1

Cybersecurity Governance Risk Compliance Jobs in Silver Spring, MD

GCT Analyst

Washington, DC · On-site

$113K - $188K/yr

Experience working in cybersecurity or IT, including experience in cybersecurity governance, risk management, and compliance * Relevant cybersecurity certification (CISSP, CISM, CGRC, CISA)

Operate effectively within a technology, cybersecurity, governance, risk, and compliance environment. Support initiatives involving information security, operational risk, technology risk, regulatory ...

Showing results 41-60

Cybersecurity Governance Risk Compliance information

See Silver Spring, MD salary details

$23.8K

$117.5K

$155.6K

How much do cybersecurity governance risk compliance jobs pay per year?

As of Aug 11, 2026, the average yearly pay for cybersecurity governance risk compliance in Silver Spring, MD is $117,545.00, according to ZipRecruiter salary data. Most workers in this role earn between $103,400.00 and $133,400.00 per year, depending on experience, location, and employer.

What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?

AspectCybersecurity Governance Risk ComplianceCybersecurity Analyst
CertificationsCISA, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, audits, compliance frameworksMonitoring security systems, incident response
Employer & Industry UsageOrganizations with compliance needs, regulatory bodiesIT security teams, cybersecurity firms

While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What are the key skills and qualifications needed to thrive as a cybersecurity governance, risk, and compliance (GRC) professional?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of information security frameworks, risk management principles, and regulatory compliance, often supported by a degree in cybersecurity or related fields. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow), and certifications such as CISSP, CISM, or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you interpret regulations and collaborate with stakeholders. These skills ensure organizations can manage cybersecurity risks proactively while meeting regulatory and industry standards.

What are some typical challenges faced by professionals in cybersecurity governance, risk, and compliance (GRC) roles?

Professionals in Cybersecurity GRC roles often navigate the challenge of keeping up with rapidly changing regulatory requirements while ensuring company policies align with both business objectives and security best practices. Balancing the need for robust security controls with operational efficiency, educating non-technical stakeholders about risk, and managing audits are common aspects of the job. Additionally, GRC professionals frequently collaborate with IT, legal, and business teams to ensure a cohesive approach to risk management and compliance. This dynamic environment requires strong communication skills, adaptability, and a commitment to continuous learning.

Is cybersecurity governance risk compliance a good career?

Cybersecurity Governance, Risk, and Compliance (GRC) is a growing field that offers opportunities in managing organizational security policies, risk assessments, and regulatory compliance. It requires knowledge of security frameworks, certifications like CISSP or CISM, and strong analytical skills. The role is in demand across various industries due to increasing cybersecurity threats and regulatory requirements.

Is cybersecurity governance risk compliance a good job?

Cybersecurity Governance, Risk, and Compliance (GRC) roles are in high demand due to increasing cybersecurity threats and regulatory requirements. These jobs typically require knowledge of security frameworks, risk management, and compliance standards, offering opportunities for career growth and specialization. They often involve collaboration across departments and may require certifications like CISSP or CISA.

What is cybersecurity governance, risk, and compliance (GRC)?

Cybersecurity Governance, Risk, and Compliance (GRC) refers to a framework used by organizations to align their IT and security strategies with business objectives, manage risks, and ensure compliance with laws and regulations. Governance involves setting policies and procedures, risk focuses on identifying and addressing threats, and compliance ensures adherence to required standards. Professionals in this field help organizations protect sensitive data, avoid regulatory penalties, and build trust with stakeholders. GRC is essential for maintaining effective cybersecurity and demonstrating due diligence.
What are popular job titles related to Cybersecurity Governance Risk Compliance jobs in Silver Spring, MD? For Cybersecurity Governance Risk Compliance jobs in Silver Spring, MD, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Governance Risk Compliance jobs in Silver Spring, MD look for? The top searched job categories for Cybersecurity Governance Risk Compliance jobs in Silver Spring, MD are:
What cities near Silver Spring, MD are hiring for Cybersecurity Governance Risk Compliance jobs? Cities near Silver Spring, MD with the most Cybersecurity Governance Risk Compliance job openings:
Infographic showing various Cybersecurity Governance Risk Compliance job openings in Silver Spring, MD as of July 2026, with employment types broken down into 1% As Needed, 82% Full Time, 15% Part Time, and 2% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $117,545 per year, or $56.5 per hour.

