1

Grc Analyst Jobs in Reston, VA (NOW HIRING)

JUNIOR GRC ANALYST ROCKVILLE, MD - HYBRID LONG TERM CONTRACT SEEKING SOMEONE WHO HAS WORKED WITH THE SERVICENOW GRC APPLICATION Overview: * The GRC Analyst supports the administration of Information ...

JUNIOR GRC ANALYST ROCKVILLE, MD - HYBRID LONG TERM CONTRACT SEEKING SOMEONE WHO HAS WORKED WITH THE SERVICENOW GRC APPLICATION Overview: * The GRC Analyst supports the administration of Information ...

Privacy Analyst

Washington, DC ยท On-site

$94K - $111K/yr

Previous experience as a privacy analyst, system analyst, ISSO, security control assessor, RMF analyst, or federal GRC analyst. * Knowledge of the Privacy Act of 1974, E-Government Act privacy ...

New

Privacy Analyst

Washington, DC ยท On-site

$94K - $111K/yr

Previous experience as a privacy analyst, system analyst, ISSO, security control assessor, RMF analyst, or federal GRC analyst. * Knowledge of the Privacy Act of 1974, E-Government Act privacy ...

New

next page

Showing results 1-20

Grc Analyst information

See Reston, VA salary details

$38K

$101.8K

$238.2K

How much do grc analyst jobs pay per year?

As of Aug 9, 2026, the average yearly pay for grc analyst in Reston, VA is $101,788.00, according to ZipRecruiter salary data. Most workers in this role earn between $57,300.00 and $115,700.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a GRC analyst?

To thrive as a GRC Analyst, you need a solid understanding of governance, risk management, and compliance frameworks, often complemented by a degree in information security, business, or a related field. Experience with GRC platforms (like RSA Archer, ServiceNow, or LogicManager), and certifications such as CISA, CRISC, or CISSP are highly valued. Strong analytical thinking, attention to detail, effective communication, and collaboration skills set outstanding GRC Analysts apart. These capabilities are vital for ensuring organizations meet regulatory requirements, identify and mitigate risks, and foster a culture of compliance.

Is GRC analyst an entry level job?

A GRC analyst role can be entry-level or require some experience, depending on the organization. Entry-level positions typically focus on basic compliance, risk management, and using tools like GRC software, often requiring relevant certifications or a related degree. More advanced roles may demand several years of experience and specialized knowledge.

Is GRC analyst in high demand?

GRC analysts are in high demand due to increasing focus on cybersecurity, regulatory compliance, and risk management across industries. Organizations seek professionals with skills in risk assessment, policy development, and familiarity with tools like GRC software, making this a growing field for qualified candidates.

What does a GRC analyst do?

GRC Analysts are responsible for monitoring and assessing organizational policies, procedures, and controls to ensure compliance with internal and external regulations. Their daily tasks often include performing risk assessments, maintaining documentation, supporting audits, analyzing data for potential security gaps, and preparing reports for management. They regularly collaborate with IT, legal, and business teams to remediate vulnerabilities and strengthen compliance programs. This dynamic role requires both independent research and cross-departmental communication to help organizations proactively manage risk and regulatory obligations.

What is a GRC analyst?

A GRC (Governance, Risk, and Compliance) Analyst is responsible for ensuring that an organization adheres to regulatory requirements, industry standards, and internal policies. They assess risks, implement compliance programs, and monitor security controls to protect data and systems. Their role often involves working with various departments to identify vulnerabilities, develop risk mitigation strategies, and prepare reports for audits. GRC Analysts play a key role in maintaining regulatory compliance and enhancing an organization's overall security posture.

What are the most commonly searched types of Grc Analyst jobs in Reston, VA? The most popular types of Grc Analyst jobs in Reston, VA are:
What are popular job titles related to Grc Analyst jobs in Reston, VA? For Grc Analyst jobs in Reston, VA, the most frequently searched job titles are:
What cities near Reston, VA are hiring for Grc Analyst jobs? Cities near Reston, VA with the most Grc Analyst job openings:
Infographic showing various Grc Analyst job openings in Reston, VA as of August 2026, with employment types broken down into 38% Full Time, and 62% Contract. Highlights an 89% In-person, and 11% Remote job distribution, with an average salary of $101,788 per year, or $48.9 per hour.

Jr. GRC Analyst

System One

Rockville, MD โ€ข On-site

Contractor

Posted 12 days ago


Job description

JUNIOR GRC ANALYST ROCKVILLE, MD - HYBRID LONG TERM CONTRACT SEEKING SOMEONE WHO HAS WORKED WITH THE SERVICENOW GRC APPLICATION Overview:
  • The GRC Analyst supports the administration of Information Security Governance, Risk, and Compliance programs, including policy exception management and enterprise risk register activities using ServiceNow Integrated Risk Management (IRM).
Working under the guidance of Information Security leadership, the analyst will apply established risk assessment methodologies, workflows, and reporting processes to support enterprise cybersecurity governance and risk management initiatives. This role provides hands-on experience in information security governance, risk analysis, policy exception management, enterprise risk management, and ServiceNow IRM. Key Responsibilities: Policy Exception Management
  • Review policy exception requests for completeness and required documentation.
  • Validate business justifications and request additional information as needed.
  • Maintain exception records and track approvals in ServiceNow.
  • Monitor expiration dates, coordinate renewals, and produce status reports.
Risk Analysis
  • Conduct risk evaluations using established methodologies and templates.
  • Assess business impact, likelihood, and overall risk.
  • Identify compensating controls and document risk analyses.
  • Prepare risk-based recommendations for management review.
  • Maintain analysis records in ServiceNow.
Enterprise Risk Register Administration
  • Create, update, and maintain risk records.
  • Track risks identified through assessments, penetration tests, vulnerability scans, security incidents, and other approved sources.
  • Monitor mitigation activities, due dates, and risk status.
  • Maintain supporting documentation and generate reports.
ServiceNow IRM Administration
  • Process policy exceptions.
  • Maintain risk register records.
  • Track approvals and workflows.
  • Generate reports and dashboards.
Stakeholder Support
  • Communicate with IT staff, business stakeholders, system owners, managers, and security teams.
  • Provide professional customer service and clear written and verbal communication.
Education
  • Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, Business Information Systems, or a related field.
Preferred Certifications - at least one
  • CompTIA Security+
  • ISACA IT Risk Fundamentals
  • NIST Cybersecurity Framework (NCSF) Practitioner
  • CISM Fundamentals
  • Cybersecurity, audit, or compliance-related certifications
Experience: Required
  • One (1) year of experience in Information Security, IT Governance, Risk Management, Compliance, Audit, Information Technology, or a related field; or
  • Recent graduate with relevant internship or equivalent experience.
Preferred
  • ServiceNow experience
  • Microsoft 365 proficiency
  • GRC program experience
  • Technical documentation experience
  • Customer service and project coordination experience
Knowledge & Skills:
  • Basic understanding of cybersecurity, risk management, information security, NIST Cybersecurity Framework, and compliance concepts.
  • Strong analytical, organizational, and critical-thinking skills.
  • Excellent written and verbal communication skills.
  • Attention to detail and ability to manage multiple priorities.
  • Ability to work independently and learn new technologies quickly.
Deliverables:
  • Policy exception reviews and tracking records
  • Risk analyses and recommendations
  • Risk register entries and updates
  • Monthly metrics and quarterly reports
  • Executive dashboards
  • ServiceNow documentation and reporting artifacts
#M1 #LI-CB3 Ref: #851-Rockville-S1