1

Cybersecurity Governance Risk Compliance Jobs in Springfield, OH

Site Cyber Security Leader

Dayton, OH

$107K - $145K/yr

Lead site governance, risk management, compliance, and cybersecurity assessment activities. * Ensure sustainable execution of cybersecurity programs and regulatory requirements. Build a Strong ...

Overview Cybersecurity (ISSM) LOCATION: WPAFB, Dayton, OH JOB STATUS: Full-Time CLEARANCE: Top ... in Governance, Risk, & Compliance) and it is highly recommended to have CISSP (Certified ...

Overview Cybersecurity (ISSM) LOCATION: WPAFB, Dayton, OH JOB STATUS: Full-Time CLEARANCE: Top ... in Governance, Risk, & Compliance) and it is highly recommended to have CISSP (Certified ...

DevSecOps Engineer

Kettering, OH ยท On-site

$160K - $175K/yr

... Governance Risk & Compliance, Oracle Discoverer, User Productivity Kit, Service Oriented ... Monitor and evaluate the impact of software, hardware, network, and Cybersecurity design changes ...

... Governance Risk & Compliance, Oracle Discoverer, User Productivity Kit, Service Oriented ... Monitor and evaluate the impact of software, hardware, network and Cybersecurity design changes ...

Cyber Data Protection/PKI Manager

Dayton, OH ยท On-site

$107K - $145K/yr

... governance, and risk assessments. Qualifications Required: * Bachelor's degree in Cybersecurity ... and compliance monitoring programs * Strong client leadership skills, including executive ...

Experience with RSA Archer or other governance, risk, and compliance platforms, including migration ... Master's degree in Computer Science, Cyber Security, Information Security, Engineering, or ...

next page

Showing results 1-20

Cybersecurity Governance Risk Compliance information

See Springfield, OH salary details

$20.7K

$102.4K

$135.6K

How much do cybersecurity governance risk compliance jobs pay per year?

As of Aug 4, 2026, the average yearly pay for cybersecurity governance risk compliance in Springfield, OH is $102,418.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,100.00 and $116,200.00 per year, depending on experience, location, and employer.

What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?

AspectCybersecurity Governance Risk ComplianceCybersecurity Analyst
CertificationsCISA, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, audits, compliance frameworksMonitoring security systems, incident response
Employer & Industry UsageOrganizations with compliance needs, regulatory bodiesIT security teams, cybersecurity firms

While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What are the key skills and qualifications needed to thrive as a cybersecurity governance, risk, and compliance (GRC) professional?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of information security frameworks, risk management principles, and regulatory compliance, often supported by a degree in cybersecurity or related fields. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow), and certifications such as CISSP, CISM, or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you interpret regulations and collaborate with stakeholders. These skills ensure organizations can manage cybersecurity risks proactively while meeting regulatory and industry standards.

What are some typical challenges faced by professionals in cybersecurity governance, risk, and compliance (GRC) roles?

Professionals in Cybersecurity GRC roles often navigate the challenge of keeping up with rapidly changing regulatory requirements while ensuring company policies align with both business objectives and security best practices. Balancing the need for robust security controls with operational efficiency, educating non-technical stakeholders about risk, and managing audits are common aspects of the job. Additionally, GRC professionals frequently collaborate with IT, legal, and business teams to ensure a cohesive approach to risk management and compliance. This dynamic environment requires strong communication skills, adaptability, and a commitment to continuous learning.

Is cybersecurity governance risk compliance a good career?

Cybersecurity Governance, Risk, and Compliance (GRC) is a growing field that offers opportunities in managing organizational security policies, risk assessments, and regulatory compliance. It requires knowledge of security frameworks, certifications like CISSP or CISM, and strong analytical skills. The role is in demand across various industries due to increasing cybersecurity threats and regulatory requirements.

Is cybersecurity governance risk compliance a good job?

Cybersecurity Governance, Risk, and Compliance (GRC) roles are in high demand due to increasing cybersecurity threats and regulatory requirements. These jobs typically require knowledge of security frameworks, risk management, and compliance standards, offering opportunities for career growth and specialization. They often involve collaboration across departments and may require certifications like CISSP or CISA.

What is cybersecurity governance, risk, and compliance (GRC)?

Cybersecurity Governance, Risk, and Compliance (GRC) refers to a framework used by organizations to align their IT and security strategies with business objectives, manage risks, and ensure compliance with laws and regulations. Governance involves setting policies and procedures, risk focuses on identifying and addressing threats, and compliance ensures adherence to required standards. Professionals in this field help organizations protect sensitive data, avoid regulatory penalties, and build trust with stakeholders. GRC is essential for maintaining effective cybersecurity and demonstrating due diligence.
What job categories do people searching Cybersecurity Governance Risk Compliance jobs in Springfield, OH look for? The top searched job categories for Cybersecurity Governance Risk Compliance jobs in Springfield, OH are:
What cities near Springfield, OH are hiring for Cybersecurity Governance Risk Compliance jobs? Cities near Springfield, OH with the most Cybersecurity Governance Risk Compliance job openings:
Infographic showing various Cybersecurity Governance Risk Compliance job openings in Springfield, OH as of June 2026, with employment types broken down into 98% Full Time, and 2% Part Time. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $102,418 per year, or $49.2 per hour.

