Serve as the firm's senior leader for cybersecurity governance, risk, and compliance advisory services * Design and oversee enterprise cybersecurity frameworks aligned with NIST CSF, NIST SP 800-171 ...
Serve as the firm's senior leader for cybersecurity governance, risk, and compliance advisory services * Design and oversee enterprise cybersecurity frameworks aligned with NIST CSF, NIST SP 800-171 ...
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
Quick apply
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
Quick apply
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
Quick apply
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
Quick apply
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
Quick apply
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
Quick apply
AI Governance Coordinator
Baltimore, MD · Remote
$44/hr
AI Governance Coordinator Type: Contract Compensation: $44/HR Work Model: 100% Remote Role Overview ... Partner with Risk, Compliance, Privacy, and Security teams; draft clear communications and reports ...
Developing AI-enabled capabilities that accelerate governance, risk, and compliance and cyber operations, including evidence summarization, control testing assist, policy question-and-answer ...
Developing AI-enabled capabilities that accelerate governance, risk, and compliance and cyber operations, including evidence summarization, control testing assist, policy question-and-answer ...
... System (RMIS), Governance, Risk & Compliance (GRC), and Environmental, Social & Governance (ESG) platform companies. What You Will Work On * Identify, initiate, and close new partnership ...
... System (RMIS), Governance, Risk & Compliance (GRC), and Environmental, Social & Governance (ESG) platform companies. What You Will Work On * Identify, initiate, and close new partnership ...
Do you have specialized knowledge and expertise in infrastructure governance and deep experience ... Performs risk assessments, monitors and reports policy and controls compliance * Facilitates and ...
Do you have specialized knowledge and expertise in infrastructure governance and deep experience ... Performs risk assessments, monitors and reports policy and controls compliance * Facilitates and ...
Cyber GRC Specialist
Baltimore, MD · On-site
Cyber Risk / Compliance Analyst work, ISO and risk-platform support, evidence coordination, client/regulatory response support, communications, and vulnerability governance. Duties and ...
Cyber GRC Specialist
Baltimore, MD · On-site
Cyber Risk / Compliance Analyst work, ISO and risk-platform support, evidence coordination, client/regulatory response support, communications, and vulnerability governance. Duties and ...
Cyber GRC Specialist
Baltimore, MD · On-site
Cyber Risk / Compliance Analyst work, ISO and risk-platform support, evidence coordination, client/regulatory response support, communications, and vulnerability governance. Duties and ...
Cyber GRC Specialist
Baltimore, MD · On-site
Cyber Risk / Compliance Analyst work, ISO and risk-platform support, evidence coordination, client/regulatory response support, communications, and vulnerability governance. Duties and ...
Senior Analyst, Operational Risk Management (Hybrid)
Baltimore, MD · Hybrid
$80K - $95K/yr
Navigate company Governance Risk & Compliance (GRC) tool to record, update and report on various risk issues, risk events, action plans, etc. Qualifications: * Bachelor's degree in accounting ...
Senior Analyst, Operational Risk Management (Hybrid)
Baltimore, MD · Hybrid
$80K - $95K/yr
Navigate company Governance Risk & Compliance (GRC) tool to record, update and report on various risk issues, risk events, action plans, etc. Qualifications: * Bachelor's degree in accounting ...
Conduct quarterly account reviews with internal stakeholders, including cyber strategy, technology risk, IT audit, governance risk and compliance, privacy, third-party risk, cloud security, incident ...
Conduct quarterly account reviews with internal stakeholders, including cyber strategy, technology risk, IT audit, governance risk and compliance, privacy, third-party risk, cloud security, incident ...
Compliance & Risk Analyst
Owings Mills, MD · On-site
$30 - $34/hr
Compliance & Risk Analyst (Audit & Controls) Location-Type: Hybrid (Owings Mills, MD - 2 Days ... Support implementation of new controls and governance processes as technologies and regulations ...
Quick apply
Compliance & Risk Analyst
Owings Mills, MD · On-site
$30 - $34/hr
Compliance & Risk Analyst (Audit & Controls) Location-Type: Hybrid (Owings Mills, MD - 2 Days ... Support implementation of new controls and governance processes as technologies and regulations ...
Cybersecurity GRC Analyst
Owings Mills, MD · On-site
$51.35/hr
The ideal candidate will have experience in cybersecurity governance, risk management, compliance, IT audit, and security controls, along with exposure to ServiceNow and database environments. Key ...
New
Cybersecurity GRC Analyst
Owings Mills, MD · On-site
$51.35/hr
The ideal candidate will have experience in cybersecurity governance, risk management, compliance, IT audit, and security controls, along with exposure to ServiceNow and database environments. Key ...
New
Cybersecurity GRC Analyst
Owings Mills, MD · Remote
$51/hr
The ideal candidate will have experience in cybersecurity governance, risk management, compliance, IT audit, and security controls, along with exposure to ServiceNow and database environments. Key ...
