1

Governance Risk Compliance Jobs in Reston, VA (NOW HIRING)

next page

Showing results 1-20

Governance Risk Compliance information

See Reston, VA salary details

$32.8K

$71.5K

$116.5K

How much do governance risk compliance jobs pay per year?

As of May 31, 2026, the average yearly pay for governance risk compliance in Reston, VA is $71,505.00, according to ZipRecruiter salary data. Most workers in this role earn between $51,000.00 and $90,000.00 per year, depending on experience, location, and employer.

What Are Jobs in Governance Risk and Compliance?

Governance risk compliance (GRC) is a method for managing and strategizing an organization's regulations regarding governance, financial or physical risk, and regulatory compliance. It aligns the IT aspects with business objectives and works to improve the efficiency of a company. There are GRC consultants and GRC analysts who provide an assessment of a business’s GRC, identify risks, analyze the data, develop policies to benefit the workplace, and consult on the best choice of action. Your duties may involve optimizing GRC systems, implementing tactics to lower risk, providing internal audits, assisting with cybersecurity, creating routine reports, and ensuring regulatory compliance.

What are the key skills and qualifications needed to thrive as a Governance Risk Compliance (GRC) professional, and why are they important?

To thrive as a Governance Risk Compliance professional, you need a solid understanding of regulatory frameworks, risk management principles, and policy development, often supported by a degree in business, law, or information security. Familiarity with GRC software platforms, compliance management systems, and certifications like CISA, CRISC, or CISSP is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set top performers apart in this field. These competencies are essential for ensuring organizational compliance, minimizing risks, and maintaining robust corporate governance.

How does a Governance, Risk, and Compliance (GRC) professional typically collaborate with other departments within an organization?

GRC professionals work closely with a variety of departments, including IT, legal, finance, and operations, to ensure that organizational policies and regulatory requirements are consistently met. Collaboration often involves leading risk assessments, facilitating compliance training, and coordinating audits to identify and mitigate potential risks. Effective communication and relationship-building are key, as GRC teams must translate complex regulations into actionable steps for different business units. This cross-functional approach helps embed a culture of compliance and risk awareness throughout the organization.

What is Governance, Risk, and Compliance (GRC)?

Governance, Risk, and Compliance (GRC) is a coordinated strategy that organizations use to manage overall governance, enterprise risk management, and compliance with regulations and standards. GRC professionals help organizations align their business objectives with risk management practices and regulatory requirements. This role involves identifying potential risks, implementing policies to mitigate those risks, and ensuring that the organization adheres to legal, ethical, and internal standards. Effective GRC management can improve decision-making, optimize processes, and protect the organization from financial or reputational harm.

What is the difference between Governance Risk Compliance vs Risk Analyst?

AspectGovernance Risk ComplianceRisk Analyst
CertificationsCRISC, CISA, CISSPCFA, FRM, CRISC
Work EnvironmentCorporate, regulated industriesFinancial, consulting firms
Employer & Industry UsageFinancial institutions, healthcare, governmentBanking, investment firms, insurance

Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing enterprise-wide risks. Risk Analysts primarily assess specific financial or operational risks through data analysis. While both roles involve risk management, Governance Risk Compliance has a broader scope related to organizational compliance and governance frameworks, whereas Risk Analysts concentrate on analyzing and quantifying particular risks.

What are the most commonly searched types of Governance Risk Compliance jobs in Reston, VA? The most popular types of Governance Risk Compliance jobs in Reston, VA are:
What are popular job titles related to Governance Risk Compliance jobs in Reston, VA? For Governance Risk Compliance jobs in Reston, VA, the most frequently searched job titles are:
What cities near Reston, VA are hiring for Governance Risk Compliance jobs? Cities near Reston, VA with the most Governance Risk Compliance job openings:
Infographic showing various Governance Risk Compliance job openings in Reston, VA as of May 2026, with employment types broken down into 2% As Needed, 86% Full Time, 1% Part Time, and 11% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $71,505 per year, or $34.4 per hour.

