1

Governance Risk Compliance Jobs in Springfield, VA

The Counsel, AI Risk & Compliance serve at the intersection of legal, technology, risk management ... This role guides the evaluation, deployment, and governance of artificial intelligence tools and ...

next page

Showing results 1-20

Governance Risk Compliance information

See Springfield, VA salary details

$32.9K

$71.8K

$117K

How much do governance risk compliance jobs pay per year?

As of Aug 4, 2026, the average yearly pay for governance risk compliance in Springfield, VA is $71,792.00, according to ZipRecruiter salary data. Most workers in this role earn between $51,200.00 and $90,400.00 per year, depending on experience, location, and employer.

What are jobs in governance risk compliance?

Governance risk compliance (GRC) is a method for managing and strategizing an organization's regulations regarding governance, financial or physical risk, and regulatory compliance. It aligns the IT aspects with business objectives and works to improve the efficiency of a company. There are GRC consultants and GRC analysts who provide an assessment of a business’s GRC, identify risks, analyze the data, develop policies to benefit the workplace, and consult on the best choice of action. Your duties may involve optimizing GRC systems, implementing tactics to lower risk, providing internal audits, assisting with cybersecurity, creating routine reports, and ensuring regulatory compliance.

What is the work of governance risk compliance?

Governance, Risk, and Compliance (GRC) professionals develop and implement policies to ensure organizations adhere to legal and regulatory requirements, manage risks, and maintain ethical standards. They analyze business processes, conduct audits, and use tools like risk management software to identify vulnerabilities and ensure compliance across departments.

What is governance risk compliance?

Governance, Risk, and Compliance (GRC) is a coordinated strategy that organizations use to manage overall governance, enterprise risk management, and compliance with regulations and standards. GRC professionals help organizations align their business objectives with risk management practices and regulatory requirements. This role involves identifying potential risks, implementing policies to mitigate those risks, and ensuring that the organization adheres to legal, ethical, and internal standards. Effective GRC management can improve decision-making, optimize processes, and protect the organization from financial or reputational harm.

How does a governance risk compliance professional typically collaborate with other departments within an organization?

GRC professionals work closely with a variety of departments, including IT, legal, finance, and operations, to ensure that organizational policies and regulatory requirements are consistently met. Collaboration often involves leading risk assessments, facilitating compliance training, and coordinating audits to identify and mitigate potential risks. Effective communication and relationship-building are key, as GRC teams must translate complex regulations into actionable steps for different business units. This cross-functional approach helps embed a culture of compliance and risk awareness throughout the organization.

What is the difference between Governance Risk Compliance vs Risk Analyst?

AspectGovernance Risk ComplianceRisk Analyst
CertificationsCRISC, CISA, CISSPCFA, FRM, CRISC
Work EnvironmentCorporate, regulated industriesFinancial, consulting firms
Employer & Industry UsageFinancial institutions, healthcare, governmentBanking, investment firms, insurance

Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing enterprise-wide risks. Risk Analysts primarily assess specific financial or operational risks through data analysis. While both roles involve risk management, Governance Risk Compliance has a broader scope related to organizational compliance and governance frameworks, whereas Risk Analysts concentrate on analyzing and quantifying particular risks.

What are the key skills and qualifications needed to thrive as a governance risk compliance professional?

To thrive as a Governance Risk Compliance professional, you need a solid understanding of regulatory frameworks, risk management principles, and policy development, often supported by a degree in business, law, or information security. Familiarity with GRC software platforms, compliance management systems, and certifications like CISA, CRISC, or CISSP is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set top performers apart in this field. These competencies are essential for ensuring organizational compliance, minimizing risks, and maintaining robust corporate governance.
What are the most commonly searched types of Governance Risk Compliance jobs in Springfield, VA? The most popular types of Governance Risk Compliance jobs in Springfield, VA are:
What cities near Springfield, VA are hiring for Governance Risk Compliance jobs? Cities near Springfield, VA with the most Governance Risk Compliance job openings:
Infographic showing various Governance Risk Compliance job openings in Springfield, VA as of July 2026, with employment types broken down into 1% As Needed, 82% Full Time, 12% Part Time, and 5% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $71,792 per year, or $34.5 per hour.

Governance, Risk & Compliance (GRC) Analyst

SkyePoint Decisions

Washington, DC • Remote

Full-time

This job post has expired today. Applications are no longer accepted.


Job description

SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider headquartered in Dulles, Virginia with operations across the U.S. We provide innovative enterprise-wide solutions as well as targeted services addressing the complex challenges faced by our federal government clients. Our focus is on enabling our clients to deliver their mission most efficiently and effectively – anytime, anywhere, securely. We combine technical expertise, mission awareness, and an empowered workforce to produce meaningful results.

This is a contingent position based on contract win.

SkyePoint Decisions is seeking a Governance, Risk & Compliance (GRC) Analyst to support a cybersecurity program and compliance initiatives by managing governance processes, risk management activities, policy compliance efforts, and audit readiness programs. The GRC Analyst serves as a key contributor to ensuring information systems and cybersecurity operations comply with Federal regulations, NIST standards and HHS policies.