New
Quick apply
Cybersecurity GRC Analyst
Owings Mills, MD · Remote
$51/hr
The ideal candidate will have experience in cybersecurity governance, risk management, compliance, IT audit, and security controls, along with exposure to ServiceNow and database environments. Key ...
New
Operational Governance, Risk & Compliance: * Establishes and maintains procedures, controls, and documentation supporting recurring processes and regulatory obligations. * Oversees exception handling ...
Operational Governance, Risk & Compliance: * Establishes and maintains procedures, controls, and documentation supporting recurring processes and regulatory obligations. * Oversees exception handling ...
Cybersecurity Governance Manager
Baltimore, MD · On-site
$110K - $149K/yr
Establish an automated technology and cyber governance risk and compliance (GRC) program to continuously monitor and report on technology and cyber risk and control effectiveness. * Lead the company ...
Cybersecurity Governance Manager
Baltimore, MD · On-site
$110K - $149K/yr
Establish an automated technology and cyber governance risk and compliance (GRC) program to continuously monitor and report on technology and cyber risk and control effectiveness. * Lead the company ...
... Governance, Risk, and Compliance (GRC) technology, data, and risk infrastructure capabilities. The Senior Risk Manager, GRC Systems, will play a pivotal role in shaping how operational risk ...
... Governance, Risk, and Compliance (GRC) technology, data, and risk infrastructure capabilities. The Senior Risk Manager, GRC Systems, will play a pivotal role in shaping how operational risk ...
Governance Risk Compliance information
See Baltimore, MD salary details
$31.3K - $38.6K
12% of jobs
$38.6K - $45.8K
7% of jobs
$48.3K is the 25th percentile. Wages below this are outliers.
$45.8K - $53.1K
17% of jobs
$53.1K - $60.4K
10% of jobs
The median wage is $62.3K / yr.
$60.4K - $67.7K
16% of jobs
$67.7K - $74.9K
9% of jobs
$79.6K is the 75th percentile. Wages above this are outliers.
$74.9K - $82.2K
7% of jobs
$82.2K - $89.5K
5% of jobs
$89.5K - $96.7K
7% of jobs
$96.7K - $104K
5% of jobs
$104K - $111.3K
4% of jobs
$31.3K
$68.3K
$111.3K
How much do governance risk compliance jobs pay per year?
What are jobs in governance risk compliance?
Governance risk compliance (GRC) is a method for managing and strategizing an organization's regulations regarding governance, financial or physical risk, and regulatory compliance. It aligns the IT aspects with business objectives and works to improve the efficiency of a company. There are GRC consultants and GRC analysts who provide an assessment of a business’s GRC, identify risks, analyze the data, develop policies to benefit the workplace, and consult on the best choice of action. Your duties may involve optimizing GRC systems, implementing tactics to lower risk, providing internal audits, assisting with cybersecurity, creating routine reports, and ensuring regulatory compliance.
What is the work of governance risk compliance?
What is governance risk compliance?
How does a governance risk compliance professional typically collaborate with other departments within an organization?
What is the difference between Governance Risk Compliance vs Risk Analyst?
| Aspect | Governance Risk Compliance | Risk Analyst |
|---|---|---|
| Certifications | CRISC, CISA, CISSP | CFA, FRM, CRISC |
| Work Environment | Corporate, regulated industries | Financial, consulting firms |
| Employer & Industry Usage | Financial institutions, healthcare, government | Banking, investment firms, insurance |
Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing enterprise-wide risks. Risk Analysts primarily assess specific financial or operational risks through data analysis. While both roles involve risk management, Governance Risk Compliance has a broader scope related to organizational compliance and governance frameworks, whereas Risk Analysts concentrate on analyzing and quantifying particular risks.
What are the key skills and qualifications needed to thrive as a governance risk compliance professional?
What are the most commonly searched types of Governance Risk Compliance jobs in Baltimore, MD?
The most popular types of Governance Risk Compliance jobs in Baltimore, MD are:
What are popular job titles related to Governance Risk Compliance jobs in Baltimore, MD?
For Governance Risk Compliance jobs in Baltimore, MD, the most frequently searched job titles are:
What job categories do people searching Governance Risk Compliance jobs in Baltimore, MD look for?
The top searched job categories for Governance Risk Compliance jobs in Baltimore, MD are:
What cities near Baltimore, MD are hiring for Governance Risk Compliance jobs?
Cities near Baltimore, MD with the most Governance Risk Compliance job openings:

Director of Cybersecurity, Governance, Risk and Compliance
Baltimore, MD • On-site
Full-time
Re-posted 12 days ago
Job description
Gross Mendelsohn, one of the Mid-Atlantic’s leading independent CPA and advisory firms, is seeking a strategic and technically strong Director of Cybersecurity Governance, Risk & Compliance (GRC) to build and lead our cybersecurity and IT risk advisory capabilities.
This is a visible, high-impact leadership role responsible for designing, implementing, and overseeing enterprise cybersecurity and IT compliance programs for both clients and the firm, particularly government contractors and organizations operating in regulated environments.
