1

Grc Analyst Jobs in Reston, VA (NOW HIRING)

The ideal candidate is an early-career information security or Governance, Risk, and Compliance (GRC) professional who possesses strong analytical, organizational, and communication skills, and is ...

GRC Senior System Administrator

Mclean, VA · On-site

$86K - $117K/yr

Provide fulllifecycle system administration for enterprise GRC platforms and supporting ... Deliver advanced troubleshooting and rootcause analysis for system, application, and ...

GRC Senior System Administrator

Mclean, VA · On-site

$86K - $117K/yr

Provide full-lifecycle system administration for enterprise GRC platforms and supporting ... Deliver advanced troubleshooting and root-cause analysis for system, application, and integration ...

Senior Product Manager, GRC

Mclean, VA · On-site

$127K - $168K/yr

Senior Product Manager, GRC The Opportunity: Our Product team is defining a new product-led growth ... Experience analyzing and solving problems * Ability to manage the entire product lifecycle, from ...

next page

Showing results 1-20

Grc Analyst information

See Reston, VA salary details

$38K

$101.8K

$238.2K

How much do grc analyst jobs pay per year?

As of Jul 19, 2026, the average yearly pay for grc analyst in Reston, VA is $101,788.00, according to ZipRecruiter salary data. Most workers in this role earn between $57,300.00 and $115,700.00 per year, depending on experience, location, and employer.

Is GRC a good career?

A GRC (Governance, Risk, and Compliance) analyst plays a key role in managing an organization’s security policies, risk assessments, and regulatory compliance. It is a growing field with demand for professionals skilled in frameworks like ISO, NIST, and tools such as audit management software. The role often requires certifications like CISA or CISSP and offers opportunities for career advancement in cybersecurity and risk management.

Is GRC an entry level job?

GRC Analyst roles can be entry-level or require some experience, depending on the organization. Entry-level positions typically focus on basic compliance, risk management, and security controls, often requiring foundational knowledge of cybersecurity or IT. More advanced roles may demand certifications like CISSP or CISA and prior experience in security or audit functions.

What are the key skills and qualifications needed to thrive in the Grc Analyst position, and why are they important?

To thrive as a GRC Analyst, you need a solid understanding of governance, risk management, and compliance frameworks, often complemented by a degree in information security, business, or a related field. Experience with GRC platforms (like RSA Archer, ServiceNow, or LogicManager), and certifications such as CISA, CRISC, or CISSP are highly valued. Strong analytical thinking, attention to detail, effective communication, and collaboration skills set outstanding GRC Analysts apart. These capabilities are vital for ensuring organizations meet regulatory requirements, identify and mitigate risks, and foster a culture of compliance.

What does a GRC analyst do?

A GRC analyst (Governance, Risk, and Compliance analyst) is responsible for managing an organization’s compliance with regulations, assessing and mitigating risks, and developing governance frameworks. They often use tools like risk management software and require knowledge of industry standards such as ISO or NIST. The role involves analyzing policies, conducting audits, and ensuring security controls are effective.

Do GRC analysts work from home?

GRC analysts can often work remotely, especially if their employer supports telecommuting and the role involves tasks like risk assessment, policy development, and compliance monitoring that can be performed online. However, some positions may require on-site presence for meetings, audits, or access to secure systems.

What are the typical daily responsibilities of a GRC Analyst?

GRC Analysts are responsible for monitoring and assessing organizational policies, procedures, and controls to ensure compliance with internal and external regulations. Their daily tasks often include performing risk assessments, maintaining documentation, supporting audits, analyzing data for potential security gaps, and preparing reports for management. They regularly collaborate with IT, legal, and business teams to remediate vulnerabilities and strengthen compliance programs. This dynamic role requires both independent research and cross-departmental communication to help organizations proactively manage risk and regulatory obligations.

What is a GRC Analyst job?

A GRC (Governance, Risk, and Compliance) Analyst is responsible for ensuring that an organization adheres to regulatory requirements, industry standards, and internal policies. They assess risks, implement compliance programs, and monitor security controls to protect data and systems. Their role often involves working with various departments to identify vulnerabilities, develop risk mitigation strategies, and prepare reports for audits. GRC Analysts play a key role in maintaining regulatory compliance and enhancing an organization's overall security posture.

