in ...
Compliance Analyst (GRC/RMF Focused)
Washington, DC · On-site
$125K - $165K/yr
Bachelor's degree in Cybersecurity, Information Technology, Information Systems, or a related field. * 3-6+ years of experience in GRC, RMF, or cybersecurity compliance roles within federal or ...
Quick apply
Compliance Analyst (GRC/RMF Focused)
Washington, DC · On-site
$125K - $165K/yr
Bachelor's degree in Cybersecurity, Information Technology, Information Systems, or a related field. * 3-6+ years of experience in GRC, RMF, or cybersecurity compliance roles within federal or ...
Compliance Analyst (GRC/RMF Focused)
Washington, DC · On-site
$125K - $165K/yr
Bachelor's degree in Cybersecurity, Information Technology, Information Systems, or a related field. * 3-6+ years of experience in GRC, RMF, or cybersecurity compliance roles within federal or ...
Quick apply
Compliance Analyst (GRC/RMF Focused)
Washington, DC · On-site
$125K - $165K/yr
Bachelor's degree in Cybersecurity, Information Technology, Information Systems, or a related field. * 3-6+ years of experience in GRC, RMF, or cybersecurity compliance roles within federal or ...
... GRC) platforms • Translate Executive Orders, federal cybersecurity policies, NIST guidance, and emerging security requirements into actionable architectures, standards, and implementation ...
... GRC) platforms • Translate Executive Orders, federal cybersecurity policies, NIST guidance, and emerging security requirements into actionable architectures, standards, and implementation ...
Enterprise Cybersecurity Federal Compliance ISSO
Mclean, VA · On-site +1
$99K - $225K/yr
The GRC team is responsible for assessing and managing compliance and regulatory requirements in partnership with key stakeholders. ECS is seeking a definitive Subject Matter Expert in Cybersecurity ...
Enterprise Cybersecurity Federal Compliance ISSO
Mclean, VA · On-site +1
$99K - $225K/yr
The GRC team is responsible for assessing and managing compliance and regulatory requirements in partnership with key stakeholders. ECS is seeking a definitive Subject Matter Expert in Cybersecurity ...
Lead Systems Architect
Washington, DC · On-site
... cybersecurity GRC tools is desired Company : AnaVation is a trusted partner that delivers high-value, cost-effective solutions to solve our customers' most complex technical and analytical problems.
Lead Systems Architect
Washington, DC · On-site
... cybersecurity GRC tools is desired Company : AnaVation is a trusted partner that delivers high-value, cost-effective solutions to solve our customers' most complex technical and analytical problems.
Enterprise Cybersecurity Federal Compliance ISSO
Mclean, VA · On-site
$99K - $225K/yr
The GRC team is responsible for assessing and managing compliance and regulatory requirements in partnership with key stakeholders. ECS is seeking a definitive Subject Matter Expert in Cybersecurity ...
Enterprise Cybersecurity Federal Compliance ISSO
Mclean, VA · On-site
$99K - $225K/yr
The GRC team is responsible for assessing and managing compliance and regulatory requirements in partnership with key stakeholders. ECS is seeking a definitive Subject Matter Expert in Cybersecurity ...
Enterprise Cybersecurity Federal Compliance ISSO
Mclean, VA · On-site
$99K - $225K/yr
Enterprise Cybersecurity (ECS) Governance, Risk and Compliance (GRC) play a pivotal role in ... The GRC team is responsible for assessing and managing compliance and regulatory requirements in ...
Enterprise Cybersecurity Federal Compliance ISSO
Mclean, VA · On-site
$99K - $225K/yr
Enterprise Cybersecurity (ECS) Governance, Risk and Compliance (GRC) play a pivotal role in ... The GRC team is responsible for assessing and managing compliance and regulatory requirements in ...
Experience with GRC platforms, ACAS, Nessus, SCAP, SonarQube, GitLab, Splunk, Tanium, Tenable, or related Federal cybersecurity tools. * Experience with RMF, A&A, continuous monitoring, Zero Trust ...
Experience with GRC platforms, ACAS, Nessus, SCAP, SonarQube, GitLab, Splunk, Tanium, Tenable, or related Federal cybersecurity tools. * Experience with RMF, A&A, continuous monitoring, Zero Trust ...
Senior Cybersecurity Engineer / (SME) ? Level III
Washington, DC · Hybrid
$120K - $163K/yr
... GRC) platform administration, and emerging technology integration across classified and unclassified environments. The Senior Cybersecurity Engineer is responsible for designing secure enterprise ...
Senior Cybersecurity Engineer / (SME) ? Level III
Washington, DC · Hybrid
$120K - $163K/yr
... GRC) platform administration, and emerging technology integration across classified and unclassified environments. The Senior Cybersecurity Engineer is responsible for designing secure enterprise ...
Senior Cybersecurity Engineer / (SME) - Level III
Washington, DC · On-site
$120K - $163K/yr
... GRC) platform administration, and emerging technology integration across classified and ... The Senior Cybersecurity Engineer is responsible for designing secure enterprise architectures ...
Senior Cybersecurity Engineer / (SME) - Level III
Washington, DC · On-site
$120K - $163K/yr
... GRC) platform administration, and emerging technology integration across classified and ... The Senior Cybersecurity Engineer is responsible for designing secure enterprise architectures ...
GRC Engineer III
Washington, DC · On-site
GRC Engineer III Category: Cyber Security Main location: United States, District of Columbia, Washington Position ID:J0626-1755 Employment Type: Full Time Position Description: The GRC Engineer III ...
GRC Engineer III
Washington, DC · On-site
GRC Engineer III Category: Cyber Security Main location: United States, District of Columbia, Washington Position ID:J0626-1755 Employment Type: Full Time Position Description: The GRC Engineer III ...