As cybersecurity requirements continue to intensify, this role will sit at the intersection of IT architecture, regulatory compliance, risk advisory, and executive leadership. The Director will help position Gross Mendelsohn as a trusted advisor in cybersecurity governance, CUI compliance, and federal regulatory readiness.
Recognized with nine Top Workplace awards, Gross Mendelsohn is committed to professional excellence, collaboration, and long-term growth. This opportunity offers leadership visibility, strategic influence, and the ability to build and expand a critical service line within a respected independent firm.
Key Responsibilities
Cybersecurity & IT Governance Leadership
Serve as the firm’s senior leader for cybersecurity governance, risk, and compliance advisory services
Design and oversee enterprise cybersecurity frameworks aligned with NIST CSF, NIST SP 800-171, NIST SP 800-53, ISO 27001, and related standards
Lead end-to-end CUI and federal compliance programs, including development and maintenance of System Security Plans (SSP) and Plans of Action & Milestones (POA&M)
Conduct NIST SP 800-171 gap assessments and develop prioritized remediation roadmaps
Support clients with DFARS 252.204-7012 compliance, SPRS scoring, and CMMC readiness initiatives
Prepare clients for audits, mock assessments, and government inquiries
IT Infrastructure & Security Oversight
Oversee implementation and validation of technical cybersecurity controls, including:
Multi-factor authentication
Encryption (data at rest and in transit)
Endpoint protection
Logging, SIEM, and continuous monitoring
Network segmentation
Secure configuration and hardening standards
Provide advisory oversight of secure cloud environments, including Microsoft GCC High, Azure Government, and AWS GovCloud
Establish identity and access management frameworks and privileged access controls
Evaluate backup, disaster recovery, and business continuity processes
Direct incident response strategy and regulatory reporting obligations
Supply Chain & Flow-Down Advisory
Advise prime contractors on subcontractor cybersecurity flow-down requirements
Assess subcontractor readiness and compliance risk exposure
Support documentation required for federal scrutiny
Training & Continuous Improvement
Develop and deliver CUI-specific and role-based cybersecurity training
Implement measurable security awareness initiatives, including phishing simulations
Lead annual program reviews and continuous improvement initiatives
Maintain compliance posture during infrastructure changes, acquisitions, or system transitions
Executive Advisory & Reporting
Prepare executive-level cybersecurity risk reports and board-ready briefings
Translate complex technical risk into actionable business guidance
Collaborate with firm leadership to expand cybersecurity service offerings
Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Engineering, or related field
7–12+ years of progressive experience in cybersecurity, IT risk, compliance, or security architecture
Demonstrated experience leading CUI, DFARS, and NIST 800-171 compliance initiatives
Experience working within a government contractor or regulated environments strongly preferred
Experience with secure federal cloud platforms such as GCC High or GovCloud preferred
Professional certifications preferred: CISSP, CISM, CISA, ISO 27001 Lead Implementer, Security+, or equivalent
Required Skills and Competencies
Technical Expertise
Deep understanding of modern IT infrastructure, cloud security, and cybersecurity architecture
Strong working knowledge of NIST frameworks and federal cybersecurity regulations
Experience leading risk assessments and remediation programs
Strong documentation, audit-readiness, and control validation capabilities
Analytical Strength
Exceptional risk analysis and problem-solving skills
Ability to align cybersecurity controls with business processes
Strong systems thinking and governance design capability
Interpersonal & Professional Skills
Strong executive presence and communication skills
Ability to present complex cybersecurity risks clearly to non-technical audiences
Collaborative leadership style with the ability to build cross-functional relationships
Growth-oriented mindset with interest in expanding advisory capabilities
Additional Requirements
U.S. Citizenship required
Ability to travel up to 30% to client sites as needed
Proficiency in Microsoft Office and cybersecurity reporting tools
Why Join Gross Mendelsohn?
Lead and grow a high-impact cybersecurity advisory capability
Work directly with firm leadership in a visible strategic role
Contribute to modernization initiatives within a respected independent firm
Collaborative, growth-oriented culture
Competitive compensation and comprehensive benefits
Free parking at our Locust Point/McHenry Row office
Hybrid flexibility is available with approval
Work Environment
This role offers flexibility to work hybrid or fully remote; however, the Director of Cybersecurity will be expected to be present at client sites or in the office as business needs require, particularly for client delivery, team leadership, and strategic initiatives.
Physical Requirements
Ability to sit for extended periods, lift up to 20 pounds, and manage physical files and documentation as needed.
Join Us
If you are a strategic and execution-driven cybersecurity leader who thrives in a collaborative, growth-oriented professional services firm and is energized by building, scaling, and protecting a high-impact practice, we encourage you to apply.
Gross Mendelsohn is an equal opportunity employer
committed to fostering a respectful and inclusive workplace.
About Gross Mendelsohn & Associates
Sourced by ZipRecruiter
Company size
51 - 200 Employees
Headquarters location
Baltimore, MD, US
Year founded
1960