The Director, Federal Security Governance, Risk & Compliance (SGRC) serves as the senior accountable lead for the SGRC pillar. This role drives the strategy, risk governance, regulatory compliance ...
The Director, Federal Security Governance, Risk & Compliance (SGRC) serves as the senior accountable lead for the SGRC pillar. This role drives the strategy, risk governance, regulatory compliance ...
Information Governance Compliance Analyst
Washington, DC · On-site
$106K - $107K/yr
Overview The Information Governance Compliance Analyst supports the firm's Information Governance program with a focus on compliance, risk mitigation, data lifecycle management, and IG operational ...
Information Governance Compliance Analyst
Washington, DC · On-site
$106K - $107K/yr
Overview The Information Governance Compliance Analyst supports the firm's Information Governance program with a focus on compliance, risk mitigation, data lifecycle management, and IG operational ...
Information Governance Compliance Analyst
Washington, DC · On-site
$106K - $107K/yr
Overview The Information Governance Compliance Analyst supports the firm's Information Governance program with a focus on compliance, risk mitigation, data lifecycle management, and IG operational ...
Information Governance Compliance Analyst
Washington, DC · On-site
$106K - $107K/yr
Overview The Information Governance Compliance Analyst supports the firm's Information Governance program with a focus on compliance, risk mitigation, data lifecycle management, and IG operational ...
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$100 - $130/hr
Mobility Global is developing and building its third‑party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head ...
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$100 - $130/hr
Mobility Global is developing and building its third‑party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head ...
Information Governance Compliance Analyst
$106K - $107K/yr
The Information Governance Compliance Analyst supports the firm's Information Governance program with a focus on compliance, risk mitigation, data lifecycle management, and IG operational support for ...
Information Governance Compliance Analyst
$106K - $107K/yr
The Information Governance Compliance Analyst supports the firm's Information Governance program with a focus on compliance, risk mitigation, data lifecycle management, and IG operational support for ...
Governance, Risk, and Compliance Engineer
Washington, DC · On-site +1
$120K - $135K/yr
P. is seeking a highly skilled Governance, Risk, and Compliance (GRC) Engineer with expertise in Microsoft Purview to provide technical leadership and subject-matter expertise for our firm's data ...
Governance, Risk, and Compliance Engineer
Washington, DC · On-site +1
$120K - $135K/yr
P. is seeking a highly skilled Governance, Risk, and Compliance (GRC) Engineer with expertise in Microsoft Purview to provide technical leadership and subject-matter expertise for our firm's data ...
Security Governance Risk & Compliance (GRC) Analyst with Security Clearance
Washington, DC · On-site
$130K - $170K/yr
As a Security Governance Risk & Compliance (GRC) Analyst, your responsibilities will include: * Manage and implement complex controls frameworks for large systems, consisting of Cloud infrastructure ...
Security Governance Risk & Compliance (GRC) Analyst with Security Clearance
Washington, DC · On-site
$130K - $170K/yr
As a Security Governance Risk & Compliance (GRC) Analyst, your responsibilities will include: * Manage and implement complex controls frameworks for large systems, consisting of Cloud infrastructure ...
AI Governance Coordinator
Baltimore, MD · On-site
$43.94/hr
... teams (Risk, Compliance, Privacy, Information Security) to ensure AI governance activities align with enterprise control frameworks. • Draft communications, mitigation plans, follow-up ...
AI Governance Coordinator
Baltimore, MD · On-site
$43.94/hr
... teams (Risk, Compliance, Privacy, Information Security) to ensure AI governance activities align with enterprise control frameworks. • Draft communications, mitigation plans, follow-up ...
AI Governance Coordinator
Baltimore, MD · Remote
$43.94/hr
Partner with control function teams (Risk, Compliance, Privacy, Information Security) to ensure AI governance activities align with enterprise control frameworks. * Draft communications, mitigation ...
Quick apply
AI Governance Coordinator
Baltimore, MD · Remote
$43.94/hr
Partner with control function teams (Risk, Compliance, Privacy, Information Security) to ensure AI governance activities align with enterprise control frameworks. * Draft communications, mitigation ...
AI Governance Coordinator
Baltimore, MD · Remote
$43.94/hr
Partner with control function teams (Risk, Compliance, Privacy, Information Security) to ensure AI governance activities align with enterprise control frameworks. * Draft communications, mitigation ...
Quick apply
AI Governance Coordinator
Baltimore, MD · Remote
$43.94/hr
Partner with control function teams (Risk, Compliance, Privacy, Information Security) to ensure AI governance activities align with enterprise control frameworks. * Draft communications, mitigation ...
AI Governance Coordinator
Baltimore, MD · Remote
$43.94/hr
Partner with control function teams (Risk, Compliance, Privacy, Information Security) to ensure AI governance activities align with enterprise control frameworks. * Draft communications, mitigation ...
Quick apply
AI Governance Coordinator
Baltimore, MD · Remote
$43.94/hr
Partner with control function teams (Risk, Compliance, Privacy, Information Security) to ensure AI governance activities align with enterprise control frameworks. * Draft communications, mitigation ...
