1

Governance Risk Compliance Jobs in Frederick, MD

The GRC Analyst supports the administration of Information Security Governance, Risk, and Compliance programs, including policy exception management and enterprise risk register activities using ...

The GRC Analyst supports the administration of Information Security Governance, Risk, and Compliance programs, including policy exception management and enterprise risk register activities using ...

Enterprise Architect (IT)

Hagerstown, MD · On-site +1

$68.50 - $88.25/hr

  • Medical

  • Life

  • Retirement

  • PTO

... IT/AI governance across a regulated financial services environment. Reporting to the Director of Enterprise Architecture, this role partners with business, technology, risk, compliance, security ...

Enterprise Architect (IT)

Hagerstown, MD · On-site +1

$102K - $208K/yr

  • Medical

  • Life

  • Retirement

  • PTO

... IT/AI governance across a regulated financial services environment. Reporting to the Director of Enterprise Architecture, this role partners with business, technology, risk, compliance, security ...

Risk, Compliance & Governance Ensure product capabilities align with applicable regulatory, legal, compliance, and risk requirements. Partner with governance stakeholders throughout the product ...

Risk, Compliance & Governance * Ensure product capabilities align with applicable regulatory, legal, compliance, and risk requirements. * Partner with governance stakeholders throughout the product ...

Merchant Product Manager - Sr

Hagerstown, MD · On-site

$93K - $189K/yr

  • Medical

  • Life

  • Retirement

  • PTO

Risk, Compliance & Governance * Ensure product capabilities align with applicable regulatory, legal, compliance, and risk requirements. * Partner with governance stakeholders throughout the product ...

Chief Compliance Officer

Rockville, MD · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Compliance Framework & Governance * Own, design, and continuously enhance the ISS Compliance ... Our services cover corporate governance, sustainability, cyber risk, and fund intelligence.

... compliance monitoring; security audit management; risk assessment; system authorization; security ... governance, optimizations, automation, and supporting tools. * Developing an agency Information ...

... compliance monitoring; security audit management; risk assessment; system authorization; security ... governance, optimizations, automation, and supporting tools. * Developing an agency Information ...

... compliance monitoring; security audit management; risk assessment; system authorization; security ... governance, optimizations, automation, and supporting tools. * Developing an agency Information ...

... compliance monitoring; security audit management; risk assessment; system authorization; security ... governance, optimizations, automation, and supporting tools. * Developing an agency Information ...

next page

Showing results 1-20

Governance Risk Compliance information

See Frederick, MD salary details

$31.3K

$68.3K

$111.4K

How much do governance risk compliance jobs pay per year?

As of Aug 14, 2026, the average yearly pay for governance risk compliance in Frederick, MD is $68,338.00, according to ZipRecruiter salary data. Most workers in this role earn between $48,700.00 and $86,000.00 per year, depending on experience, location, and employer.

What are jobs in governance risk compliance?

Governance risk compliance (GRC) is a method for managing and strategizing an organization's regulations regarding governance, financial or physical risk, and regulatory compliance. It aligns the IT aspects with business objectives and works to improve the efficiency of a company. There are GRC consultants and GRC analysts who provide an assessment of a business’s GRC, identify risks, analyze the data, develop policies to benefit the workplace, and consult on the best choice of action. Your duties may involve optimizing GRC systems, implementing tactics to lower risk, providing internal audits, assisting with cybersecurity, creating routine reports, and ensuring regulatory compliance.

What is the work of governance risk compliance?

Governance, Risk, and Compliance (GRC) professionals develop and implement policies to ensure organizations adhere to legal and regulatory requirements, manage risks, and maintain ethical standards. They analyze business processes, conduct audits, and use tools like risk management software to identify vulnerabilities and ensure compliance across departments.

What is governance risk compliance?

Governance, Risk, and Compliance (GRC) is a coordinated strategy that organizations use to manage overall governance, enterprise risk management, and compliance with regulations and standards. GRC professionals help organizations align their business objectives with risk management practices and regulatory requirements. This role involves identifying potential risks, implementing policies to mitigate those risks, and ensuring that the organization adheres to legal, ethical, and internal standards. Effective GRC management can improve decision-making, optimize processes, and protect the organization from financial or reputational harm.

How does a governance risk compliance professional typically collaborate with other departments within an organization?

GRC professionals work closely with a variety of departments, including IT, legal, finance, and operations, to ensure that organizational policies and regulatory requirements are consistently met. Collaboration often involves leading risk assessments, facilitating compliance training, and coordinating audits to identify and mitigate potential risks. Effective communication and relationship-building are key, as GRC teams must translate complex regulations into actionable steps for different business units. This cross-functional approach helps embed a culture of compliance and risk awareness throughout the organization.

