1

Cybersecurity Governance Risk Compliance Jobs in Baltimore, MD

The ideal candidate will have experience in cybersecurity governance, risk management, compliance, IT audit, and security controls, along with exposure to ServiceNow and database environments. Key ...

Cyber GRC Specialist

Baltimore, MD ยท On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

... governance, risk, compliance, and control-management routines. This blended role is designed for ... Preferred Qualifications * Bachelor's degree in cyber security, information systems, risk ...

Cyber GRC Specialist

Baltimore, MD ยท On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

... governance, risk, compliance, and control-management routines. This blended role is designed for ... Preferred Qualifications * Bachelor's degree in cyber security, information systems, risk ...

Cyber GRC Specialist

Baltimore, MD ยท On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

... governance, risk, compliance, and control-management routines. This blended role is designed for ... Preferred Qualifications * Bachelor's degree in cyber security, information systems, risk ...

AI Governance Coordinator

Baltimore, MD ยท Remote

$44/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...

AI Governance Coordinator

Baltimore, MD ยท Remote

$44/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...

AI Governance Coordinator

Baltimore, MD ยท Remote

$44/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...

AI Governance Coordinator

Baltimore, MD ยท Remote

$44/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...

AI Governance Coordinator

Baltimore, MD ยท Remote

$44/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...

next page

Showing results 1-20

Cybersecurity Governance Risk Compliance information

See Baltimore, MD salary details

$22.9K

$113K

$149.5K

How much do cybersecurity governance risk compliance jobs pay per year?

As of Aug 18, 2026, the average yearly pay for cybersecurity governance risk compliance in Baltimore, MD is $112,981.00, according to ZipRecruiter salary data. Most workers in this role earn between $99,400.00 and $128,200.00 per year, depending on experience, location, and employer.

What is cybersecurity governance, risk, and compliance (GRC)?

Cybersecurity Governance, Risk, and Compliance (GRC) refers to a framework used by organizations to align their IT and security strategies with business objectives, manage risks, and ensure compliance with laws and regulations. Governance involves setting policies and procedures, risk focuses on identifying and addressing threats, and compliance ensures adherence to required standards. Professionals in this field help organizations protect sensitive data, avoid regulatory penalties, and build trust with stakeholders. GRC is essential for maintaining effective cybersecurity and demonstrating due diligence.

What are the key skills and qualifications needed to thrive as a cybersecurity governance, risk, and compliance (GRC) professional?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of information security frameworks, risk management principles, and regulatory compliance, often supported by a degree in cybersecurity or related fields. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow), and certifications such as CISSP, CISM, or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you interpret regulations and collaborate with stakeholders. These skills ensure organizations can manage cybersecurity risks proactively while meeting regulatory and industry standards.

What are some typical challenges faced by professionals in cybersecurity governance, risk, and compliance (GRC) roles?

Professionals in Cybersecurity GRC roles often navigate the challenge of keeping up with rapidly changing regulatory requirements while ensuring company policies align with both business objectives and security best practices. Balancing the need for robust security controls with operational efficiency, educating non-technical stakeholders about risk, and managing audits are common aspects of the job. Additionally, GRC professionals frequently collaborate with IT, legal, and business teams to ensure a cohesive approach to risk management and compliance. This dynamic environment requires strong communication skills, adaptability, and a commitment to continuous learning.

What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?

AspectCybersecurity Governance Risk ComplianceCybersecurity Analyst
CertificationsCISA, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, audits, compliance frameworksMonitoring security systems, incident response
Employer & Industry UsageOrganizations with compliance needs, regulatory bodiesIT security teams, cybersecurity firms

While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What are popular job titles related to Cybersecurity Governance Risk Compliance jobs in Baltimore, MD?

For Cybersecurity Governance Risk Compliance jobs in Baltimore, MD, the most frequently searched job titles are:

What job categories do people searching Cybersecurity Governance Risk Compliance jobs in Baltimore, MD look for?

The top searched job categories for Cybersecurity Governance Risk Compliance jobs in Baltimore, MD are:

What cities near Baltimore, MD are hiring for Cybersecurity Governance Risk Compliance jobs?

Cities near Baltimore, MD with the most Cybersecurity Governance Risk Compliance job openings:

Infographic showing various Cybersecurity Governance Risk Compliance job openings in Baltimore, MD as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 12% Part Time, and 4% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $112,981 per year, or $54.3 per hour.

Director of Cybersecurity, Governance, Risk and Compliance

Gross, Mendelsohn & Associates, P.A.

Baltimore, MD โ€ข On-site

Full-time

Re-posted 17 days ago


Job description

Gross Mendelsohn, one of the Mid-Atlanticโ€™s leading independent CPA and advisory firms, is seeking a strategic and technically strong Director of Cybersecurity Governance, Risk & Compliance (GRC) to build and lead our cybersecurity and IT risk advisory capabilities.

This is a visible, high-impact leadership role responsible for designing, implementing, and overseeing enterprise cybersecurity and IT compliance programs for both clients and the firm, particularly government contractors and organizations operating in regulated environments.

