1

Grc Director Jobs in Silver Spring, MD (NOW HIRING)

GRC Lead

Fairfax, VA · On-site

$95 - $120/hr

Direct experience with FedRAMP, FISMA, or an equivalent federal framework, and with third-party ... A GRC Analyst onboarded, directed, and delivering, with the departing analyst's and intern ...

New

We're looking for a Senior GRC Manager to own our GRC program end to end and keep ClearDATA aligned ... You won't have direct reports, but you won't be working alone either - you'll have security ...

We're looking for a Senior GRC Manager to own our GRC program end to end and keep ClearDATA aligned ... You won't have direct reports, but you won't be working alone either - you'll have security ...

Be Seen First

SaaS GRC Sales Manager

Fairfax, VA · Remote

$100K - $160K/yr (+ commission)

GRC Fluency: Confidently converse around complex cyber compliance frameworks such as CMMC, NIST ... You will own the revenue engine that drives the majority of our growth, with direct visibility to ...

Cybersecurity GRC Program Manager

Arlington, VA · On-site

$148K - $180K/yr

Guidehouse is seeking an experienced Cybersecurity Governance, Risk, and Compliance (GRC) Program ... programs, directing multidisciplinary teams, overseeing contract performance, and delivering ...

Cybersecurity GRC Program Manager

Washington, DC · On-site

$146K - $177K/yr

Guidehouse is seeking an experienced Cybersecurity Governance, Risk, and Compliance (GRC) Program ... programs, directing multidisciplinary teams, overseeing contract performance, and delivering ...

next page

Showing results 1-20

Grc Director information

What does a GRC Director do?

A GRC Director oversees an organization’s Governance, Risk, and Compliance (GRC) programs. They are responsible for developing strategies and policies to ensure the company meets regulatory requirements, manages risks effectively, and maintains strong corporate governance. This role involves coordinating cross-functional teams, implementing compliance frameworks, and reporting to senior leadership on risk exposures and controls. The GRC Director also stays updated on changing regulations and industry best practices to protect the organization from legal and reputational risks.

What are the key skills and qualifications needed to thrive as a GRC Director?

To thrive as a GRC Director, you need deep knowledge of governance, risk management, and compliance frameworks, often supported by a relevant degree and certifications such as CISA, CRISC, or CISSP. Expertise with GRC software platforms, regulatory databases, and risk assessment tools is typically required. Exceptional leadership, strategic thinking, and communication skills enable effective cross-functional collaboration and influence at the executive level. These capabilities are critical for ensuring organizational resilience, regulatory adherence, and informed decision-making across the enterprise.

What are some common challenges a GRC Director faces when aligning compliance initiatives across multiple departments?

A GRC Director often encounters challenges such as differing departmental priorities, varying levels of compliance awareness, and inconsistent processes. Successfully aligning compliance initiatives requires strong communication, the ability to build consensus, and the development of standardized frameworks that can be adapted across departments. Regular cross-functional meetings and ongoing training can help overcome these barriers and ensure that all teams are working towards the same compliance objectives.

What is the difference between Grc Director vs Compliance Manager?

AspectGrc DirectorCompliance Manager
CredentialsCertifications like CRISC, CISA, or CISM often preferredSimilar certifications, often CCEP or CISA
Work EnvironmentOversees enterprise-wide risk, governance, and compliance strategiesFocuses on specific compliance programs within organizations
Industry UsageCommon in finance, healthcare, and large corporationsWidespread across industries, especially regulated sectors
Search IntentUnderstanding high-level risk and governance rolesLooking for specific compliance responsibilities

The Grc Director typically manages enterprise risk, governance, and compliance strategies at a high level, requiring broader oversight and strategic planning. In contrast, a Compliance Manager focuses on implementing and maintaining specific compliance programs within an organization. Both roles require similar certifications and are prevalent in regulated industries, but the Grc Director has a wider scope and strategic responsibilities.

Are GRC director jobs hard to get?

GRC Director roles are competitive and typically require extensive experience in governance, risk management, and compliance, along with relevant certifications such as CISA or CISSP. Strong leadership skills and knowledge of regulatory frameworks can improve chances, but the position often demands a proven track record in managing complex security and compliance programs.

What are the most commonly searched types of Grc jobs in Silver Spring, MD?