What is the difference between Governance Risk Compliance vs Risk Analyst?

AspectGovernance Risk ComplianceRisk Analyst
CertificationsCRISC, CISA, CISSPCFA, FRM, CRISC
Work EnvironmentCorporate, regulated industriesFinancial, consulting firms
Employer & Industry UsageFinancial institutions, healthcare, governmentBanking, investment firms, insurance

Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing enterprise-wide risks. Risk Analysts primarily assess specific financial or operational risks through data analysis. While both roles involve risk management, Governance Risk Compliance has a broader scope related to organizational compliance and governance frameworks, whereas Risk Analysts concentrate on analyzing and quantifying particular risks.

What are the key skills and qualifications needed to thrive as a governance risk compliance professional?

To thrive as a Governance Risk Compliance professional, you need a solid understanding of regulatory frameworks, risk management principles, and policy development, often supported by a degree in business, law, or information security. Familiarity with GRC software platforms, compliance management systems, and certifications like CISA, CRISC, or CISSP is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set top performers apart in this field. These competencies are essential for ensuring organizational compliance, minimizing risks, and maintaining robust corporate governance.

What are the most commonly searched types of Governance Risk Compliance jobs in Frederick, MD?

The most popular types of Governance Risk Compliance jobs in Frederick, MD are:

What are popular job titles related to Governance Risk Compliance jobs in Frederick, MD?

For Governance Risk Compliance jobs in Frederick, MD, the most frequently searched job titles are:

What job categories do people searching Governance Risk Compliance jobs in Frederick, MD look for?

The top searched job categories for Governance Risk Compliance jobs in Frederick, MD are:

What cities near Frederick, MD are hiring for Governance Risk Compliance jobs?

Cities near Frederick, MD with the most Governance Risk Compliance job openings:

Infographic showing various Governance Risk Compliance job openings in Frederick, MD as of August 2026, with employment types broken down into 88% Full Time, and 12% Contract. Highlights an 88% In-person, and 12% Remote job distribution, with an average salary of $68,338 per year, or $32.9 per hour.

Lead, Governance, Risk & Compliance (Remote)

Emergent Biosolutions

Gaithersburg, MD • Remote

$169K/yr

Full-time

Posted 23 hours ago

Posted today


Job description


 Preparedness today, safer tomorrow.

 Emergent is a leading public health company that delivers protective and life-saving solutions to
 communities around the world.  Here, you will join passionate professionals where our culture is informed
 by our values and commitment to protecting and saving lives.

I.    JOB SUMMARY 

The Lead for Governance, Risk and Compliance will oversee cybersecurity governance, risk management and compliance processes including the data protection and security awareness training programs.  This position is an individual contributor role, reporting to the IT Vice President and CISO at Emergent. 

This role will initially focus on maturing enterprise-wide data protection capabilities, including data classification, data loss prevention, information protection and data governance frameworks. Over time, the role will expand to support Manufacturing OT security and oversee broader GRC functions, including cybersecurity risk management, regulatory compliance, security policies and standards and security governance.

The ideal candidate combines strong cybersecurity expertise with program leadership,  executive communications and experience implementing security programs leveraging governance and technologies. This position will be hands-on and require strong collaboration with various IT and business functions to satisfy our governance, risk management and compliance processes. 

This position is full-time remote.

II.    ESSENTIAL FUNCTIONS


Reasonable accommodations will be made to enable individuals with disabilities to perform the essential functions.

Data Protection 

  • Lead implementation and governance of technologies supporting: Data Classification and Labeling, Data Loss Prevention (DLP), Insider Risk Management, Data Discovery and Inventory, Records and 

Information Management

  • Partner with business stakeholders to identify, classify, and protect information
  • Establish governance processes for data owners, custodians, and users
  • Define data protection metrics, KPIs, and reporting for executive leadership
  • Lead remediation efforts for large volumes of inadequately protected data
  • Oversee data protection policy compliance across all technology platforms
  • Drive adoption of data protection capabilities via training and change management

Governance

  • Lead the organization on improved maturity with regards to IS27001, CMMC or related industry certifications based on the NIST framework.
  • Lead cybersecurity maturity assessments and create/maintain cybersecurity KPI and metrics for efficient decision making with functional leaders  
  • Establish and maintain cybersecurity governance frameworks and operating models.
  • Support various cyber councils, governance forums and program steering committees
  • Collaborate with IT and functional leaders to align cybersecurity initiatives with business objectives

Risk Management

  • Create and maintain the Cybersecurity risk register and support risk quantification and prioritization efforts that are appropriate for the environment
  • Partner with business leaders to evaluate technology, operational, third-party, data-related risks and document risk assessments and their approvals
  • Support risk reporting dashboards for executive management and governance councils
  •  Assist the vulnerability management program to document risks and plans of actions.

