2

Full Time Cyber Security Grc Jobs (NOW HIRING)

... Bison GRC tool (and other designated repositories), and communicates clearly in English using ... Full time benefits include Medical, Dental, Vision, 401K and other possible benefits as provided.

Addison, TX (Hybrid - 2-4 days onsite, 4 days preferred*) Employment Type: Full-Time Position ... Bachelor's degree in Information Systems, Cybersecurity, Computer Science, Business, or a related ...

Sys Administrator Schedule: Full-Time Shift: Day Job Travel: Yes - 10% of the time Minimum ... Coordinate with cybersecurity, network, and GRC teams to ensure ongoing compliance with internal ...

Clemmons,NC Job Type: Full-time Department: Information Security / Risk & Compliance Reports To ... Bachelor's degree in Accounting, Information Systems, Cybersecurity, or related field. * 3-6 years ...

GRC Engineer Department: Engineering Employment Type: Full Time Location: Remote Reporting To ... Conduct cybersecurity risk assessments, including third-party/vendor risk evaluations, with an ...

... and cybersecurity governance, along with demonstrated leadership in driving enterprise-wide ... Applicants must be currently authorized to work in the United States on a full-time basis without ...

Clemmons, NC Job Type: Full-time Department: Information Security / Risk & Compliance Reports To ... Bachelor's degree in Accounting, Information Systems, Cybersecurity, or related field. * 3-6 years ...

... and cybersecurity governance, along with demonstrated leadership in driving enterprise-wide ... Applicants must be currently authorized to work in the United States on a full-time basis without ...

GRC Engineer

Foster City, CA ยท On-site

$210K - $320K/yr

You will operate the Cybersecurity Risk Register . You will be responsible for identifying ... This is a full-time role that can be held from our Foster City, CA office. The role has an in ...

Showing results 21-40

Full Time Cyber Security Grc information

See salary details

$40.5K

$122.9K

$180K

How much do full time cyber security grc jobs pay per year?

As of Aug 11, 2026, the average yearly pay for full time cyber security grc in the United States is $122,890.00, according to ZipRecruiter salary data. Most workers in this role earn between $102,000.00 and $142,000.00 per year, depending on experience, location, and employer.

What are the typical challenges faced by professionals in a full time Cyber Security GRC role, and how can they be addressed?

Professionals in full-time Cyber Security GRC (Governance, Risk, and Compliance) roles often face the challenge of keeping up with constantly evolving regulatory requirements and cyber threats. Balancing the needs of compliance with practical risk management can be complex, especially when collaborating with technical teams and business stakeholders. To address these challenges, strong communication skills, continuous learning, and staying updated with industry frameworks are essential. Many organizations support this by encouraging cross-departmental collaboration and providing opportunities for professional development.

What is the difference between Full Time Cyber Security Grc vs Cyber Security Analyst?

AspectFull Time Cyber Security GrcCyber Security Analyst
CertificationsISO 27001, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, compliance, risk managementThreat detection, incident response, system monitoring
Employer & Industry UsageOrganizations focusing on governance and complianceOrganizations focusing on security operations and analysis

Full Time Cyber Security Grc roles primarily focus on governance, risk management, and compliance activities, requiring certifications like ISO 27001 and CISA. Cyber Security Analysts concentrate on monitoring security threats and responding to incidents, often holding certifications like Security+ or CEH. While Grc roles emphasize policy and compliance, Analysts are more involved in technical threat detection. Both roles are essential in a comprehensive cybersecurity strategy but differ in daily tasks and focus areas.

What is a full time Cyber Security GRC professional?

Full Time Cyber Security GRC (Governance, Risk, and Compliance) professionals are experts who help organizations identify, assess, and manage cybersecurity risks in alignment with regulatory requirements and internal policies. They develop and implement frameworks, policies, and procedures to ensure the organization's digital information is protected and compliant with laws and standards. Their work often includes conducting risk assessments, monitoring compliance, and advising on best practices to mitigate cybersecurity threats. These professionals play a crucial role in maintaining an organization's security posture and ensuring data integrity across all systems.

What are the key skills and qualifications needed to thrive as a full time Cyber Security GRC professional?

