1

Governance Risk Compliance Jobs in Virginia (NOW HIRING)

AVP, AI Risk and Governance

Arlington, VA · On-site

$117.21 - $195.29/hr

Conduct risk assessments and gap analyses on AI solutions to identify and evaluate risks and ensure compliance with internal policies and external regulations. * Evaluate AI governance practices such ...

... Compliance Consultant. The Senior Consultant will lead a workstream led related to cybersecurity risk management and risk governance within the agency. This position provides leadership and subject ...

... Compliance Consultant. The Senior Consultant will lead a workstream led related to cybersecurity risk management and risk governance within the agency. This position provides leadership and subject ...

AVP, AI Risk and Governance

Arlington, VA · On-site

$117K - $195K/yr

This role involves managing and establishing AI governance frameworks, performing risk assessments, and ensuring compliance with regulatory requirements. With a strong analytical background, the AVP ...

AVP, AI Risk and Governance

Arlington, VA · On-site +1

$117K - $195K/yr

This role involves managing and establishing AI governance frameworks, performing risk assessments, and ensuring compliance with regulatory requirements. With a strong analytical background, the AVP ...

Risk Analyst

Richmond, VA · On-site +1

$87K - $110K/yr

Document risks, findings, recommendations, and remediation plans while maintaining accurate records within governance, risk, and compliance platforms * Serve as a trusted advisor to stakeholders by ...

Experience using a Governance, Risk, and Compliance System. Physical Requirements: * Express or exchange ideas by means of the spoken word via email and verbally. * Exert up to 10 pounds of force ...

Showing results 21-40

Governance Risk Compliance information

See Virginia salary details

$31.2K

$68.1K

$111K

How much do governance risk compliance jobs pay per year?

As of Sep 2, 2026, the average yearly pay for governance risk compliance in Virginia is $68,142.00, according to ZipRecruiter salary data. Most workers in this role earn between $48,600.00 and $85,800.00 per year, depending on experience, location, and employer.

What is governance risk compliance?

Governance, Risk, and Compliance (GRC) is a coordinated strategy that organizations use to manage overall governance, enterprise risk management, and compliance with regulations and standards. GRC professionals help organizations align their business objectives with risk management practices and regulatory requirements. This role involves identifying potential risks, implementing policies to mitigate those risks, and ensuring that the organization adheres to legal, ethical, and internal standards. Effective GRC management can improve decision-making, optimize processes, and protect the organization from financial or reputational harm.

What are jobs in governance risk compliance?

Governance risk compliance (GRC) is a method for managing and strategizing an organization's regulations regarding governance, financial or physical risk, and regulatory compliance. It aligns the IT aspects with business objectives and works to improve the efficiency of a company. There are GRC consultants and GRC analysts who provide an assessment of a business’s GRC, identify risks, analyze the data, develop policies to benefit the workplace, and consult on the best choice of action. Your duties may involve optimizing GRC systems, implementing tactics to lower risk, providing internal audits, assisting with cybersecurity, creating routine reports, and ensuring regulatory compliance.

What are the key skills and qualifications needed to thrive as a governance risk compliance professional?

To thrive as a Governance Risk Compliance professional, you need a solid understanding of regulatory frameworks, risk management principles, and policy development, often supported by a degree in business, law, or information security. Familiarity with GRC software platforms, compliance management systems, and certifications like CISA, CRISC, or CISSP is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set top performers apart in this field. These competencies are essential for ensuring organizational compliance, minimizing risks, and maintaining robust corporate governance.

How does a governance risk compliance professional typically collaborate with other departments within an organization?

GRC professionals work closely with a variety of departments, including IT, legal, finance, and operations, to ensure that organizational policies and regulatory requirements are consistently met. Collaboration often involves leading risk assessments, facilitating compliance training, and coordinating audits to identify and mitigate potential risks. Effective communication and relationship-building are key, as GRC teams must translate complex regulations into actionable steps for different business units. This cross-functional approach helps embed a culture of compliance and risk awareness throughout the organization.