Policies & Communications 

  • Lead, own and develop new information security policies and review existing policies for updates and approvals
  • Lead, maintain and continuously improve security awareness and training programs, cybersecurity company-wide campaign, and
  • Lead cybersecurity audits internally and develop readiness activities. Support internal and external audits and assessments.

Manufacturing Security

  • Support the manufacturing security program workstreams around network segmentation, secure remote access, logging and OT incident management.  
  • Create and lead the cyber training and awareness for manufacturing sites
  • Support the execution of periodic BCP and Cybersecurity table top exercises  
     
    The above statements are intended to describe the nature of work performed by those in this job and are not an exhaustive list of all duties. Nothing in this job description restricts managements right to assign or reassign duties and responsibilities to this job at any time which reflects management’s assignment of essential functions. 


III. MINIMUM EDUCATION, EXPERIENCE, SKILLS
 
Education: 

  • Bachelor’s Degree in Business or Information Systems, or equivalent experience.

Experience: 

  • 5+ years in cybersecurity, compliance, risk management or 7+ years of related/industry experience 
  • Experience leading cybersecurity projects and programs
  • Experience working with cybersecurity tools, methodologies and technologies

Knowledge: 

  • Experience supporting cybersecurity programs within manufacturing environments, including familiarity with cybersecurity risks associated with industrial operation
  • Must understand network and computing, vulnerability management, IAM/PAM
  • Must be familiar with Sarbanes Oxley (SOX), SSAE 18 SOC reports, NIST CSF, ISO27001 and CMMC  

Skills: 

  • Strong interpersonal and collaboration skills to work well with all IT and business stakeholders
  • Strong communication skills (oral, written, presentation) to influence across all levels of the organization  
  • Adequate program management and organizational skills to ensure accuracy and timeliness of job duties
  • Must be able to author policy documents, provide business risk assessments, and communicate well with other teams.
  • Must be able to identify sensitive information, such as PII, PHI, Clinical Data, etc.

Abilities: 

  • Demonstrated experience working across organizations to resolve conflicts
  • Demonstrated experience with organization-wide communications.
  • Demonstrated experience managing and documenting security risks.

U.S. Base Pay Ranges and Benefits Information

The estimated annual base salary as a new hire for this position ranges from [$155,500 to $188,200]. Individual base pay depends on various factors such as applicant’s education, experience, skills, and abilities, as well as internal equity and alignment with market data.  The salary may also be adjusted based on applicant’s geographic location.  Certain roles are eligible for additional incentive compensation, including merit increases, annual bonus, [and/or long-term incentives in the form of stock options.]

Additionally, Emergent offers a comprehensive benefits package*.  Information regarding additional benefits can be found here:  https://www.emergentbiosolutions.com/careers/life-at-emergent

(*Eligibility for benefits is governed by the applicable plan documents and policies).

If you are selected for an interview, please feel welcome to speak to a Human Resources Partner about our compensation philosophy and available benefits.

There are physical/mental demands and work environment characteristics that must be met by an individual to successfully perform the essential functions of the job. This information is available upon request from the candidate.

Reasonable accommodations may be made to enable individuals with disabilities to perform all essential functions.

Emergent BioSolutions is an Equal Opportunity/Affirmative Action Employer and values the diversity of our workforce.  Emergent does not discriminate on the basis of race, color, creed, religion, sex or gender (including pregnancy, childbirth, and related medical conditions), gender identity or gender expression (including transgender status), sexual orientation, age, national origin, ancestry, citizenship status, marital status, physical or mental disability, military service or veteran status, genetic information or any other characteristics protected by applicable federal, state or local law.

Information submitted will be used by Emergent BioSolutions for activities related to your prospective employment. Emergent BioSolutions respects your privacy and any use of the information submitted will be subject to the terms of our Privacy Policy .

Emergent BioSolutions does not accept non-solicited resumes or candidate submittals from search/recruiting agencies not already on Emergent BioSolutions’ approved agency list. Unsolicited resumes or candidate information submitted to Emergent BioSolutions by search/recruiting agencies not already on Emergent BioSolutions’ approved agency list shall become the property of Emergent BioSolutions and if the candidate is subsequently hired by Emergent BioSolutions, Emergent BioSolutions shall not owe any fee to the submitting agency.