1

Governance Risk Compliance Manager Jobs in Silver Spring, MD

GRC Engineer

Vienna, VA · On-site

$140K - $170K/yr

... compliance posture * Support vendor security reviews on both sides: evaluating vendors we onboard and participating in customer-side reviews of us Risk Management * Maintain the risk register and ...

Procurement Risk & Compliance Lead

Centreville, VA · On-site

$155K/yr

Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...

next page

Showing results 1-20

Governance Risk Compliance Manager information

See Silver Spring, MD salary details

$39.8K

$98.3K

$162.3K

How much do governance risk compliance manager jobs pay per year?

As of Jul 27, 2026, the average yearly pay for governance risk compliance manager in Silver Spring, MD is $98,315.00, according to ZipRecruiter salary data. Most workers in this role earn between $72,400.00 and $120,400.00 per year, depending on experience, location, and employer.

How does a Governance Risk Compliance (GRC) Manager typically collaborate with other departments to ensure effective risk management?

A GRC Manager works closely with various departments such as IT, legal, finance, and operations to identify, assess, and mitigate risks across the organization. This often involves facilitating cross-departmental meetings, guiding teams through compliance requirements, and ensuring that controls are implemented effectively. Strong communication and project management skills are essential, as GRC Managers must translate complex regulatory requirements into actionable steps for different teams. This collaborative approach helps ensure that risk management strategies are integrated into daily business processes and that compliance goals are met organization-wide.

What is the salary of governance risk compliance?

The salary for a Governance, Risk, and Compliance (GRC) Manager typically ranges from $80,000 to $150,000 annually, depending on experience, location, and industry. Professionals with certifications like CRISC or CISA and strong knowledge of regulatory frameworks may earn higher salaries.

Is governance risk and compliance a good career?

Governance, Risk, and Compliance (GRC) management is a growing field that involves developing policies, managing regulatory requirements, and ensuring organizational integrity. It often requires certifications like CISA or CRISC and skills in risk assessment, policy development, and compliance frameworks. The role offers stability and opportunities across various industries, making it a viable career choice for those interested in organizational governance and risk management.

What does a governance and risk manager do?

A governance and risk manager oversees an organization’s compliance with laws, regulations, and internal policies, identifying and mitigating potential risks. They develop frameworks, conduct audits, and implement controls to ensure operational integrity and reduce vulnerabilities, often using tools like risk assessment software and requiring certifications such as CRISC or ISO standards.

What is the difference between Governance Risk Compliance Manager vs Compliance Analyst?

AspectGovernance Risk Compliance ManagerCompliance Analyst
CertificationsISO 31000, CRISC, CISACCA, CCEP, or similar
Work EnvironmentStrategic, managerial, policy-focusedOperational, detail-oriented, audit-focused
Employer & Industry UsageFinancial, healthcare, corporate sectorsRegulatory agencies, corporations, consulting firms
Search & Comparison IntentUnderstanding managerial roles in governance and riskDetailing compliance procedures and analysis

The Governance Risk Compliance Manager oversees organizational policies, risk management strategies, and compliance frameworks at a strategic level. In contrast, the Compliance Analyst focuses on implementing and monitoring compliance procedures, conducting audits, and ensuring adherence to regulations. Both roles require relevant certifications and are vital in maintaining organizational integrity, but they differ in scope and responsibilities.

What does a Governance Risk Compliance (GRC) Manager do?

A Governance Risk Compliance (GRC) Manager is responsible for developing, implementing, and overseeing policies and procedures to ensure that an organization complies with regulatory requirements and manages risks effectively. They work closely with various departments to identify potential risks, ensure proper governance frameworks are in place, and monitor compliance with relevant laws and standards. GRC Managers play a key role in maintaining ethical practices, preventing legal issues, and helping organizations achieve their business objectives securely and efficiently.

What are the key skills and qualifications needed to thrive as a Governance Risk Compliance Manager, and why are they important?

To thrive as a Governance Risk Compliance Manager, you need expertise in risk assessment, regulatory frameworks, and compliance management, typically supported by a degree in business, law, or a related field. Familiarity with GRC platforms (like RSA Archer or MetricStream), internal audit tools, and relevant certifications such as CISA, CISM, or CRISC is common. Strong analytical thinking, attention to detail, and effective communication help manage complex regulations and drive organizational compliance culture. These skills ensure the organization can proactively identify risks, comply with legal requirements, and maintain operational integrity.

Is GRC an entry level job?

