2

Entrylevel Governance Risk Compliance Jobs in Virginia

Audit Compliance Analyst

Richmond, VA · On-site +1

$125K/yr

Practical experience applying governance, risk, and compliance (GRC) principles * Familiarity with governance tools such as the Unified Control Framework (UCF) and SIG * Strong collaboration ...

Demonstrated professional consulting (internal or external) experience with enterprise IT-security, information security and Governance Risk Compliance services gained in previous delivery capacity.

New

Understanding of data governance frameworks (policies, standards, controls) and regulatory drivers (e.g., privacy, risk, compliance) * Experience facilitating data stewardship forums and familiarity ...

Understanding of data governance frameworks (policies, standards, controls) and regulatory drivers (e.g., privacy, risk, compliance) * Experience facilitating data stewardship forums and familiarity ...

Understanding of data governance frameworks (policies, standards, controls) and regulatory drivers (e.g., privacy, risk, compliance) * Experience facilitating data stewardship forums and familiarity ...

The IT Risk Assessor is responsible for assisting with meeting security and compliance requirements ... governance & risk teams as needed. Core tools supported by this role will be Vulnerability scanning ...

The IT Risk Assessor is responsible for assisting with meeting security and compliance requirements ... governance & risk teams as needed. Core tools supported by this role will be Vulnerability scanning ...

next page

Showing results 1-20

Entrylevel Governance Risk Compliance information

What is the difference between Entrylevel Governance Risk Compliance vs Entrylevel Internal Auditor?

AspectEntrylevel Governance Risk ComplianceEntrylevel Internal Auditor
CertificationsISO 31000, CCPA, GDPR awarenessCPA, CIA, CISA
Work EnvironmentCorporate compliance departments, risk management teamsInternal audit departments, consulting firms
Employer & Industry UsageFinancial, healthcare, manufacturingFinancial services, government, consulting

While both roles focus on organizational integrity, Entrylevel Governance Risk Compliance professionals primarily ensure adherence to regulations and manage risks, whereas Entrylevel Internal Auditors evaluate internal controls and financial accuracy. The GRC role emphasizes compliance frameworks and risk mitigation, while Internal Auditors focus on audit processes and financial integrity.

What are popular job titles related to Entrylevel Governance Risk Compliance jobs in Virginia? For Entrylevel Governance Risk Compliance jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Entrylevel Governance Risk Compliance jobs in Virginia look for? The top searched job categories for Entrylevel Governance Risk Compliance jobs in Virginia are:
What cities in Virginia are hiring for Entrylevel Governance Risk Compliance jobs? Cities in Virginia with the most Entrylevel Governance Risk Compliance job openings:
Infographic showing various Entrylevel Governance Risk Compliance job openings in Virginia as of August 2026, with employment types broken down into 100% Full Time. Highlights an 67% In-person, and 33% Hybrid job distribution.

Governance, Risk and Compliance Analyst

Babel Street

Reston, VA

Other

Medical, Dental, Vision, Life, Retirement

Posted 21 days ago


Job description

Position Summary

The Governance, Risk & Compliance (GRC) Analyst is responsible for supporting and maintaining the organization's cybersecurity governance, risk management, and compliance programs. This role works across Information Security, Engineering, Product, IT, and business stakeholders to ensure compliance with applicable regulatory, contractual, and industry security requirements. 

The GRC Analyst will assist in maintaining compliance with the NIST Cybersecurity Framework (NIST CSF), Cybersecurity Maturity Model Certification (CMMC), Cyber Essentials Plus, SOC 2, and ISO/IEC 27001 requirements through evidence collection, control monitoring, risk assessments, audit support, policy management, and remediation tracking. 

Key Responsibilities 

Compliance & Audit Management 

  • Maintain compliance programs aligned with NIST CSF, CMMC, Cyber Essentials Plus, SOC 2, and ISO/IEC 27001.
  • Coordinate internal and external audits, assessments, and attestation activities.
  • Collect, validate, and maintain compliance evidence and audit artifacts.
  • Track audit findings and remediation activities through completion.
  • Support control testing and validation to ensure ongoing compliance. 

Governance & Risk Management 

  • Conduct security risk assessments and assist with enterprise risk management activities.
  • Maintain risk registers, track mitigation plans, and monitor remediation progress.
  • Assist with development and maintenance of security policies, standards, procedures, and guidelines.
  • Monitor security and compliance control effectiveness and identify opportunities for improvement.
  • Support control mapping and crosswalk activities across multiple compliance frameworks. 

Third-Party Risk Management 

  • Perform security reviews of vendors, suppliers, and third-party service providers.
  • Track vendor assessment findings and remediation activities.
  • Support ongoing monitoring of third-party security and compliance risks. 

Customer & Regulatory Support 

  • Respond to customer security questionnaires, due diligence requests, and compliance inquiries.
  • Support sales and customer-facing teams with security documentation and assurance materials.
  • Assist with documenting compliance posture and security program maturity. 

Program Administration 

  • Maintain GRC platforms and compliance repositories.
  • Develop metrics, dashboards, and compliance reporting for management.
  • Coordinate annual security awareness, compliance, and policy review activities.
  • Support continuous improvement initiatives across the security and compliance program. 

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Security, Information Systems, Business, or related field (or equivalent experience).
  • 3+years of experience in Governance, Risk, and Compliance, Information Security, Audit, or related disciplines.
  • Working knowledge of:  
    • NIST Cybersecurity Framework (CSF)
    • CMMC
    • Cyber Essentials Plus
    • ISO/IEC 27001
    • SOC 2
    • Risk assessment methodologies
  • Experience supporting audits, assessments, or certification activities. 
  • Strong written communication, documentation, and organizational skills.
  • Ability to manage multiple priorities and deadlines in a fast-paced environment. 

Benefits at Babel Street (just to name a few...)

  • Health Benefits: Babel Street covers 85-100% monthly premium costs for Medical, Dental, Vision, Life & Disability insurances - for you and your family!
  • Retirement Plans: Babel Street offers both a Traditional and Roth 401(K) with a very competitive match.
  • Unlimited Flexible Leave: We trust our employees to manage their own time and balance their personal and work lives.
  • Holidays: Babel Street provides employees with 12 paid Federal Holidays
  • Tuition Reimbursement: We are committed to investing in our employees. One way we do that is with our Tuition Reimbursement Program for continuing education.                 

Babel Street is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. Further, Babel Street will not discriminate against applicants for inquiring about, discussing or disclosing their pay or, in certain circumstances, the pay of their coworker, Pay Transparency Nondiscrimination. In addition, Babel Street's policy is to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations and ordinances where a particular employee works. Upon request, we will provide you with more information about such accommodations.