1

Cybersecurity Governance Risk Compliance Jobs in Reston, VA

... cybersecurity governance, risk, and compliance consulting, preferably within a public accounting or large professional services environment. * Ability to travel up to 30% to federal client sites and ...

next page

Showing results 1-20

Cybersecurity Governance Risk Compliance information

See Reston, VA salary details

$23.9K

$118.3K

$156.6K

How much do cybersecurity governance risk compliance jobs pay per year?

As of May 29, 2026, the average yearly pay for cybersecurity governance risk compliance in Reston, VA is $118,293.00, according to ZipRecruiter salary data. Most workers in this role earn between $104,000.00 and $134,200.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Cybersecurity Governance, Risk, and Compliance (GRC) professional, and why are they important?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of information security frameworks, risk management principles, and regulatory compliance, often supported by a degree in cybersecurity or related fields. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow), and certifications such as CISSP, CISM, or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you interpret regulations and collaborate with stakeholders. These skills ensure organizations can manage cybersecurity risks proactively while meeting regulatory and industry standards.

What are some typical challenges faced by professionals in Cybersecurity Governance, Risk, and Compliance (GRC) roles?

Professionals in Cybersecurity GRC roles often navigate the challenge of keeping up with rapidly changing regulatory requirements while ensuring company policies align with both business objectives and security best practices. Balancing the need for robust security controls with operational efficiency, educating non-technical stakeholders about risk, and managing audits are common aspects of the job. Additionally, GRC professionals frequently collaborate with IT, legal, and business teams to ensure a cohesive approach to risk management and compliance. This dynamic environment requires strong communication skills, adaptability, and a commitment to continuous learning.

What is Cybersecurity Governance, Risk, and Compliance (GRC)?

Cybersecurity Governance, Risk, and Compliance (GRC) refers to a framework used by organizations to align their IT and security strategies with business objectives, manage risks, and ensure compliance with laws and regulations. Governance involves setting policies and procedures, risk focuses on identifying and addressing threats, and compliance ensures adherence to required standards. Professionals in this field help organizations protect sensitive data, avoid regulatory penalties, and build trust with stakeholders. GRC is essential for maintaining effective cybersecurity and demonstrating due diligence.

What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?

AspectCybersecurity Governance Risk ComplianceCybersecurity Analyst
CertificationsCISA, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, audits, compliance frameworksMonitoring security systems, incident response
Employer & Industry UsageOrganizations with compliance needs, regulatory bodiesIT security teams, cybersecurity firms

While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What cities near Reston, VA are hiring for Cybersecurity Governance Risk Compliance jobs? Cities near Reston, VA with the most Cybersecurity Governance Risk Compliance job openings:
System Owner-Boundary Compliance Owner - US Federal

System Owner-Boundary Compliance Owner - US Federal

Workday

Reston, VA

Full-time

Posted 8 days ago


Workday rating

9.2

Company rating: 9.2 out of 10

Based on 7 frontline employees who took The Breakroom Quiz

12th of 183 rated software companies


Job description

Your work days are brighter here.

We're obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we're shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you'll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We're in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you'll do meaningful work with Workmates who've got your back. In return, we'll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you've found a match in Workday, and we hope to be a match for you too.

About the Team

The Workday Cybersecurity Governance, Risk, Compliance & Trust (cGRCT) team enables business agility while maintaining a strong security posture via intelligent The Workday's National Security Group (NSG) is responsible for all aspects of cybersecurity and compliance for Workday's US Department of Defense and Intelligence Community customer regions. The NSG Governance, Risk, Compliance (GRC) Team enables business agility while maintaining a strong security posture via intelligent risk-taking, optimized controls management, and iterative security governance. The NSG GRC team's mission is to enable and maintain Workday's National Security offerings through certification, continuous monitoring, consultation and deep stakeholder alignment. We act as a trusted advisor across Workday to help maintain and enhance our customer's trust.

About the Role

This role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native).

As the system owner for our federal information system, you will be responsible for the lifecycle of our information systems. This is a high-impact role that will provide cross-functional ownership, stewardship, and focus for our compliance boundaries (e.g., Fedramp Moderate, IL4, Top Secret). While individual teams will focus on their respective functions (Security Operations, GRC, Engineering) this role will span all teams and boundaries and act as a focal point for the Federal business.