Governance, Risk, and Compliance (GRC) roles are typically not entry-level positions; they usually require several years of experience in compliance, risk management, or related fields. Entry-level roles in GRC may focus on supporting functions, while managerial positions often demand a strong understanding of regulations, policies, and relevant tools like GRC software. Certifications such as CISA or CRISC can also be beneficial for advancement.
What are the most commonly searched types of Governance Risk Compliance jobs in Silver Spring, MD? The most popular types of Governance Risk Compliance jobs in Silver Spring, MD are:
What are popular job titles related to Governance Risk Compliance Manager jobs in Silver Spring, MD? For Governance Risk Compliance Manager jobs in Silver Spring, MD, the most frequently searched job titles are:
What job categories do people searching Governance Risk Compliance Manager jobs in Silver Spring, MD look for? The top searched job categories for Governance Risk Compliance Manager jobs in Silver Spring, MD are:
What cities near Silver Spring, MD are hiring for Governance Risk Compliance Manager jobs? Cities near Silver Spring, MD with the most Governance Risk Compliance Manager job openings:
Information Security Governance, Risk & Compliance (GRC) Analyst

Information Security Governance, Risk & Compliance (GRC) Analyst

ASSYST, Inc.

Rockville, MD

Full-time

Posted yesterday


Job description

ASSYST is seeking an Information Security Governance, Risk & Compliance (GRC) Analyst to support our client in administering and maintaining an established enterprise Information Security Governance, Risk, and Compliance (GRC) program. This role will focus on managing Information Security Policy Exceptions and maintaining the Enterprise Information Security Risk Register using the ServiceNow Integrated Risk Management (IRM) platform.

The ideal candidate will work under the guidance of Information Security leadership to execute established governance processes, document and track information security risks, and support enterprise risk management activities. This position provides an excellent opportunity to gain hands-on experience with enterprise cybersecurity governance, information security risk management, ServiceNow IRM, and policy exception management while collaborating with experienced information security professionals.

Note: This position focuses on governance, documentation, and risk management activities. It does not involve performing security assessments, penetration testing, vulnerability assessments, audits, or compliance reviews.

Roles & Responsibilities:

  • Administer and support the Information Security Policy Exception Program.
  • Maintain and update the Enterprise Information Security Risk Register using the ServiceNow Integrated Risk Management (IRM) platform.
  • Execute established governance processes, standardized risk assessment methodologies, workflows, templates, and reporting procedures.
  • Review policy exception requests and document findings.
  • Perform information security risk analyses and provide approval or denial recommendations.
  • Document, track, and maintain identified information security risks within the enterprise Risk Register.
  • Prepare and maintain accurate policy exception tracking records.
  • Produce monthly metrics, quarterly reports, executive dashboards, and ServiceNow documentation.
  • Coordinate assigned tasks, workflows, and activities while ensuring timely completion.
  • Prepare clear and accurate technical documentation related to governance and risk management processes.
  • Collaborate with internal stakeholders to support enterprise information security governance initiatives.
  • Maintain high standards of documentation accuracy, consistency, and data integrity.
  • Provide excellent customer service while supporting governance and risk management activities.
  • Work independently while effectively managing multiple priorities and deadlines.

Required Skills & Qualifications:
Minimum Qualifications:

  • Professional experience in Information Security, IT Governance, Compliance, Risk Management, Information Technology, Audit, or a related field.
  • Basic understanding of Information Security Governance, Risk Management, and Cybersecurity principles.
  • Strong analytical and critical thinking skills.
  • Excellent written and verbal communication skills.
  • Strong organizational skills with exceptional attention to detail.
  • Ability to manage multiple priorities in a fast-paced environment.
  • Ability to quickly learn new technologies and business processes.
  • Demonstrated professionalism and ability to work independently.

Preferred Qualifications:

  • Experience using ServiceNow, preferably Integrated Risk Management (IRM).
  • Experience with Governance, Risk, and Compliance (GRC) programs or platforms.
  • Experience using Microsoft Office 365 applications.
  • Experience preparing technical documentation and reports.
  • Experience coordinating projects, tasks, or workflow activities.
  • Experience working in customer service or stakeholder-facing environments.

Knowledge & Technical Skills:

  • Cybersecurity Principles
  • Information Security Governance
  • Governance, Risk & Compliance (GRC)
  • Enterprise Risk Management
  • Risk Assessment Methodologies
  • Risk Register Management
  • ServiceNow Integrated Risk Management (IRM)
  • NIST Cybersecurity Framework (NIST CSF)
  • Risk Scoring Systems and Quantitative Risk Frameworks
  • HIPAA
  • Technical Documentation
  • Workflow Coordination
  • Microsoft Office 365

ASSYST is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, disability, military status, national origin or any other characteristic protected under federal, state, or applicable local law.