To thrive as a Full Time Cyber Security GRC (Governance, Risk, and Compliance) professional, you need a solid understanding of information security principles, risk management frameworks, and regulatory requirements, often demonstrated by a relevant degree and certifications like CISSP or CISA. Familiarity with tools such as GRC platforms (e.g., RSA Archer), risk assessment software, and compliance management systems is typical for this role. Strong analytical thinking, attention to detail, effective communication, and stakeholder management set exceptional professionals apart. These skills ensure that organizations can identify risks, maintain compliance, and build robust security postures in an evolving threat landscape.
More about Full Time Cyber Security Grc jobs
What cities are hiring for Full Time Cyber Security Grc jobs? Cities with the most Full Time Cyber Security Grc job openings:
What are the most commonly searched types of Cyber Security Grc jobs? The most popular types of Cyber Security Grc jobs are:
What states have the most Full Time Cyber Security Grc jobs? States with the most job openings for Full Time Cyber Security Grc jobs include:
Infographic showing various Full Time Cyber Security Grc job openings in the United States as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $122,890 per year, or $59.1 per hour.

Cyber Security Engineer III

Cherokee Federal

Denver, CO โ€ข On-site

Full-time

Medical, Dental, Vision, Retirement

Posted 19 days ago


Job description


Cyber Security Engineer III
The Cyber Security Engineer III supports Reclamation IT systems and performs security and privacy tasks aligned to NIST SP 800-37 Rev. 2 (RMF) and task order requirements. Work is executed during the period of performance and is reviewed weekly for completeness of tasks and objectives. The ISSO receives direct or indirect technical direction from the COR and/or TSAL. The ISSO produces and maintains government-required cybersecurity and privacy documentation, keeps system records current in the Bison GRC tool (and other designated repositories), and communicates clearly in English using Reclamation-approved terms and formats. All deliverables are Government property and are stored electronically on designated network drives.
Compensation & Benefits:
Estimated Starting Salary Range for Cyber Security Engineer III: TBD
Pay commensurate with experience.
Full time benefits include Medical, Dental, Vision, 401K and other possible benefits as provided. Benefits are subject to change with or without notice.
Cyber Security Engineer III Responsibilities Include:
  • Maintain the operational cybersecurity posture for assigned IT systems and advise system owners and the Enterprise ISSM on risk, changes, and security status.
  • Execute RMF/ATO (A&A) activities for assigned systems, including required documentation, assessments, and ongoing compliance tasks.
  • Develop, update, and maintain the System Security and Privacy Plan (SSPP) and all supporting artifacts, to include (as applicable): configuration management, contingency planning and after-action reporting, continuous monitoring, incident response plans/contact lists and after-action reporting, interconnection security agreements, POA&Ms, privacy artifacts (PTA/PIA), risk assessments, control baselines and inheritance, security/business impact analyses, control implementation statements, technical/system narratives, inventories, network/system boundary diagrams, supply chain risk management documentation, and SaaS attestations/workbooks.
  • Perform continuous monitoring of security controls, including tracking Reclamation-defined metrics, reviewing audit logs, identifying/responding to vulnerabilities, and addressing Organizational Assessment (OA) metrics.
  • Conduct technical vulnerability assessments; prioritize, track, and validate remediation activities with technical teams.
  • Manage the POA&M lifecycle: create POA&Ms for newly identified weaknesses, coordinate milestones/dates with technical staff, and update POA&Ms in Bison GRC (at least monthly for audit-related POA&Ms and quarterly for all others). Collect evidence and complete WCVFs when closing POA&Ms or pursuing risk acceptance.
  • Support and participate in incident response activities for assigned systems.
  • Participate in contingency, recovery, and incident response training and tests; produce/maintain related evidence and after-action documentation.
  • Perform cybersecurity impact analysis for system changes and support change control by reviewing change requests, identifying security impacts, approving/denying as required, ensuring procedures are followed, and updating hardware/software inventories.
  • Conduct cybersecurity impact reviews for new software requests.
  • Execute annual assurance/assessment tasks: update FISMA/RMF documentation on required schedules, perform Internal Control Reviews (ICRs), and ensure control tailoring remains aligned with the applicable baseline.
  • Participate in security assessments and audits; provide required access, documentation, and system information to assessors/auditors.
  • Develop and maintain system standard operating procedures (SOPs) aligned to security control requirements.
  • Provide Quarterly Cybersecurity Briefings to System Owners for assigned systems.
  • Support federal staff by providing expertise/training to Reclamation ISSOs and advising on RMF requirements for new systems or significant changes before production deployment.
  • Provide technical cybersecurity input across operational projects throughout the SDLC.
  • Deliver documentation for all assigned tasks/projects; keep content current, accurate, compliant with current standards, and maintained in approved formats and repositories (including Bison GRC).