GCT Analyst

Guidehouse

Washington, DC • On-site

$113K - $188K/yr

Full-time

Medical, Dental, Vision, Life, Retirement

Posted 19 days ago


Guidehouse rating

7.7

Company rating: 7.7 out of 10

Based on 27 frontline employees who took The Breakroom Quiz

42nd of 72 rated business consultants


Job description

Job Family:

Cyber Consulting


Travel Required:

None


Clearance Required:

Active Top Secret (TS)

What You Will Do:

Guidehouse is seeking a cybersecurity Governance, Compliance, and Training (GCT) Analyst to provide program management and product development support to a client GCT Manager. The GCT Analyst will be responsible for recommending, developing, and implementing GCT program initiatives.

Responsibilities include the following:

  • Supporting the GCT Manager with execution of the Authorizing Official's Risk Management Framework program

  • Preparing risk assessment reports and system authorization recommendations

  • Facilitating System Owner briefings to the Authorizing Official

  • Developing and updating cybersecurity policies, plans, and procedures

  • Preparing and maintaining cybersecurity governance documentation

  • Communicating cybersecurity policy and procedure updates to stakeholders

  • Implementing new cybersecurity governance processes

  • Providing compliance standard research and gap analyses

  • Advising on the implementation of federal cybersecurity compliance standards

  • Coordinating the technical implementation of cybersecurity controls with technical teams

  • Managing cybersecurity audit preparation and execution projects across the system environment

  • Analyzing and reporting on cybersecurity audit reports and remediation recommendations

  • Validating that implemented cybersecurity controls adequately address system security risk

  • Developing and implementing cybersecurity awareness and training initiatives

  • Managing GCT program projects and providing project coordination support to cybersecurity operations and network operations teams

  • Providing security impact assessments and compliance assessments to the Change Control Board

  • Regularly interfacing with system administrator, engineering, and development teams

  • Recommending GCT program initiatives to continuously improve GCT program effectiveness and integration with the operational system environment

  • Preparing and facilitating briefings to the Chief Information Security Officer and Chief Information Officer


What You Will Need:

  • An ACTIVE and MAINTAINED "TOP SECRET" Federal or DoD securityclearance

  • Bachelor's degree

  • THREE (3) years of experience in cybersecurity

  • Ability to work onsite at client site in Washington D.C. 4 days a week

  • Experience supporting customers in a client-facing environment

What Would Be Nice To Have:

  • Bachelor's degree in cybersecurity, information security, or a related field

  • Master's degree in a cybersecurity discipline

  • Experience working in cybersecurity or IT, including experience in cybersecurity governance, risk management, and compliance

  • Relevant cybersecurity certification (CISSP, CISM, CGRC, CISA)

  • Experience supporting DoD or Intelligence Community cybersecurity programs

  • Experience in cybersecurity or IT project management, including managing multiple long-term projects simultaneously

  • Experience deliberately improving program maturity

  • Experience evaluating, setting, and modifying program priorities

  • Experience leading cybersecurity compliance projects in a classified federal environment

  • Experience executing cybersecurity compliance external audits

  • Experience supporting the NIST Risk Management Framework for classified federal systems

  • Experience building new cybersecurity programs

  • Experience developing cybersecurity training products and communications

  • Experience working directly with both management and technical teams

  • Demonstrated ability to quickly grasp new technical concepts and integrate new information into existing plans and frameworks

  • Experience leading Cybersecurity Awareness Month campaigns

  • Experience leading technical teams in cybersecurity or IT settings

  • Experience interfacing with physical security and personnel security stakeholders

  • Experience coordinating multidisciplinary cybersecurity initiatives (including cybersecurity operations and cybersecurity engineering)

  • Understanding of Zero Trust architecture

  • Understanding of cybersecurity risk and governance considerations associated with emerging technologies

  • Excellent written and verbal communication, organizational, and time management skills

The annual salary range for this position is $113,000.00-$188,000.00. Compensation decisions depend on a wide range of factors, including but not limited to skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs.


What We Offer:

Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.

Benefits include:

  • Medical, Rx, Dental & Vision Insurance

  • Personal and Family Sick Time & Company Paid Holidays

  • Position may be eligible for a discretionary variable incentive bonus

  • Parental Leave and Adoption Assistance

  • 401(k) Retirement Plan

  • Basic Life & Supplemental Life

  • Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts

  • Short-Term & Long-Term Disability

  • Student Loan PayDown

  • Tuition Reimbursement, Personal Development & Learning Opportunities

  • Skills Development & Certifications

  • Employee Referral Program

  • Corporate Sponsored Events & Community Outreach

  • Emergency Back-Up Childcare Program

  • Mobility Stipend

About Guidehouse

Guidehouse is an Equal Opportunity Employer-Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.

Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.

If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.

All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.

If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse's Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant's dealings with unauthorized third parties.

Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.


What Guidehouse employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom