1

Grc Engineer Jobs in Alabama (NOW HIRING)

ServiceNow Developer

Montgomery, AL · On-site

$40 - $50/hr

Role Summary Seeking an experienced ServiceNow Developer to design, develop, test, and implement ... Prior experience working with ServiceNow ITSM, SecOps, and GRC/IRM modules. * Knowledge of CMDB and ...

Mission Multiplier is looking for a Systems Engineer, SME to support one of our subcontracts onsite ... Experience with GRC tools (RiskVision, Xacta and JCAM) * Microsoft Windows, Active Directory

Senior Security Control Assessor

Huntsville, AL · On-site

$113K - $155K/yr

Manage the SAA process for new FBI ISs and legacy FBI ISs migrating into the GRC application * Provide baseline security controls to the system owner, contingent upon the IS's security categorization ...

Senior Security Control Assessor

Huntsville, AL · On-site

$113K - $155K/yr

Manage the SAA process for new FBI ISs and legacy FBI ISs migrating into the GRC application * Provide baseline security controls to the system owner, contingent upon the IS's security categorization ...

Showing results 21-32

Grc Engineer information

See Alabama salary details

$53.9K

$101.2K

$184K

How much do grc engineer jobs pay per year?

As of Aug 17, 2026, the average yearly pay for grc engineer in Alabama is $101,182.00, according to ZipRecruiter salary data. Most workers in this role earn between $73,000.00 and $120,100.00 per year, depending on experience, location, and employer.

What is a GRC engineer?

GRC Engineers are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization’s information security and IT frameworks. They help ensure that a company’s policies and procedures meet regulatory requirements, manage risks, and align with business objectives. GRC Engineers often implement and maintain tools, conduct risk assessments, and ensure compliance through audits and reporting. Their role is critical in minimizing risks and protecting organizational assets from security threats.

What are the key skills and qualifications needed to thrive as a GRC engineer?

To thrive as a GRC Engineer, you need a solid understanding of governance, risk management, and compliance frameworks, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as RSA Archer or ServiceNow GRC), risk assessment tools, and certifications like CISA or CISSP are highly valued. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating across departments and translating complex requirements. These competencies ensure that organizations can effectively manage risk, maintain regulatory compliance, and safeguard critical information assets.

What are some common challenges faced by GRC engineers when implementing new compliance frameworks?

GRC Engineers often encounter challenges such as integrating new compliance requirements with existing IT systems, ensuring consistent documentation, and keeping up with evolving regulatory standards. Collaboration with various departments—like IT, legal, and operations—is essential to map processes accurately and address potential gaps. Proactive communication and a strong understanding of both technical and regulatory aspects help GRC Engineers overcome these hurdles and support organizational compliance effectively.

What is the difference between Grc Engineer vs Security Analyst?

AspectGrc EngineerSecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, compliance, risk managementMonitoring, incident response, threat analysis
Industry UsageCorporate governance, compliance teamsSecurity operations centers, IT departments

Grc Engineers focus on establishing and maintaining governance, risk, and compliance frameworks, ensuring organizations meet regulatory standards. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity industry, Grc Engineers emphasize policy and compliance, whereas Security Analysts focus on threat detection and response.

Are GRC engineer jobs hard to get?

GRC (Governance, Risk, and Compliance) engineer jobs can be competitive, especially for entry-level positions, but having relevant skills in cybersecurity, risk management, and certifications like CISSP or CISA can improve chances. The difficulty of securing a GRC engineer role depends on experience, education, and the demand within the industry or organization. Strong knowledge of compliance frameworks and tools is often required to stand out.

How much do GRC engineers make?

GRC (Governance, Risk, and Compliance) engineers typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in cybersecurity tools and frameworks can earn higher salaries, often exceeding $150,000.

Is GRC engineer an entry-level job?

A GRC (Governance, Risk, and Compliance) engineer is typically an intermediate to senior role that requires relevant experience and knowledge of security frameworks, compliance standards, and risk management tools. Entry-level positions may be available but often require foundational skills, certifications, or internships in cybersecurity or IT governance.

What are popular job titles related to Grc Engineer jobs in Alabama?

For Grc Engineer jobs in Alabama, the most frequently searched job titles are:

What job categories do people searching Grc Engineer jobs in Alabama look for?