Security Engineer - Governance Risk Compliance

xAI

Washington, DC

Full-time

Medical, Dental, Vision, Life, Retirement

Posted 3 days ago


Job description

ABOUT xAI

xAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company's mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.

ABOUT THE ROLE:
We are seeking an experienced and strategic Governance, Risk, and Compliance (GRC) team member as we expand into government and public sector applications of AI. This critical role will ensure that xAI operates within regulatory, ethical, operational, and federal boundaries while fostering a culture of integrity and resilience. You will collaborate with cross-functional teams to safeguard our mission-driven work in AI development and deployment, including support for sensitive and classified environments.
RESPONSIBILITIES:
  • Execute security compliance implementation and audits (e.g., ISO 27001/42001, SOC2, FedRAMP HIGH, DoD Cloud Computing SRG IL5/IL6, NIST 800-53 rev 5, NIST 800-171/CMMC, Risk Management Framework).
  • Work with 3PAOs (Third-Party Assessment Organizations) and federal government Authorizing Officials (AOs) to achieve compliance certifications, reports, and Authorized to Operate (ATO) status.
  • Identify, assess, and prioritize risks related to AI operations, cybersecurity, regulatory compliance, intellectual property, and cloud deployments.
  • Design and implement risk mitigation strategies, including monitoring systems, contingency plans, vulnerability scans, Plan of Action and Milestones (POAMs), and STIGs.
  • Ensure the implementation, oversight, monitoring, and maintenance of security configurations, practices, and procedures throughout the project lifecycle.
  • Serve as a liaison between system owners, security personnel, and cross-functional teams to facilitate effective communication, collaboration, and control implementation.
  • Lead Risk Management Assessment and Authorization (A&A) processes, cloud system risk assessments, compliance reviews for new products/changes/features, and process enhancements.
  • Conduct regular risk assessments, scenario analyses, and proactive evaluations of emerging threats, certifications, requirements, and technologies in the AI landscape.
  • Oversee audits, certifications, third-party assessments, and vulnerability management to maintain compliance and operational credibility.
  • Act as a subject matter expert, providing guidance on risk, compliance, and cybersecurity matters; translate business and technical risks for leadership.
  • Create and present regular reports on GRC performance, risks, and compliance status to senior leadership and stakeholders.
BASIC QUALIFICATIONS:
  • Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field
  • 3+ years of experience in governance, risk management, compliance, or technology audit roles.
  • Experience with vulnerability management, POAMs, STIG implementation, and cloud security controls.
PREFERRED SKILLS AND EXPERIENCE:
  • 5+ years of security compliance or technology audit-related.
  • Previous systems engineering experience strongly preferred
  • Ability to evaluate control objectives with IT configurations
  • Experience in the tech or AI industry, particularly with startups, innovative organizations, or government/public sector engagements.
  • Proven expertise in regulatory frameworks, data privacy, cybersecurity, and federal compliance standards, preferably in a technology, cloud, or AI-driven environment.
  • Strong understanding of AI ethics, emerging technologies, Risk Management Framework (RMF), and their associated risks.
  • Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to balance innovation, oversight, and taking projects from conception to launch.
  • Excellent communication, stakeholder management, and translation skills, with experience influencing cross-functional teams and communicating risks to leadership.
  • Ability to thrive in a fast-paced, dynamic environment and adapt to evolving priorities.
  • Certifications like CISA, CRISC, CGEIT, Security+, CASP+, or similar preferred.
  • Deep expertise maintaining frameworks such as FedRAMP, DoD Cloud Computing SRG, NIST 800-171, NIST 800-53, CMMC, and STIG/RMF policies (including validation via ACAS and similar tools).
  • Familiarity with ISO 27001, ISO 42001, NIST, SOC 2, or similar compliance frameworks.
  • Background in managing third-party risk, vendor compliance programs, or federal assessments.
  • Understanding of cybersecurity controls for cloud service providers.
  • Knowledge of government cloud services and evolving certification programs.
COMPENSATION AND BENEFITS:

$100,000 - $228,000 USD

Base salary is just one part of our total rewards package at xAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks.

xAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.