Minimum Requirements
  • Bachelor's Degree in Cyber Security, MIS, IT or similar Information Technology degree
  • Demonstrated ISSO (or equivalent) experience performing FISMA/RMF activities aligned to NIST SP 800-37 Rev. 2, including A&A/ATO support and continuous monitoring.
  • Proven ability to develop and maintain SSPP/SSP and related system security/privacy documentation (e.g., contingency, incident response, configuration management, continuous monitoring, risk assessments, inventories, diagrams, POA&M).
  • Experience performing control monitoring, vulnerability review/triage, remediation tracking, and audit support.
  • Working knowledge of federal privacy requirements, including PTA/PIA and PII protection.
  • Strong written and verbal communication skills; ability to brief system owners and security leadership on cybersecurity posture and risk.
  • Experience drafting policies, procedures, standards, SOPs, and instructional materials.
  • Experience working effectively in a civilian federal government environment and with interagency stakeholders.
  • Ability to follow government documentation standards, maintain records in designated repositories, and deliver weekly/recurring status-driven outputs.

Preferred Qualifications
  • Experience implementing RMF for cloud-hosted systems and/or SaaS solutions, including SaaS attestation artifacts.
  • Experience using Bison GRC, Xacta 360, or similar GRC platforms to manage controls, evidence, and POA&Ms under continuous monitoring.
  • Knowledge/experience with GIS environments.
  • Knowledge/experience supporting Operational Technology (OT) systems.
  • Certifications: CISSP, CISM, and/or CAP.
  • Mut pass pre-employment requirements of Cherokee Federal.

Company Information:
Cherokee Nation System Solutions (CNSS) is a part of Cherokee Federal - the division of tribally owned federal contracting companies owned by Cherokee Nation Businesses. As a trusted partner for more than 60 federal clients, Cherokee Federal LLCs are focused on building a brighter future, solving complex challenges, and serving the government's mission with compassion and heart. To learn more about CNSS, visit cherokee-federal.com.
#CherokeeFederal #LI-IG
Cherokee Federal is a military friendly employer. Veterans and active military transitioning to civilian status are encouraged to apply.
Legal Disclaimer: Cherokee Federal is an equal opportunity employer. Please visit cherokee-federal.com/careers for information regarding our Affirmative Action and Equal Opportunity Employer Statement, and Accommodation request.
Many of our job openings require access to government buildings or military installations. Candidates must pass pre-employment qualifications of Cherokee Federal.
Please Note:This position is pending a contract award.If you are interested in a future with Cherokee Federal, APPLY TODAY!Although this is not an approved position, we are accepting applications for this future and anticipated need.

Cherokee Federal logo

About Cherokee Federal

Sourced by ZipRecruiter

Cherokee Federal - a division of Cherokee Nation Businesses - is a team of tribally owned federal contracting companies focused on building solutions, solving complex challenges, and serving the nation's mission around the globe for more than 60 federal clients. Our team of companies manages nearly 1,000 projects of all sizes across the construction, consulting, engineering and manufacturing, health, and technology portfolios. Since 2012, the Cherokee Federal team of companies has won more than $5 billion in government contracts. Our 3,000+ employees work in 26 countries, 50 states and 2 U.S. territories. Why choose Cherokee Federal? Visit our website and learn about the great reasons to join our team. cherokee-federal.com

Industry

Architectural services

Company size

1,001 - 5,000 Employees

Headquarters location

Tulsa, OK, US

Year founded

1969

Social media