What is the difference between Governance Risk Compliance vs Risk Analyst?

AspectGovernance Risk ComplianceRisk Analyst
CertificationsCRISC, CISA, CISSPCFA, FRM, CRISC
Work EnvironmentCorporate, regulated industriesFinancial, consulting firms
Employer & Industry UsageFinancial institutions, healthcare, governmentBanking, investment firms, insurance

Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing enterprise-wide risks. Risk Analysts primarily assess specific financial or operational risks through data analysis. While both roles involve risk management, Governance Risk Compliance has a broader scope related to organizational compliance and governance frameworks, whereas Risk Analysts concentrate on analyzing and quantifying particular risks.

What is the work of governance risk compliance?

Governance, Risk, and Compliance (GRC) professionals develop and implement policies to ensure organizations adhere to legal and regulatory requirements, manage risks, and maintain ethical standards. They analyze business processes, conduct audits, and use tools like risk management software to identify vulnerabilities and ensure compliance across departments.

What are the most commonly searched types of Governance Risk Compliance jobs in Virginia?

The most popular types of Governance Risk Compliance jobs in Virginia are:

What are popular job titles related to Governance Risk Compliance jobs in Virginia?

For Governance Risk Compliance jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Governance Risk Compliance jobs in Virginia look for?

The top searched job categories for Governance Risk Compliance jobs in Virginia are:

What cities in Virginia are hiring for Governance Risk Compliance jobs?

Cities in Virginia with the most Governance Risk Compliance job openings:

Infographic showing various Governance Risk Compliance job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 13% Part Time, and 3% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $68,142 per year, or $32.8 per hour.

Information Security Analyst (Risk & Compliance)

Performance Food Group

Richmond, VA • On-site

$70K - $100K/yr

Full-time

Medical, Retirement, PTO

Posted 27 days ago


Job description


We Deliver the Goods:
  • Competitive pay and benefits, including Day 1 Health & Wellness Benefits, Employee Stock Purchase Plan, 401K Employer Matching, Education Assistance, Paid Time Off, and much more
  • Growth opportunities performing essential work to support America's food distribution system
  • Safe and inclusive working environment, including culture of rewards, recognition, and respect
Position Summary:
Performance Food Group is looking for a talented Information Security Analyst to play a key role in supporting Information and Privacy Risk Management aspects of the company as a member of the Information Security Department. PFG is in the midst of establishing a Risk Management function that focuses on identifying, quantifying, communicating, and tracking risks associated with information assets. Reporting to the Manager of Information Security Risk Management and working with IT and line of business stakeholders, the analyst will have a heavy focus on compliance with internal/external policies/statutes, IT Risk Management, and Third Party Risk.
Position Responsibilities:
  • Conduct risk assessments and maintain risk register. Perform assessments of IT controls processes, and systems, identifying gaps and opportunities to enhance design/operational effectiveness while reducing the cost of compliance. Conduct periodic readouts and risk reviews with IT teams and segment/line of business stakeholders to convey risk and influence decision making
  • Assist in maintaining security exception lifecycle, including qualfiying associated risk, determining compensating controls, communicating with IT and LOB stakeholders.
  • Assist in development of evaluative risk frameworks for new and emerging technologies, including but not limited to Artificial Intelligence
  • Maintain Business Impact Analysis. Work with IT and LOB teams to maintain Business Impact Analysis, establishing risk categorizations for applications and infrastructure based on mission criticality and sensitivity of hosted data.
  • Assist in development and implementation of Enterprise Crown Jewels program. Work with IT, LOB teams, and security control owners to define and govern control parameters for critical applications and technologies.
  • KPI/KRI Development and Reporting. Assist in development of control-based Key Risk Indicators and Key Performance Indicators across business segments. Assist in developing associated governance model and metric tiers for consumption by various levels of stakeholders, up to and including the Board of Directors.
  • Support IT Risk and exception management governance forums across business segments with varying operational models and business context.
  • Support PFG's Third Party Risk Management Program, assessing third parties for inherent and residual risk based on the nature of their services and their ability to appropriately secure PFG data and provide dependent services.
  • Negotiate the inclusion of security requirements into third party contract agreements.
  • Develop and Maintain IT Audit and Control documentation.
  • Support necessary governance forums (committees, working groups) to ensure sound decision-making and stakeholder communications.
  • Identify and report on non-compliance with regulatory mandates (i.e. Sarbanes Oxley section 404 PCI DSS, HIPAA, GDPR, CCPA).
  • Support operational audits as necessary.
  • Performs other related duties as assigned.

