1

Cybersecurity Governance Risk Compliance Jobs in Reston, VA

Manager, Cyber Security

Reston, VA ยท Remote

$115.50K - $156.10K/yr

ICF is seeking an experienced Cybersecurity Manager to lead cybersecurity governance, risk management, compliance coordination, and security integration for a complex federal technology services ...

Manager, Cyber Security

Reston, VA ยท On-site

$115.50K - $156.10K/yr

ICF is seeking an experienced Cybersecurity Manager to lead cybersecurity governance, risk management, compliance coordination, and security integration for a complex federal technology services ...

Cybersecurity Program Manager

Alexandria, VA

$118.80K - $160.50K/yr

This role requires a seasoned professional with extensive experience in cybersecurity program management, federal compliance frameworks, risk management, and enterprise security governance . The ...

Cybersecurity Program Manager

Washington, DC ยท On-site

$130.90K - $131.50K/yr

Advise executive leadership on cybersecurity strategy and risk management * Lead enterprise cybersecurity governance and compliance efforts * Support zero trust and cloud modernization initiatives

next page

Showing results 1-20

Cybersecurity Governance Risk Compliance information

See Reston, VA salary details

$23.9K

$118.3K

$156.6K

How much do cybersecurity governance risk compliance jobs pay per year?

As of May 29, 2026, the average yearly pay for cybersecurity governance risk compliance in Reston, VA is $118,293.00, according to ZipRecruiter salary data. Most workers in this role earn between $104,000.00 and $134,200.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Cybersecurity Governance, Risk, and Compliance (GRC) professional, and why are they important?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of information security frameworks, risk management principles, and regulatory compliance, often supported by a degree in cybersecurity or related fields. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow), and certifications such as CISSP, CISM, or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you interpret regulations and collaborate with stakeholders. These skills ensure organizations can manage cybersecurity risks proactively while meeting regulatory and industry standards.

What are some typical challenges faced by professionals in Cybersecurity Governance, Risk, and Compliance (GRC) roles?

Professionals in Cybersecurity GRC roles often navigate the challenge of keeping up with rapidly changing regulatory requirements while ensuring company policies align with both business objectives and security best practices. Balancing the need for robust security controls with operational efficiency, educating non-technical stakeholders about risk, and managing audits are common aspects of the job. Additionally, GRC professionals frequently collaborate with IT, legal, and business teams to ensure a cohesive approach to risk management and compliance. This dynamic environment requires strong communication skills, adaptability, and a commitment to continuous learning.

What is Cybersecurity Governance, Risk, and Compliance (GRC)?

Cybersecurity Governance, Risk, and Compliance (GRC) refers to a framework used by organizations to align their IT and security strategies with business objectives, manage risks, and ensure compliance with laws and regulations. Governance involves setting policies and procedures, risk focuses on identifying and addressing threats, and compliance ensures adherence to required standards. Professionals in this field help organizations protect sensitive data, avoid regulatory penalties, and build trust with stakeholders. GRC is essential for maintaining effective cybersecurity and demonstrating due diligence.

What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?

AspectCybersecurity Governance Risk ComplianceCybersecurity Analyst
CertificationsCISA, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, audits, compliance frameworksMonitoring security systems, incident response
Employer & Industry UsageOrganizations with compliance needs, regulatory bodiesIT security teams, cybersecurity firms

While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What cities near Reston, VA are hiring for Cybersecurity Governance Risk Compliance jobs? Cities near Reston, VA with the most Cybersecurity Governance Risk Compliance job openings:
Senior Analyst, Cybersecurity Governance, Risk and Compliance