As cybersecurity requirements continue to intensify, this role will sit at the intersection of IT architecture, regulatory compliance, risk advisory, and executive leadership. The Director will help position Gross Mendelsohn as a trusted advisor in cybersecurity governance, CUI compliance, and federal regulatory readiness.

Recognized with nine Top Workplace awards, Gross Mendelsohn is committed to professional excellence, collaboration, and long-term growth. This opportunity offers leadership visibility, strategic influence, and the ability to build and expand a critical service line within a respected independent firm.

Key Responsibilities

Cybersecurity & IT Governance Leadership

  • Serve as the firmโ€™s senior leader for cybersecurity governance, risk, and compliance advisory services

  • Design and oversee enterprise cybersecurity frameworks aligned with NIST CSF, NIST SP 800-171, NIST SP 800-53, ISO 27001, and related standards

  • Lead end-to-end CUI and federal compliance programs, including development and maintenance of System Security Plans (SSP) and Plans of Action & Milestones (POA&M)

  • Conduct NIST SP 800-171 gap assessments and develop prioritized remediation roadmaps

  • Support clients with DFARS 252.204-7012 compliance, SPRS scoring, and CMMC readiness initiatives

  • Prepare clients for audits, mock assessments, and government inquiries

IT Infrastructure & Security Oversight

  • Oversee implementation and validation of technical cybersecurity controls, including:

  • Multi-factor authentication

  • Encryption (data at rest and in transit)

  • Endpoint protection

  • Logging, SIEM, and continuous monitoring

  • Network segmentation

  • Secure configuration and hardening standards

  • Provide advisory oversight of secure cloud environments, including Microsoft GCC High, Azure Government, and AWS GovCloud

  • Establish identity and access management frameworks and privileged access controls

  • Evaluate backup, disaster recovery, and business continuity processes

  • Direct incident response strategy and regulatory reporting obligations

Supply Chain & Flow-Down Advisory

  • Advise prime contractors on subcontractor cybersecurity flow-down requirements

  • Assess subcontractor readiness and compliance risk exposure

  • Support documentation required for federal scrutiny

Training & Continuous Improvement

  • Develop and deliver CUI-specific and role-based cybersecurity training

  • Implement measurable security awareness initiatives, including phishing simulations

  • Lead annual program reviews and continuous improvement initiatives

  • Maintain compliance posture during infrastructure changes, acquisitions, or system transitions

Executive Advisory & Reporting

  • Prepare executive-level cybersecurity risk reports and board-ready briefings

  • Translate complex technical risk into actionable business guidance

  • Collaborate with firm leadership to expand cybersecurity service offerings

  • Bachelorโ€™s degree in Cybersecurity, Information Systems, Computer Science, Engineering, or related field

  • 7โ€“12+ years of progressive experience in cybersecurity, IT risk, compliance, or security architecture

  • Demonstrated experience leading CUI, DFARS, and NIST 800-171 compliance initiatives

  • Experience working within a government contractor or regulated environments strongly preferred

  • Experience with secure federal cloud platforms such as GCC High or GovCloud preferred

  • Professional certifications preferred: CISSP, CISM, CISA, ISO 27001 Lead Implementer, Security+, or equivalent

Required Skills and Competencies

ย  ย  ย  Technical Expertise

  • Deep understanding of modern IT infrastructure, cloud security, and cybersecurity architecture

  • Strong working knowledge of NIST frameworks and federal cybersecurity regulations

  • Experience leading risk assessments and remediation programs

  • Strong documentation, audit-readiness, and control validation capabilities

Analytical Strength

  • Exceptional risk analysis and problem-solving skills

  • Ability to align cybersecurity controls with business processes

  • Strong systems thinking and governance design capability

Interpersonal & Professional Skills

  • Strong executive presence and communication skills

  • Ability to present complex cybersecurity risks clearly to non-technical audiences

  • Collaborative leadership style with the ability to build cross-functional relationships

  • Growth-oriented mindset with interest in expanding advisory capabilities

Additional Requirements

  • U.S. Citizenship required

  • Ability to travel up to 30% to client sites as needed

  • Proficiency in Microsoft Office and cybersecurity reporting tools

Why Join Gross Mendelsohn?

  • Lead and grow a high-impact cybersecurity advisory capability

  • Work directly with firm leadership in a visible strategic role

  • Contribute to modernization initiatives within a respected independent firm

  • Collaborative, growth-oriented culture

  • Competitive compensation and comprehensive benefits

  • Free parking at our Locust Point/McHenry Row office

  • Hybrid flexibility is available with approval

Work Environment

This role offers flexibility to work hybrid or fully remote; however, the Director of Cybersecurity will be expected to be present at client sites or in the office as business needs require, particularly for client delivery, team leadership, and strategic initiatives.

Physical Requirements

Ability to sit for extended periods, lift up to 20 pounds, and manage physical files and documentation as needed.

Join Us

If you are a strategic and execution-driven cybersecurity leader who thrives in a collaborative, growth-oriented professional services firm and is energized by building, scaling, and protecting a high-impact practice, we encourage you to apply.

Gross Mendelsohn is an equal opportunity employer

committed to fostering a respectful and inclusive workplace.