Principal Information Security Engineer - Governance, Risk & Security Awareness
Springfield, VA · On-site +1
Principal Information Security Engineer - Governance, Risk & Security Awareness The Principal ... Review security questionnaires, SOC reports, penetration test results, compliance certifications ...
Principal Information Security Engineer - Governance, Risk & Security Awareness
Springfield, VA · On-site +1
Principal Information Security Engineer - Governance, Risk & Security Awareness The Principal ... Review security questionnaires, SOC reports, penetration test results, compliance certifications ...
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
Quick apply
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
Quick apply
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
Quick apply
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
Quick apply
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
Quick apply
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
Quick apply
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
The Counsel, AI Risk & Compliance serve at the intersection of legal, technology, risk management ... This role guides the evaluation, deployment, and governance of artificial intelligence tools and ...
The Counsel, AI Risk & Compliance serve at the intersection of legal, technology, risk management ... This role guides the evaluation, deployment, and governance of artificial intelligence tools and ...
Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Manager
Washington, DC · On-site
$124K - $280K/yr
... governance objectives - Promoting a culture of compliance and ethical behavior through training and development initiatives What You Must Have - At least a Bachelor's degree - At least 7 years of ...
Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Manager
Washington, DC · On-site
$124K - $280K/yr
... governance objectives - Promoting a culture of compliance and ethical behavior through training and development initiatives What You Must Have - At least a Bachelor's degree - At least 7 years of ...
Governance Risk And Compliance information
See Silver Spring, MD salary details
$102.3K - $129.1K
1% of jobs
$129.1K - $155.9K
21% of jobs
$178.2K is the 25th percentile. Wages below this are outliers.
$155.9K - $182.7K
3% of jobs
The median wage is $191.9K / yr.
$182.7K - $209.5K
71% of jobs
$209.5K - $236.3K
0% of jobs
$236.3K - $263K
3% of jobs
$263K - $289.8K
0% of jobs
$289.8K - $316.6K
0% of jobs
$316.6K - $343.4K
0% of jobs
$343.4K - $370.2K
0% of jobs
$370.2K - $397K
0% of jobs
$102.3K
$198.2K
$397K
How much do governance risk and compliance jobs pay per year?
What are governance risk and compliance roles?
What are the key skills and qualifications needed to thrive as a governance risk and compliance professional?
What are some common challenges faced by professionals in governance risk and compliance roles, and how can they be addressed?
What is the difference between Governance Risk And Compliance vs Compliance Analyst?
| Aspect | Governance Risk And Compliance | Compliance Analyst |
|---|---|---|
| Certifications | ISO 31000, ISO 27001, Certified Risk Management Professional | Certified Compliance & Ethics Professional (CCEP), ISO 19600 |
| Work Environment | Corporate, regulated industries, risk management departments | Legal, audit, compliance departments within organizations |
| Employer & Industry Usage | Financial services, healthcare, energy, government | Financial institutions, healthcare, manufacturing, retail |
Governance Risk And Compliance professionals focus on establishing frameworks, managing risks, and ensuring overall compliance strategies across organizations. Compliance Analysts primarily focus on implementing and monitoring specific compliance policies, often within legal or audit teams. While both roles require understanding regulations and certifications, Governance Risk And Compliance roles have a broader scope involving risk management and governance structures.
Is governance risk and compliance a good career?
What is the work of governance risk and compliance?
What are popular job titles related to Governance Risk And Compliance jobs in Silver Spring, MD?
For Governance Risk And Compliance jobs in Silver Spring, MD, the most frequently searched job titles are:
What job categories do people searching Governance Risk And Compliance jobs in Silver Spring, MD look for?
The top searched job categories for Governance Risk And Compliance jobs in Silver Spring, MD are:
What cities near Silver Spring, MD are hiring for Governance Risk And Compliance jobs?
Cities near Silver Spring, MD with the most Governance Risk And Compliance job openings:

Full-time
Medical, Dental, Vision, Retirement, PTO
Posted 23 days ago
Key responsibilities
Lead the Federal GRC strategy, roadmap, governance, and control maturity initiatives across BCG Federal.
Oversee enterprise compliance efforts supporting federal cybersecurity frameworks such as CMMC Level 2, NIST SP 800-171/53, FedRAMP, and AI governance.
Manage organizational readiness for federal assessments, including scope, documentation, evidence, audit defense, and stakeholder preparation.
Boston Consulting Group rating
9.5
Based on 16 frontline employees who took The Breakroom Quiz
3rd of 72 rated business consultants
Job description
Locations: Boston | Washington
Who We Are
Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact.
To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures-and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive.
What You'll Do
BCG Federal operates within a federally regulated environment supporting consulting, cloud, software, data, and emerging AI technology capabilities. The Director, Federal Security Governance, Risk & Compliance (SGRC) serves as the senior accountable lead for the SGRC pillar. This role drives the strategy, risk governance, regulatory compliance, certification readiness, and control maturity agenda across all BCG Federal offerings.
The Director leads enterprise readiness and audit defense across key federal frameworks; including CMMC Level 2, NIST SP 800-171/53, FedRAMP and DFARS. Working closely with Security Architecture, the Director translates complex regulatory requirements into policy and control objectives, establishing the governance framework while Architecture designs the technical controls and secure cloud baselines.