Senior Analyst, Cybersecurity Governance, Risk and Compliance

Next Step Systems

Washington, DC โ€ข On-site

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 21 days ago


Job description

Senior Analyst, Cybersecurity Governance, Risk and Compliance, Washington, DC
The Senior Analyst, Cybersecurity Governance Risk & Compliance will administer the completion of compliance-related client requests to assess security policies and procedures. The Senior Analyst will respond to inquiries on the security controls policy, processes, and procedures implemented for managed systems and applications, as well as support Third Party Risk Management (TPRM) and Governance and Risk functions in conducting vendor due diligence (initial, reassessments and ongoing monitoring) and supporting broader GRC efforts. This position is 100% Onsite and not open for Remote.
Senior Analyst, Cybersecurity Governance, Risk and Compliance Responsibilities:
- Review and understand current IT Risk Management (ITRM) program framework and associated policies, standards, procedures, and processes.
- Prepare and respond to related compliance requests and web-shares including referencing evidentiary artifacts or other documentation.
- Complete external information security assessments, remediation efforts and support status tracking of assessment queues.
- Coordinate with external assessors and internal subject matter experts to address compliance inquiries and web-shares of security artifacts.
- Assist in further defining the process for completing information security control assessments.
- Support metrics and reporting of the Information Security Program through the collection and analysis of effectiveness security control measures.
- Develop understanding of control structure to support the creating or revising standard narratives/responses for client questionnaires (e.g., SIG).
- Work with the CISO, senior managers, managers and other internal stakeholders to report existing information security programs and ongoing security projects that address information security risks and compliance requirements.
- Manage competing deadlines and multiple external inquiries using effective organizational skills and attention to detail as demonstrated by prior work experience.
- Contribute to the creation of GRC related processes and procedures and relevant documents.
- Collaborate with InfoSec, Privacy and GRC management and internal subject matter experts to support coordination, tracking, and reporting of GRC team strategy and goals; and complete other tasks as assigned.
- Participate in efforts to evolve and streamline GRC solutions, processes and procedures.
- Develop and maintain the status tracking related to findings from information security assessments, Governance, Risk and Compliance, and TPRM due diligence/reassessment assessments and associated remediations.
Senior Analyst, Cybersecurity Governance, Risk and Compliance Qualifications:
- Bachelor's degree (required) and at least 5 years of combined information technology and information security experience.
- Strong understanding of multiple risk management concepts, frameworks, and standards (CSC, NIST, ISO, COBIT).
- Strong understanding of information security concepts and technologies.
- Strong understanding of due diligence and compliance documents (e.g. SOC 2 Type 2, ISO 27001 Certification, SIG Questionnaires, Certificates of Insurance, Pen Test, etc.).
- Strong communication skills with the ability to interact with various teams.
- Demonstrated experience with the NIST Cybersecurity Framework and auditing security controls identified in NIST SP800-171 and NIST SP800-53A.
- Experience in the analysis of IT and Security control requirements and understanding of associated technology processes.
- Experience working with internal and external auditing firms.
- Fundamental knowledge of MS Outlook, Word, Excel, Visio, and PowerPoint.
Benefits include medical insurance, retirement plan, Dental, Vision, PTO, etc.
Keywords: Washington DC Jobs, Senior Analyst, Cybersecurity Governance Risk and Compliance, Information Security, Risk Management, CSC, NIST, ISO, COBIT, Cybersecurity Framework, NIST SP800-171, NIST SP800-53A, SOC 2 Type 2, ISO 27001 Certification, SIG Questionnaires, Certificates of Insurance, Pen Test, Washington, DC Recruiters, Information Technology Jobs, IT Jobs, Washington, DC Recruiting
Looking to hire for similar positions in Washington, DC or in other cities? Our IT recruiting agencies and staffing companies can help.
We help companies that are looking to hire Senior Analysts, Cybersecurity Governance Risk and Compliance for jobs in Washington, DC and in other cities too. Please contact our IT recruiting agencies and IT staffing companies today! Phone 630-428-0600 ext. 11 or email us at jobs@nextstepsystems.com. Click here to submit your resume for this job and others.
Atlanta Georgia IT Recruiters, Austin TX IT Recruiters, Baltimore Executive Staffing, Boston IT Recruiters, Charlotte IT Recruiters, Chicago Recruiting Agency, Cincinnati Executive Search Firms, Cleveland Executive Tech Recruiting, Columbus Technical Recruiters, Dallas Recruiters for IT, Denver Technology Headhunters, Detroit IT Headhunters, Fort Lauderdale Information Technology Recruiters, Houston IT Recruiters, Indianapolis IT Recruiters, Jacksonville IT Recruiters, Kansas City IT Recruiters, Los Angeles IT Recruiters, Miami IT Recruiters, Minneapolis IT Recruiters, Nashville IT Recruiters, New Jersey Tech Recruiters, New York IT Recruiters, Phoenix IT Recruiters, Raleigh IT Recruiters, Salt Lake City IT Recruitment, San Antonio Information Technology Recruiters, San Diego Executive Staffing, San Francisco Executive Search Firms, San Jose Executive Tech Recruiting, Seattle Technical Recruiters, Silicon Valley Tech Recruiters, St. Louis Technology Headhunters, Tampa Technology Headhunters, Washington DC IT Recruiters
Home"Senior Analyst, Cybersecurity Governance, Risk and Compliance