What are the most commonly searched types of Grc Analyst jobs in Reston, VA? The most popular types of Grc Analyst jobs in Reston, VA are:
What are popular job titles related to Grc Analyst jobs in Reston, VA? For Grc Analyst jobs in Reston, VA, the most frequently searched job titles are:
What job categories do people searching Grc Analyst jobs in Reston, VA look for? The top searched job categories for Grc Analyst jobs in Reston, VA are:
What cities near Reston, VA are hiring for Grc Analyst jobs? Cities near Reston, VA with the most Grc Analyst job openings:
Infographic showing various Grc Analyst job openings in Reston, VA as of July 2026, with employment types broken down into 1% Locum Tenens, 1% Internship, 86% Full Time, 6% Part Time, 1% Temporary, and 5% Contract. Highlights an 82% Physical, 5% Hybrid, and 13% Remote job distribution, with an average salary of $101,788 per year, or $48.9 per hour.
GRC Analyst

Other

Posted 4 days ago


Job description

About us:

Creative Information Technology Inc (CITI) is an esteemed IT enterprise renowned for its exceptional customer service and innovation. We serve both government and commercial sectors, offering a range of solutions such as Healthcare IT, Human Services, Identity Credentialing, Cloud Computing, and Big Data Analytics. With clients in the US and abroad, we hold key contract vehicles including GSA IT Schedule 70, NIH CIO-SP3, GSA Alliant, and DHS-Eagle II.

Join us in driving growth and seizing new business opportunities!

 

Position Description:

The ideal candidate is an early-career information security or Governance, Risk, and Compliance (GRC) professional who possesses strong analytical, organizational, and communication skills, and is seeking to build a long-term career in enterprise information security governance and risk management.

The successful candidate will be self-motivated, detail-oriented, and capable of learning and consistently applying established County policies, procedures, and risk assessment methodologies. The individual should demonstrate sound judgment, professionalism, and a commitment to delivering high-quality work while effectively managing multiple assignments and competing priorities.

Responsibilities:

·        Analyze information objectively and identify missing or incomplete information.

·        Learn and consistently apply established policies, procedures, and standardized risk assessment methodologies.

·        Communicate professionally and effectively with both technical and non-technical stakeholders.

·        Prepare clear, concise, and well-organized written documentation and recommendations.

·        Manage multiple assignments while meeting established deadlines.

·        Work independently with minimal supervision while recognizing when guidance is appropriate.

·        Exercise sound judgment and maintain objectivity when evaluating information.

·        Provide excellent customer service while maintaining compliance with County policies and procedures.

·        Demonstrate integrity, professionalism, discretion, and attention to detail when handling sensitive information.

·        Adapt to changing priorities and continuously seek opportunities to improve processes and personal knowledge.

 

Required Skills:

·        Experience using ServiceNow.

·        Experience using Office 365 suite of products

·        Experience with Governance, Risk and Compliance (GRC).

·        Experience preparing technical documentation.

·        Experience working in customer service environments.

·        Experience with coordinating projects, tasks and/or workflows.

Desired Skills:

·        Strong analytical thinking

·        Excellent written communication

·        Excellent verbal communication

·        Customer service

·        Organization

·        Attention to detail

·        Time management

·        Critical thinking

·        Ability to learn new technologies quickly

·        Ability to work independently

·        Professionalism

·        Ability to manage multiple priorities

Education and certifications:

Bachelor’s degree in:

  • Cybersecurity
  • Information Systems
  • Information Technology
  • Computer Science
  • Business Information Systems

Certifications (not required/points awarded)

  • CompTIA Security+ (Sec+)
  • Certified Information Security Manager – Fundamentals (CISM‑F)
  • NIST Cybersecurity Framework (NCSF) Practitioner
  • ISACA IT Risk Fundamentals Certificate
  • ISACA Cybersecurity Audit Certificate
  • HIPAA Security Training or Compliance Certificate