Furthermore, this role pioneers Federal AI Governance, establishing guardrails, risk assessment protocols, and approval pathways for Generative AI and machine learning tools deployed across federal boundaries.
YOU'RE GOOD AT
You excel at leading complex federal cybersecurity and compliance programs by combining technical GRC expertise, executive communication, organizational change management, and trusted stakeholder relationships.
YOUR DUTIES WILL INCLUDE
- Lead the Federal GRC pillar strategy, roadmap, operating model, governance rhythm, reporting structure, and control maturity agenda across BCG Federal.
- Direct enterprise compliance initiatives supporting DFARS, CMMC Level 2, NIST 800-171/, FedRAMP, AI governance, cloud security, and related federal cybersecurity requirements.
- Partner closely with Security Architecture to align policies with technical engineering; defining what control outcomes are required while Architecture designs how technical controls and baselines are configured.
- Own organizational readiness for federal assessments and certifications, including assessment scoping, SSP development, evidence preparation, stakeholder preparation, audit defense, C3PAO engagement, and executive reporting.
- Establish and mature Federal AI Governance, including risk methodologies, safety frameworks (e.g., NIST AI RMF), boundary protections, and approval pathways for secure adoption of Generative AI and LLMs.
- Own the federal risk register governance model, including risk identification, severity assessment, mitigation planning, exception management, escalation, and reporting.
- Lead cybersecurity review of federal contracts, RFPs, client opportunities, software approvals, cloud service reviews, and third-party vendor risk management to support secure technology adoption.
- Lead organizational change management for federal cybersecurity and compliance initiatives, including stakeholder alignment, communications, training, readiness tracking, and sustainment of new governance processes.
- Oversee continuous monitoring (CONMON) governance, evidence traceability, recurring review cadences, POA&M tracking, and management reporting.
- Define and deliver executive-level metrics, dashboards, QBR content, risk reporting, compliance status updates, and decision-ready materials for leadership.
- Lead, mentor, onboard, and develop GRC personnel while improving team operating rhythms, accountability, prioritization, and delivery quality.
What You'll Bring
- 10+ years of experience in cybersecurity, information security, GRC, audit, compliance, risk management, or technology governance environments.
- Demonstrated experience leading federal cybersecurity compliance programs (preferably supporting CMMC Level 2, NIST 800-171/53, FedRAMP) in consulting, cloud, SaaS, or federal contracting environments.
- Direct experience leading or materially supporting external assessments, regulatory inquiries, audit readiness efforts, C3PAO assessments, evidence preparation, and audit defense.
- Proven track record establishing AI Security Governance, evaluating machine learning/GenAI security risks, and applying federal AI risk management frameworks.
- Proven ability to partner with Security Architecture, DevSecOps, and IT engineering teams to translate complex legal and federal requirements into practical operating baselines.
- Strong organizational change management experience, including leading cross-functional process adoption, stakeholder readiness, communications, training, and sustainment of new operating models.
- Excellent written and verbal communication skills, including experience developing executive briefings, policies, audit materials, and management-level reporting.
- Ability to obtain and maintain a U.S. Government Secret Clearance where required.
Additional info
*** For US locations only ***
In the US, we have a compensation transparency approach.
Total compensation for this role includes base salary, annual discretionary performance bonus, retirement contribution, and a market leading benefits package described below.
- The base salary range for this role begins at $176,000.00 in our lowest cost US region and goes up to $199,830.00 in our highest cost US region. Your recruiting contact can share more about the specific salary range for your preferred location during the hiring process.
This is an estimated range, however, specific base salaries within the range depend on various factors such as experience and skill set. It is not common for new BCG employees to be hired at the high-end of the salary range. BCG regularly reviews its ranges to ensure market competitiveness.
In addition to your base salary, your total compensation will include a bonus of up to 30% and a generous retirement contribution that starts at 5% and moves to 10% after 2 years.
All of our plans provide best in class coverage:
Zero dollar ($0) health insurance premiums for BCG employees, spouses, and children
Low $10 (USD) copays for trips to the doctor, urgent care visits and prescriptions for generic drugs
Dental coverage, including up to $5,000 in orthodontia benefits
Vision insurance with coverage for both glasses and contact lenses annually
Reimbursement for gym memberships and other fitness activities
Fully vested Profit Sharing Retirement Fund contributions made annually, whether you contribute or not, plus the option for employees to make personal contributions to a 401(k) plan
Paid Parental Leave and other family benefits such as elective egg freezing, surrogacy, and adoption reimbursement
Generous paid time off including 12 holidays per year, an annual office closure between Christmas and New Years, and 15 vacation days per year (earned at 1.25 days per month)
Paid sick time on an as needed basis
Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws.
BCG is an E - Verify Employer. Click here for more information on E-Verify.
What Boston Consulting Group employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Boston Consulting Group
Sourced by ZipRecruiter
Industry
Business management consulting
Company size
10,000+ Employees
Headquarters location
Boston, MA, US
Year founded
1963