The position supports an integrated cybersecurity risk and compliance program by linking risks, POA&Ms, vulnerabilities, audit findings, incidents, corrective actions, and governance reporting to support executive decision-making and authorization activities. Collaborates with cybersecurity teams, system owners, ISSOs, auditors, and leadership to identify risks, monitor compliance, maintain governance documentation, and support continuous improvement of the organization's cybersecurity posture.

This position is fully remote.

Responsibilities:

  • Support governance and compliance activities within GRC platforms.
  • Maintain compliance records, risks, findings, and corrective action tracking.
  • Ensure data accuracy and completeness within governance systems.
  • Assist users with governance workflows and compliance processes.
  • Generate reports and metrics from GRC tools and repositories.
  • Support development, maintenance, and implementation of cybersecurity policies, procedures, standards, and guidelines.
  • Assist in mapping organizational controls to Federal cybersecurity requirements and frameworks.
  • Maintain governance documentation and standards repositories.
  • Ensure policies and procedures remain aligned with Federal requirements.
  • Support policy reviews, updates, and compliance assessments.
  • Maintain and update cybersecurity risk registers.
  • Perform risk identification, analysis, and tracking activities.
  • Support risk assessments and risk mitigation planning.
  • Monitor remediation activities for identified risks and control deficiencies.
  • Develop and maintain cybersecurity compliance metrics and reporting.
  • Support creation of executive dashboards and compliance scorecards.
  • Analyze program performance indicators and identify trends.

Required Qualifications:

  • Bachelor's degree in Cybersecurity, Information Systems, Information Assurance, Business Administration, or a related field.
  • Minimum 5 years of experience in cybersecurity governance, risk management, compliance, audit support, or information assurance.
  • Experience supporting Federal cybersecurity programs.
  • Knowledge of:
    • NIST Cybersecurity Framework (CSF)
    • NIST Risk Management Framework (RMF)
    • NIST SP 800-53 Rev. 5
    • FISMA
    • Federal cybersecurity compliance requirements
  • Experience conducting compliance reviews, risk assessments, or audit preparation activities.
  • Strong analytical, organizational, and written communication skills.
  • U.S. Citizenship required.
  • Ability to obtain and maintain a Public Trust.

Preferred Qualifications:

  • One or more of the following certifications:
    • CGRC (formerly CAP)
    • CRISC
    • CISA
    • CISSP
    • CISM
    • Security+
    • Certified in Governance, Risk and Compliance (GRC)
  • Experience supporting NIH, HHS, or other Federal civilian agencies.
  • Experience with governance and compliance platforms such as:
    • ServiceNow GRC
    • Archer
    • eMASS
    • Xacta
  • Experience supporting FISMA audits and OIG assessments.
  • Knowledge of Zero Trust Architecture and Federal cybersecurity modernization initiatives.
  • Experience developing executive-level cybersecurity reporting and dashboards.
  • Familiarity with privacy compliance requirements, including PTAs and PIAs.

Compensation:

Salary Range: $80,000 - $100,00

The SkyePoint Decisions salary range for this position is a general guideline only. It represents an estimated range for this position and is just one piece of our total compensation package.

Salary at SkyePoint is determined by various factors, including but not limited to location, work schedule, the candidate's combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability, market data and business considerations.

In addition to a competitive salary, SkyePoint offers benefits including a certification incentive program, PTO, floating federal holiday options, several insurance options including HMO and High Deductible plans with Health Savings Accounts [HSAs], Flex Spending Accounts [FSAs], Full Dental Plans, Vision, ST/LT Disability, Life Insurance, and 401k matched.

What We Can Offer You:

  • At SkyePoint, we go B.I.G. (beginning in GRATITUDE) by recognizing all we have and giving back to our employees, families, and communities. It instills a positive mindset that permeates all we do. By beginning in gratitude, SkyePoint can continue to spread living in gratitude each day.
  • Great Benefits: Several insurance options including HMO and High Deductible plans with Health Savings Accounts [HSAs], Flex Spending Accounts [FSAs], Full Dental Plans, ST/LT Disability, Life Insurance, floating federal holiday options, and 401k matched
  • Certificate Incentive Program: To promote professional development, we recognize and reward employees who obtain new certifications aligned with business needs.
  • Flexible Work Environment

SkyePoint Decisions is an established ISO 9001:2015 and ISO/IEC 27001:2013 certified small business and appraised at CMMI Level 3 for Services and Development. We possess a common vision of excellence and foster a collaborative team culture built upon individual performance and accountability. We invest in our people and systems to create value for our clients. It is the SkyePoint Way. We are grateful for the opportunity to work with exceptional people and give back to the communities we serve. Our employees value the flexibility at SkyePoint that allows them to balance quality work and their personal lives.

SkyePoint Decisions is a participating E-Verify Employer.

U.S. Citizenship is required for most positions.

Equal Opportunity Employer/Veterans/Disabled.

CCPA Disclosure Notice Here