Governance, Risk & Compliance (GRC) Manager

Riverside Research Institute

Beavercreek, OH โ€ข On-site

Other

Posted 25 days ago


Job description

Riverside OverviewRiverside Research is an independent National Security Nonprofit dedicated to research and development in the national interest. We provide high-end technical services, research and development, and prototype solutions to some of the country's most challenging technical problems. ย  ย All Riverside Research opportunities require U.S. Citizenship. ย Position Overview

The Manager, Governance, Risk & Compliance (GRC) leads Riverside Research's Governance, Risk, and Compliance program supporting the organization's unclassified enterprise and research information systems. Reporting to the Director of Information Security, this position is responsible for maintaining and continuously maturing Riverside's cybersecurity governance framework, enterprise risk management program, and regulatory compliance initiatives.

This role serves as both a people leader and technical contributor, providing leadership for a team of GRC professionals while partnering across Information Security, Information Technology, Contracts, Human Resources, Finance, Legal, and Business Operations to ensure cybersecurity and compliance objectives align with organizational and customer requirements.

The Manager owns Riverside's Cybersecurity Maturity Model Certification (CMMC) program, leading continuous readiness activities, regulatory assessments, governance initiatives, and enterprise risk management efforts to maintain the organization's strong cybersecurity posture and support Department of Defense mission requirements.

Responsibilities
  • Lead Riverside Research's Governance, Risk, and Compliance (GRC) program supporting the enterprise cybersecurity strategy, governance framework, and compliance objectives.
  • Own Riverside's Cybersecurity Maturity Model Certification (CMMC) program, ensuring continuous readiness for annual affirmations and Certified Third-Party Assessment Organization (C3PAO) assessments.
  • Lead and mentor a team of GRC Analysts, establishing priorities, developing staff, and fostering a culture of accountability, collaboration, and continuous improvement.
  • Develop, maintain, and govern enterprise cybersecurity policies, standards, procedures, and supporting documentation.
  • Lead Riverside's Enterprise Risk Management (ERM) program by facilitating risk identification, assessment, mitigation planning, and executive reporting.
  • Drive continuous monitoring activities through operational oversight, technical auditing, internal control assessments, and compliance reviews to ensure adherence to regulatory, contractual, and organizational security requirements.
  • Manage corrective action plans, findings, Plans of Action & Milestones (POA&Ms), and remediation activities through closure.
  • Provide governance oversight for cybersecurity programs including identity and access management, vulnerability management, configuration management, incident response, security awareness, external information sharing, third-party risk management, and data protection.
  • Partner with Information Technology and Information Security teams to ensure enterprise architecture and technology solutions align with cybersecurity strategy, regulatory requirements, and organizational risk tolerance.
  • Maintain awareness of evolving FAR, DFARS, CMMC, NIST, and Department of Defense cybersecurity requirements, advising leadership on regulatory changes and organizational impacts.
  • Develop executive dashboards, metrics, and reports that communicate cybersecurity posture, enterprise risk, and compliance status to senior leadership.
  • Collaborate with business stakeholders including Contracts, Human Resources, Finance, Legal, Marketing, and Business Operations to integrate cybersecurity governance into business processes.
  • Serve as a trusted advisor to leadership by translating cybersecurity, compliance, and enterprise risk into actionable business recommendations.
QualificationsRequired Qualifications
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, Business, or a related discipline.
  • Twelve (12) years of progressively responsible experience in cybersecurity, information assurance, governance, risk, compliance, or related disciplines, including at least three (3) years of leadership experience managing technical teams or enterprise cybersecurity programs.
  • Demonstrated success leading external security assessments, regulatory audits, or certification efforts within a regulated industry such as the Defense Industrial Base, government contracting, financial services, healthcare, or telecommunications.
  • Strong knowledge of Cybersecurity Maturity Model Certification (CMMC), NIST SP 800-171, Department of Defense Controlled Unclassified Information (CUI) requirements, and applicable FAR and DFARS cybersecurity clauses.
  • Experience developing and maintaining cybersecurity governance programs, policies, standards, and enterprise compliance initiatives.
  • Strong understanding of enterprise information technology including Microsoft 365, Microsoft Entra ID, Microsoft Azure, Amazon Web Services (AWS), virtualization, and hybrid infrastructure.
  • Excellent written, verbal, and presentation skills with the ability to communicate complex technical concepts to executive leadership and non-technical stakeholders.
  • Demonstrated ability to lead cross-functional initiatives, influence organizational change, and build collaborative relationships across multiple business functions.
  • Must live or relocate to a commutable distance of Beavercreek, Ohio

Preferred Qualifications
  • Experience maintaining a certified CMMC Level 2 environment.
  • Experience leading Certified Third-Party Assessment Organization (C3PAO) assessments and/or DIBCAC assessments.
  • Experience leading Enterprise Risk Management (ERM) programs.
  • Experience with cloud security, Data Loss Prevention (DLP), Third-Party Risk Management, Cyber Supply Chain Risk Management (C-SCRM).
  • Industry certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified in Governance, Risk and Compliance (CGRC), or Certified Cloud Security Professional (CCSP).
Global Comp$140,000- $170,000 This represents the typical compensation range for this position based on experience, location and other factors.Closing Statementย  Riverside Research Institute is a not-for-profit, technology-oriented defense company, where service to our customers and support of our staff is our overall mission. Riverside is an affirmative action-equal opportunity employer and complies with all applicable federal, state, and local laws regarding recruitment and hiring.ย  Riverside offers comprehensive compensation and benefit packages to our employees. Riverside bases its employment decisions solely on technical experience, qualifications and other job-related criteria related to our organizational purpose as a not-for-profit company, and without regard to race, color, religion, age, sex marital status, sexual orientation, national origin, physical or mental disability, veteran's status or any other status legally protected by applicable federal, state, and local law.Employment Type: OTHER