1

Cyber Security Grc Jobs in Silver Spring, MD (NOW HIRING)

Lead or support GRC program activities including control implementation planning, risk assessments ... Monitor evolving federal cybersecurity policy and translate emerging requirements into architecture ...

We are looking for a Cybersecurity Engineer to design and guide secure system architectures that ... Lead or support GRC program activities including control implementation planning, risk assessments ...

Be Seen First

Proven B2B services or solution sales experience, ideally in cybersecurity, GRC, compliance, IT, or government contracting * Comfortable with long, consultative, trust-based sales cycles * A self ...

New

Education * Bachelor's degree in Cybersecurity, Information Technology, Information Systems ... GRC program experience * Technical documentation experience * Customer service and project ...

Education * Bachelor's degree in Cybersecurity, Information Technology, Information Systems ... GRC program experience * Technical documentation experience * Customer service and project ...

Showing results 21-40

Cyber Security Grc information

See Silver Spring, MD salary details

$41.9K

$127K

$186.1K

How much do cyber security grc jobs pay per year?

As of Sep 6, 2026, the average yearly pay for cyber security grc in Silver Spring, MD is $127,041.00, according to ZipRecruiter salary data. Most workers in this role earn between $105,400.00 and $146,800.00 per year, depending on experience, location, and employer.

What is a Cyber Security GRC?

A Cyber Security GRC (Governance, Risk, and Compliance) job focuses on ensuring an organization's security policies, risk management strategies, and regulatory compliance. Professionals in this role develop and enforce security policies, assess risks, and ensure adherence to industry regulations like GDPR, HIPAA, or ISO 27001. They collaborate with different teams to mitigate cybersecurity threats while aligning security practices with business goals. This role is critical for maintaining an organization's security posture and reducing potential risks.

What are the key skills and qualifications needed to thrive in the Cyber Security GRC position?

To thrive as a Cyber Security GRC professional, a solid understanding of information security frameworks, risk management, and regulatory compliance is essential, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as Archer, ServiceNow, or LogicGate), and certifications like CISSP, CISM, or CRISC, are highly valued. Excellent analytical skills, attention to detail, and the ability to communicate complex risks to non-technical stakeholders are critical soft skills. These capabilities ensure organizations remain secure, compliant, and able to effectively manage evolving cyber risks.

What are some common challenges faced by Cyber Security GRC professionals, and how do they typically overcome them?

Cyber Security GRC professionals often face the challenge of keeping up with evolving regulations, adapting controls for new technologies, and coordinating between security teams and business units. To overcome these challenges, professionals stay current with industry standards, participate in ongoing training, and actively communicate policy changes and risk assessments to stakeholders across the organization. They also leverage robust GRC tools to streamline compliance processes and documentation. Working collaboratively with IT, legal, and compliance teams allows them to better identify risks and implement effective, practical security controls. This approach ensures a well-integrated and proactive risk management posture for the organization.

Is cyber security GRC a good job?

Cyber security GRC (Governance, Risk, and Compliance) is a growing field that offers opportunities in risk management, policy development, and compliance auditing. It typically requires knowledge of security frameworks, regulations, and tools like audit software, with roles often involving regular office hours and certification requirements such as CISSP or CISA. The job can be stable and well-paying for those with relevant skills and experience.

Is cyber security GRC in high demand?

Cyber security GRC (Governance, Risk, and Compliance) professionals are in high demand due to increasing cybersecurity threats and regulatory requirements. Organizations seek experts with knowledge of frameworks like ISO 27001 and NIST, and certifications such as CISA or CISSP, to manage compliance and risk effectively.

What are the most commonly searched types of Cyber Security Grc jobs in Silver Spring, MD?

The most popular types of Cyber Security Grc jobs in Silver Spring, MD are:

What are popular job titles related to Cyber Security Grc jobs in Silver Spring, MD?

For Cyber Security Grc jobs in Silver Spring, MD, the most frequently searched job titles are:

What job categories do people searching Cyber Security Grc jobs in Silver Spring, MD look for?

The top searched job categories for Cyber Security Grc jobs in Silver Spring, MD are:

What cities near Silver Spring, MD are hiring for Cyber Security Grc jobs?

Cities near Silver Spring, MD with the most Cyber Security Grc job openings:

Infographic showing various Cyber Security Grc job openings in Silver Spring, MD as of August 2026, with employment types broken down into 87% Full Time, 10% Part Time, and 3% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $127,041 per year, or $61.1 per hour.

Cybersecurity Engineer

LMI

Tysons, VA โ€ข On-site

Full-time

Posted 18 days ago


Job description

Overview

We are looking for a Cybersecurity Engineer to design and guide secure system architectures that can achieve and sustain federal cybersecurity authorization. This role focuses on translating complex regulatory frameworks into practical architecture patterns that enable platforms and applications to meet the rigorous expectations of federal security programs.