The most popular types of Grc jobs in Silver Spring, MD are:

What are popular job titles related to Grc Director jobs in Silver Spring, MD?

For Grc Director jobs in Silver Spring, MD, the most frequently searched job titles are:

What job categories do people searching Grc Director jobs in Silver Spring, MD look for?

The top searched job categories for Grc Director jobs in Silver Spring, MD are:

What cities near Silver Spring, MD are hiring for Grc Director jobs?

Cities near Silver Spring, MD with the most Grc Director job openings:

Infographic showing various Grc Director job openings in Silver Spring, MD as of August 2026, with employment types broken down into 2% As Needed, 85% Full Time, 10% Part Time, 1% Temporary, and 2% Contract. Highlights an 91% Physical, 3% Hybrid, and 6% Remote job distribution.

$95 - $120/hr

Other

Posted 3 days ago

New


Job description

Location: Onsite – Fairfax, VA · U.S. Citizen Required (FedRAMP / Federal Customer)

Type: Full Time

NextgenID is hiring a GRC Lead to own our governance, risk, and compliance program end-to-end. We verify and credential identity at the highest assurance level (IAL3) for federal agencies and enterprises, which means our authorizations — FedRAMP, Kantara, UK digital identity (DIATF/DVS), and the security assurances our customers depend on — are core to the business. You own the compliance calendar, the risk register, the audit and assessment relationships, and the evidence that proves our posture. You lead a GRC Analyst and report to the CTO & EVP. This is a working leadership role: you set the program, and you also do the senior, judgment-heavy work yourself.

Salary Range: $95,000–$120,000

Role Fit & Non-Negotiables
  • Onsite at our Fairfax, VA headquarters. This is a hands-on leadership role, not remote.
  • U.S. citizen, required for FedRAMP and federal-customer obligations.
  • Five or more years in governance, risk, and compliance, including ownership of a formal authorization or audit program.
  • Direct experience with FedRAMP, FISMA, or an equivalent federal framework, and with third-party (3PAO) assessments.
  • Able to make and defend risk decisions and to sign off on evidence that goes to assessors and customers.
What You Will Own (90 to 180 Day Outcomes)
  • A single, authoritative compliance calendar and program plan across FedRAMP, Kantara, UK DVS, SOC 2, and customer questionnaires.
  • The FedRAMP 20x authorization effort carried toward submission, including the 3PAO relationship, Trust Center publication, and machine-readable (OSCAL) control package.
  • A current, governed risk register and monthly POA&M process, with documented risk decisions and compensating controls.
  • Kantara 800-63A (IAL3) certification maintained, with a planned path from Rev 3 to Rev 4.
  • A functioning GRC tooling and evidence pipeline (Vanta) that keeps documentation and submissions current with less manual effort.
  • A GRC Analyst onboarded, directed, and delivering, with the departing analyst’s and intern’s workstreams fully absorbed.
Core Responsibilities

Compliance Program Leadership — own the program, the calendar, and the standard.

  • Own the compliance calendar and program plan across FedRAMP, FISMA, Kantara/NIST 800-63, UK DIATF/DVS, SOC 2, and ADA.
  • Set GRC policy, standards, and process, and keep them current and version-controlled.
  • Report compliance status, risk posture, and audit readiness to the CTO and leadership.

Authorizations & External Assessments — lead audits, 3PAOs, and certification bodies.

  • Lead FedRAMP 20x authorization: 3PAO selection and relationship, ATO timeline, Trust Center publication, and the OSCAL submission strategy.
  • Own the Kantara certification program (800-63A, IAL3) and the Rev 3 to Rev 4 transition strategy.
  • Own the UK DVS / DIATF certification, including scoping and gap-assessment leadership.

Risk Management — own the risk register and the decisions that carry risk.

  • Maintain the enterprise and vendor risk register and govern the monthly POA&M process.
  • Make and document risk decisions, risk adjustments, and compensating controls, including vendor vulnerabilities.
  • Set vulnerability remediation priorities and pentest readiness with the engineering and DevSecOps leads.

Vendor & Customer Assurance — prove our posture to third parties without slowing the business.