... GRC efforts. This position is 100% Onsite and not open for Remote. Senior Analyst, Cybersecurity Governance, Risk and Compliance Responsibilities: - Review and understand current IT Risk Management ...
... GRC efforts. This position is 100% Onsite and not open for Remote. Senior Analyst, Cybersecurity Governance, Risk and Compliance Responsibilities: - Review and understand current IT Risk Management ...
Familiarity with Governance, Risk, and Compliance (GRC) platforms such as RSA Archer . * Experience supporting cybersecurity audits, inspections, policy compliance assessments, and governance reviews.
Familiarity with Governance, Risk, and Compliance (GRC) platforms such as RSA Archer . * Experience supporting cybersecurity audits, inspections, policy compliance assessments, and governance reviews.
Sr. Security Engineer - GRC Frameworks & AI Governance
Washington, DC · On-site
$129K - $177K/yr
Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory ... Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, Drata, or ...
Quick apply
Sr. Security Engineer - GRC Frameworks & AI Governance
Washington, DC · On-site
$129K - $177K/yr
Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory ... Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, Drata, or ...
Cyber Security Grc information
See Reston, VA salary details
$42.8K - $56.2K
0% of jobs
$56.2K - $69.6K
0% of jobs
$69.6K - $83K
4% of jobs
$83K - $96.4K
9% of jobs
$109.3K is the 25th percentile. Wages below this are outliers.
$96.4K - $109.8K
13% of jobs
$109.8K - $123.2K
20% of jobs
The median wage is $126.8K / yr.
$123.2K - $136.6K
16% of jobs
$147.1K is the 75th percentile. Wages above this are outliers.
$136.6K - $150K
17% of jobs
$150K - $163.4K
12% of jobs
$163.4K - $176.8K
6% of jobs
$176.8K - $190.2K
3% of jobs
$42.8K
$129.9K
$190.2K
How much do cyber security grc jobs pay per year?
Is cyber security GRC a good job?
What are some common challenges faced by Cyber Security GRC professionals, and how do they typically overcome them?
Cyber Security GRC professionals often face the challenge of keeping up with evolving regulations, adapting controls for new technologies, and coordinating between security teams and business units. To overcome these challenges, professionals stay current with industry standards, participate in ongoing training, and actively communicate policy changes and risk assessments to stakeholders across the organization. They also leverage robust GRC tools to streamline compliance processes and documentation. Working collaboratively with IT, legal, and compliance teams allows them to better identify risks and implement effective, practical security controls. This approach ensures a well-integrated and proactive risk management posture for the organization.
What is a Cyber Security GRC?
A Cyber Security GRC (Governance, Risk, and Compliance) job focuses on ensuring an organization's security policies, risk management strategies, and regulatory compliance. Professionals in this role develop and enforce security policies, assess risks, and ensure adherence to industry regulations like GDPR, HIPAA, or ISO 27001. They collaborate with different teams to mitigate cybersecurity threats while aligning security practices with business goals. This role is critical for maintaining an organization's security posture and reducing potential risks.
Is cyber security GRC in high demand?
What are the key skills and qualifications needed to thrive in the Cyber Security GRC position?
To thrive as a Cyber Security GRC professional, a solid understanding of information security frameworks, risk management, and regulatory compliance is essential, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as Archer, ServiceNow, or LogicGate), and certifications like CISSP, CISM, or CRISC, are highly valued. Excellent analytical skills, attention to detail, and the ability to communicate complex risks to non-technical stakeholders are critical soft skills. These capabilities ensure organizations remain secure, compliant, and able to effectively manage evolving cyber risks.

Full-time
Re-posted 18 days ago
Job description
Emerging Technology / Cybersecurity Engineer
Zermount is seeking a senior Emerging Technology / Cybersecurity Engineer to support a federal client in modernizing cybersecurity authorization, cloud security, architecture review, and emerging technology assessment.
This client-facing role helps accelerate secure adoption of SaaS, AI technologies, cloud services, commercial products, and emerging capabilities. The engineer will support RMF, ATO, continuous monitoring, cloud compliance, control validation, AI security testing, and risk-based authorization decisions.
Responsibilities include architecture reviews; SaaS, cloud, AI, and non-COTS assessments; review of data flows, identity models, access controls, logging, tenant isolation, and network architecture; development of reusable security patterns, test plans, control checklists, and ATO-ready evidence; documentation of risks, POA&Ms, remediation plans, and executive recommendations; vendor coordination; and continuous ATO modernization.
Candidates must have 5+ years of experience in cybersecurity, architecture, cloud security, GRC, RMF, ATO, or federal compliance. Experience with federal programs, NIST RMF/CSF, FISMA, FedRAMP, vulnerability management, cloud compliance, SaaS assessments, control validation, risk reporting, and stakeholder coordination is required.
Preferred experience includes AI/LLM security testing, generative AI risk assessment, continuous ATO, evidence automation, AWS, Azure, GCP, DevSecOps, SIEM/SOAR/GRC tools, Tenable, Splunk, Sentinel, ServiceNow, Prisma Cloud, or similar tools.
Bachelor's degree in Computer Science, IT, Cybersecurity, Engineering, or equivalent experience required. One certification is required, such as Security+, CISSP, CISM, CISA, CCSP, GCIH, AWS Security Specialty, Microsoft Cybersecurity Architect Expert, Azure Security Engineer Associate, or equivalent GIAC.
Public Trust required; Secret preferred. Remote with occasional reporting to Arlington/Alexandria, VA.
- Ability to pass a minimum background investigation.
About Zermount
Sourced by ZipRecruiter
Industry
Network security
Company size
11 - 50 Employees
Headquarters location
Arlington, VA, US
Year founded
2013