You will operate at the intersection of security architecture, DevSecOps, and Governance, Risk, and Compliance (GRC)-ensuring systems are architected for authorization success while also guiding the documentation, risk management, and programmatic processes required to achieve and maintain compliance.

This role is ideal for an experienced security architect or senior federal cybersecurity professional who understands both federal authorization frameworks and modern cloud/software architectures, and who can bridge engineering teams, security governance functions, and government stakeholders.

LMI is a new breed of digital solutions provider dedicated to accelerating government impact with innovation and speed. Investing in technology and prototypes ahead of need, LMI brings commercial-grade platforms and mission-ready AI to federal agencies at commercial speed.

Leveraging our mission-ready technology and solutions, proven expertise in federal deployment, and strategic relationships, we enhance outcomes for the government, efficiently and effectively. With a focus on agility and collaboration, LMI serves the defense, space, healthcare, and energy sectors-helping agencies navigate complexity and outpace change. Headquartered in Tysons, Virginia, LMI is committed to delivering impactful results that strengthen missions and drive lasting value.

Responsibilities
  • Architect systems to support authorization under FedRAMP, DoD RMF, CMMC, and related federal cybersecurity frameworks
  • Translate requirements from NIST SP 800-53, NIST SP 800-171/172, and DoD security guidance into concrete architecture patterns and engineering implementation strategies
  • Define secure reference architectures across identity, network segmentation, platform security, data protection, logging, monitoring, and system boundary design
  • Work directly with engineering and DevSecOps teams to embed security controls into platform architecture, CI/CD pipelines, and operational workflows
  • Conduct security architecture and design reviews for applications, platforms, and infrastructure supporting federal missions
  • Guide teams in structuring systems for authorization efficiency, including control inheritance strategies, system boundary definitions, and shared service architectures
  • Lead or support GRC program activities including control implementation planning, risk assessments, and authorization readiness
  • Support development of authorization artifacts including System Security Plans (SSPs), control narratives, architecture documentation, and POA&Ms
  • Provide expertise on DoD Cloud Computing environments (IL4/5/6), National Security Systems (NSS), and environments handling CUI and National Security Information
  • Conduct DISA STIG analysis and secure configuration reviews for operating systems, platforms, and infrastructure
  • Collaborate with DevSecOps teams to implement automated compliance validation, continuous monitoring, and security telemetry
  • Provide architecture guidance and security readiness briefings to engineering teams, leadership, and government stakeholders
  • Monitor evolving federal cybersecurity policy and translate emerging requirements into architecture and GRC program guidance
Qualifications
  • Top Secret clearance required.
  • Active CISSP, CISM, GSLC, C|CISO, or comparable senior cybersecurity certification
  • 10+ years of experience in federal cybersecurity supporting system security engineering, security architecture, or GRC programs aligned with NIST SP 800-53 and the NIST Risk Management Framework
  • Experience supporting systems pursuing FedRAMP, DoD RMF, or CMMC authorization
  • Experience implementing and managing security control programs and compliance activities including SSP development, POA&M management, and authorization readiness
  • Strong understanding of modern cloud architectures (AWS, Azure, or similar), hybrid infrastructure, and containerized platforms
  • Experience translating compliance frameworks into technical implementation guidance for engineering teams
  • Experience performing risk assessments related to architecture changes, vulnerabilities, new systems, and data governance
  • Strong communication skills and the ability to bridge security, engineering, and government stakeholders

Preferred Qualifications

  • Experience supporting DoD Cloud Computing SRG environments (IL4/5/6)
  • Experience working with National Security Systems (NSS) or classified-adjacent architectures
  • Familiarity with DevSecOps platforms and compliance automation approaches
  • Experience using GRC platforms to manage controls, artifacts, and continuous monitoring
  • Experience participating in Architecture Review Boards (ARB), Change Advisory Boards (CAB), or security design reviews
  • Experience supporting environments that process or store Controlled Unclassified Information (CUI)
  • Experience working in federal consulting, defense, intelligence, or mission-focused environments
  • Master's degree or bachelor's degree with equivalent experience

What Success Looks Like

  • Systems are architected from the start to meet federal security requirements, avoiding costly redesigns during authorization
  • Engineering teams understand how to implement security controls as part of system architecture

The salary range displayed represents the typical salary range for this position and is not a guarantee of compensation. Individual salaries are determined by various factors including, but not limited to location, internal equity, business considerations, client contract requirements, and candidate qualifications, such as education, experience, skills, and security clearances.ย 

The target salary range for this posiiton is up to $170,000

Applicants must meet eligibility requirements for a U.S. Government security clearance. Only US Citizens are eligible for a security clearance. For this position, LMI will only consider applicants with security clearances or applicants who are eligible for security clearances, due to the nature of the work.

Job LocationsUS-VA-TysonsEmployment Type: FULL_TIME