The boundary's scope is wide-ranging, covering security, system health, compliance risks, cost/unit economics, incident/on-call trends, and future roadmaps (e.g., AI/ML capabilities or SKUs). To effectively address these complex issues, the System Owner must engage and coordinate the appropriate cross-functional experts from Security, Engineering, Product, Finance, and GRC. You will own the long-term trajectory, risk posture, and architectural runway of your assigned boundary, ensuring it is secure, efficient, and ready for future demands.

Key Responsibilities
1. Boundary Health, Risk & Cross-Functional Stewardship

  • Holistic Boundary Ownership: Serve as the single point of accountability for the overall health and compliance status of the assigned boundary.
  • Risk Aggregation and Mitigation: Identify, document, and socialize systemic, long-term risks related to architecture, technical debt, and control decay within your specific boundary.
  • System Health & Security Posture: Define and monitor long-term health metrics for the boundary, integrating data from SOC rules, Vulnerability Management, Incident Response, and Configuration Management to assess overall systemic risk.
  • Compliance Control Assurance: Ensure all compliance controls relevant to the boundary (e.g., NIST 800-53 controls) are implemented, continuously monitored, and architecturally sustainable.
  • Compliance Artifact Tracking: Track, prioritize and raise exceptions for the creation, maintenance, and audit readiness of all necessary compliance artifacts for the assigned boundary (e.g., System Security Plan (SSP), POA&Ms, Control Implementation Details).

2. Future-Proofing & Strategic Planning

  • AI and New SKU Readiness: Proactively assess the impact of Artificial Intelligence (AI) features, machine learning models, and new Product SKUs coming into the environment. Define the necessary architectural modifications and compliance controls to safely and securely integrate these future capabilities into the boundary.
  • Vulnerability Trajectory Ownership: Own the strategic direction for reducing the long-term vulnerability surface area within the boundary, guiding functional teams on architectural dependencies and risk prioritization unique to your system.
  • Cloud Cost Efficiency: Collaborate with the Engineering team to analyze and optimize cloud infrastructure costs within the boundary, ensuring security requirements are met in the most fiscally responsible manner.
  • Core Workday Product and Technology: Interface with core Workday engineering and product teams as well as Security teams to ensure base product capabilities are designed to be compliant and deployable within your restricted government environment.

About You

Basic Qualifications

  • 7+ years of experience in Security Engineering, Security Architecture, or a Compliance-focused role within a cloud or SaaS environment.
  • 5+ years of direct experience with U.S. Government compliance frameworks such as FedRAMP (Moderate/High), DoD IL4/IL5/IL6, NIST RMF, or ICD-503.
  • Proven ability to own and drive large-scale, multi-year architectural and security roadmaps for a single, complex system.
  • Deep understanding of cloud architecture AWS, Azure, GCP and how security controls are implemented at scale.
  • Experience integrating future technologies (e.g., AI/ML systems) into regulated, high-security environments.
  • Excellent communication skills with the ability to articulate complex, multi-faceted technical risk across all domains (architecture, operations, cost) to executive leadership.


Workday Pay Transparency Statement

The annualized base salary ranges for the primary location and any additional locations are listed below. Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate's compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday's comprehensive benefits, please click here.

Primary Location: USA.VA.Reston


Primary Location Base Pay Range: $144,500 USD - $216,700 USD


Additional US Location(s) Base Pay Range: $130,700 USD - $232,200 USD


Our Approach to Flexible Work

With Flex Work, we're combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.

Pursuant to applicable Fair Chance law, Workday will consider for employment qualified applicants with arrest and conviction records.

Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.


At Workday, we are committed to providing an accessible and inclusive hiring experience where all candidates can fully demonstrate their skills. If you require assistance or an accommodation at any point, please email accommodations@workday.com.

Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!

At Workday, we value our candidates' privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers.

Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.

In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.


Workday logo

About Workday

Sourced by ZipRecruiter

Workday's journey began with a transformative idea generated during a breakfast conversation between its founders in sunny California. What set us apart from the start was our people-centric culture, driven by the core value of prioritizing our employees. At Workday, the happiness, growth, and contributions of every team member are at the heart of who we are. Our collaborative and employee-focused culture is the key ingredient for our business success. We not only care for our people but also for the communities and the environment, all while maintaining profitability. Embrace your uniqueness, as we encourage our Workmates to shine brightly in their authentic selves. Our passion and energy make us distinct, and we are inspired to create a brighter workday for everyone.

Industry

Software development

Company size

10,000+ Employees

Headquarters location

Pleasanton, CA, US

Year founded

2005