  • Own third-party and vendor risk assessments across our tooling and supply chain.
  • Own the security-questionnaire program (final review and sign-off) and represent our posture to customers and prospects.
  • Partner with Growth and Legal on assurance commitments and trust-center content.

Team & Tooling — deliver the program through the analyst and the toolchain.

  • Lead, mentor, and prioritize the work of the GRC Analyst and absorb the departing intern’s workstreams.
  • Own GRC tooling strategy and the evidence pipeline (Vanta, Qualys, OSCAL).
  • Coordinate engineering, DevSecOps, operations, and legal contributors to compliance deliverables.
What You Must Have Already Done
  • Owned a federal authorization or audit program (FedRAMP, FISMA, StateRAMP, or equivalent) through a 3PAO or independent assessment.
  • Built and maintained a risk register and a POA&M process, and defended risk decisions to an assessor or customer.
  • Interpreted a control framework (NIST 800-53, 800-63, or ISO 27001) and translated it into policy, procedure, and evidence.
  • Managed an external assessor or certification-body relationship end to end.
  • Led or mentored analysts and coordinated cross-functional contributors to a compliance deadline.
Required Qualifications
  • Five or more years in governance, risk, and compliance, security compliance, or audit, with program ownership.
  • Direct experience with FedRAMP and/or FISMA, including continuous monitoring (ConMon) and 3PAO assessment.
  • Working command of NIST SP 800-53 and NIST SP 800-63 (identity assurance), and of risk-assessment methodology.
  • Experience owning a risk register, a POA&M process, and a vendor-risk program.
  • Experience managing external assessors, auditors, or certification bodies.
  • Experience with GRC or compliance-automation tooling (Vanta or similar) and vulnerability tools (Qualys or Nessus).
  • Ability to make, document, and defend risk decisions.
  • Excellent written and verbal communication for assessors, customers, and executives.
  • Must be able to work onsite in Fairfax, VA; U.S. citizen (FedRAMP / federal customer).
Preferred Qualifications
  • CISA, CRISC, CISSP, or CISM certification.
  • Experience with Kantara / NIST 800-63 identity assurance (IAL2 / IAL3) certification.
  • Experience with international identity frameworks (UK DIATF / DVS) or ISO 27001 certification.
  • Experience with OSCAL or machine-readable control packages for FedRAMP 20x.
  • Background in a federal-contractor or IDaaS / identity-security environment.
  • Familiarity with SOC 2 and ADA / Section 508 accessibility assessments.
  • You own the calendar in your head: you know what is due, to whom, and what evidence proves it.
  • You make risk calls and defend them with documented reasoning, not hand-waving.
  • You turn a framework into a short list of what has to be done, and get it done.
  • You keep assessors and customers confident because your evidence is clean and current.
  • You lead through other teams, coordinating engineering and operations without owning their headcount.
What Success Looks Like
  • FedRAMP 20x reaches submission on schedule, with a published Trust Center and a machine-readable control package.
  • Kantara IAL3 certification stays current, with a credible Rev 4 transition plan.
  • A single risk register and monthly POA&M process run on cadence, with documented risk decisions.
  • Customer questionnaires and external assessments are answered accurately and on time, with no material findings from poor evidence.
  • The GRC Analyst is productive and the departing analyst’s and intern’s workstreams continue without gaps.
Why NextgenID

NextgenID builds the compliance-grade identity infrastructure that federal agencies and enterprises rely on to verify and credential identity at IAL3. Compliance is not overhead here — it is the product’s license to operate. As GRC Lead, you own the authorizations and the evidence that let us sell and deliver, and you will see your work directly in every certification we hold and every customer we win. For the right person, this is the path to a GRC Manager or Director role as the program grows.

NextgenID focuses on improving the efficiency and speed of mission critical, high assurance identity enrollment and credentialing operations that are essential to hundreds of millions of users worldwide.

Our technologies are engineered to dramatically reduce the time and cost of capturing accurate data when creating a digital identity. Our industry-neutral solutions revolve around "Supervised Remote-Identity Proofing" to automatically, securely and "remotely" perform all proofing, enrollment and credentialing processes and workflows for our customers. The industry is taking notice as we are now working with some of the largest agencies in the US Defense, intelligence, Civil, State and Local government markets, as well as other national governments and commercial organizations throughout the world.

#J-18808-Ljbffr