EEO Statement
Performance Food Group and/or its subsidiaries (individually or collectively, the "Company") provides equal employment opportunity (EEO) to all applicants and employees, regardless of race, color, national origin, sex, marital status, pregnancy, sexual orientation, gender identity, religion, age, disability, genetic information, veteran status, and any other characteristic protected by applicable local, state and federal laws and regulations. Please click on the following links to review: (1) our EEO Policy; (2) the "EEO is the Law" poster and supplement; and (3) the Pay Transparency Policy Statement.
Required Qualifications
• Bachelors Degree
• 1 - 3 Years of experience
• Experience in developing, communicating, and presenting security or risk concepts to varying audiences
• Experience with evaluating AI initiatives through a security risk lens
• Knowledge of regulatory requirements and frameworks
• Development and implementation of security policies
• Experience conducting security maturity assessments
• Development and implementation of security controls
• Strong teamwork and interpersonal skills
• Experience in assisting with process improvement initiatives
• Hold relevant security certifications or willingness to pursue additional certifications
• Continuous learning mindset
• Experience performing IT and security risk assessments, using both qualitative and quantitative methods to identify, quantify, and communicate risk
• Working knowledge of privacy statutes including the European Union General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA)
• Experience with Data Classification, Data Security, and Data Loss Prevention methods and tools, specifically Microsoft Azure Information Protection
• Strong MS Office skills (specifically PowerPoint, Word, Excel, Project, Visio)
• Strong process analysis and engineering skills
• Experience conducting and documenting business impact analysis, designing and implementing Business Continuity/Disaster Recovery plans
• Experience with IT assurance mandates/frameworks such as Sarbanes-Oxley, CobIT
• Demonstrated leadership skills
• Demonstrated high level of analytical and problem-solving skills
• Excellent written and verbal communication skills
• Ability to influence cross functional and highly matrixes business and IT stakeholders
Preferred Qualifications
• Bachelor's Degree
• 3 - 5 Years of experience
• Experience in assessing hosted service architectures (SaaS, PaaS, IaaS)
• Experience performing third party assessments across information security and control domains, using industry tools/frameworks such as the Cloud Security Alliance, evaluation of Service Organization Controls (SOC) attestations. Manage supplemental evaluation Service Providers
• Experience with Data Classification, Data Security, and Data Loss Prevention methods and tools
• Strong MS Office skills (specifically PowerPoint, Word, Excel, Project, Visio)
• Strong process analysis and engineering skills
• Experience conducting and documenting business impact analysis, designing and implementing Business Continuity/Disaster Recovery plans
• Experience presenting on complex technical subjects to non-technical stakeholders
• Preferred Professional Certifications: Security Plus, CSP certifications, SANS Certifications, FAIR, Certified Information Systems Security Professional (CISSP)
Company Description
Performance Food Group is a customer-centric foodservice distribution leader headquartered in Richmond, Va. Grounded by roots that date back to a grocery peddler in 1885, PFG has a nationwide network of approximately 150 distribution centers, 35,000-plus talented associates, and thousands of valued suppliers across the country. With the goal of helping customers thrive, PFG markets and delivers quality food and related products to independent and chain restaurants, schools, business and industry locations, convenience operations, healthcare facilities, vending distributors, office coffee service distributors, big box retailers, and theaters across the U.S.