The top searched job categories for Grc Engineer jobs in Alabama are:

What cities in Alabama are hiring for Grc Engineer jobs?

Cities in Alabama with the most Grc Engineer job openings:

Infographic showing various Grc Engineer job openings in Alabama as of August 2026, with employment types broken down into 90% Full Time, 4% Part Time, and 6% Contract. Highlights an 85% Physical, 6% Hybrid, and 9% Remote job distribution, with an average salary of $101,182 per year, or $48.6 per hour.

Information Systems Security Engineer SME with Security Clearance

ECS

Huntsville, AL • On-site

$155K - $168K/yr

Other

Re-posted 9 days ago


Job description

Job Description ECS is seeking an experienced Information Systems Security Engineer SME to support a mission-critical federal cybersecurity programs in the Red Stone Arsenal area. The selected candidate will serve as a senior cybersecurity engineering expert supporting Security Assessment and Authorization, Risk Management Framework execution, cloud security, technical control implementation, assessment readiness, continuous monitoring, vulnerability remediation, audit support, and risk-informed authorization activities. This role is ideal for a senior cybersecurity professional who can operate at both the strategic and technical levels and who is passionate in leading security engineering efforts, mentoring cybersecurity personnel, advising stakeholders, improving authorization quality, and translating complex technical risks into clear, actionable recommendations. Please Note: This position is contingent upon contract award. Salary Range: $155,000 - $168,000 Key responsibilities include: * Lead and support full lifecycle RMF and Security Assessment and Authorization activities for federal information systems. * Provide senior technical guidance to system owners, ISSOs, ISSMs, engineering teams, program leadership, and authorization stakeholders. * Advise on system categorization, security control selection and tailoring, control implementation, assessment readiness, risk analysis, and authorization package quality. * Review and strengthen RMF documentation, including System Security Plans, control implementation descriptions, risk assessments, security test plans, assessment results, POA&Ms, inventories, network diagrams, data flow diagrams, and continuous monitoring artifacts. * Evaluate technical, operational, and management controls to determine whether safeguards are implemented correctly, operating as intended, and supported by complete evidence. * Identify technical control gaps and develop remediation recommendations that are practical, risk-informed, and aligned to federal cybersecurity standards. * Support cloud security engineering activities for systems using AWS, Azure, Google Cloud, or hybrid environments. * Provide technical input for vulnerability remediation, patch compliance, POA&M tracking, emergency directive response, audit readiness, and corrective action planning. * Support security impact analysis for proposed technical changes, including architecture updates, system integrations, cloud services, network changes, and control modifications. * Develop or improve templates, checklists, SOPs, evidence standards, dashboards, and repeatable processes that improve quality, consistency, and efficiency. * Track and communicate risks, findings, action items, assessment status, remediation progress, and improvement opportunities to stakeholders and leadership. * Maintain current knowledge of RMF, NIST, CNSS, FISMA, cloud security, and federal cybersecurity best practices. Required Skills * Active Top Secret clearance with SCI eligibility. * U.S. citizenship. * 10+ years of experience in secure design, analysis, and testing of information security systems and products. * 10+ years of experience applying cybersecurity methods, standards, and approaches to ensure baseline security safeguards are properly implemented and documented. * 10+ years of experience creating or updating security test plans to detect, assess, and mitigate risk to information systems. * CISSP or CEH required. * Experience supporting RMF, ATO, SAA, continuous monitoring, POA&M management, vulnerability remediation, security assessment, and audit readiness activities. * Experience developing, reviewing, or improving federal cybersecurity documentation and authorization artifacts. * Knowledge of NIST SP 800-53, NIST SP 800-53A, FIPS 199, FIPS 200, CNSS guidance, FISMA, and federal information security requirements. * Ability to assess technical security evidence and provide risk-based recommendations to technical and non-technical stakeholders. * Strong written and verbal communication skills. * Ability to lead teams, mentor personnel, coordinate across multiple stakeholders, and manage complex cybersecurity tasks in a high-accountability environment. Desired Skills * Cloud security certification preferred, such as CCSP, AWS Certified Security - Specialty, AWS Certified Solutions Architect, Microsoft Azure Security Engineer Associate, or Google Professional Cloud Security Engineer. * Experience securing AWS, Azure, Google Cloud, or hybrid cloud environments. * Experience with GRC tools, control inheritance, evidence reuse, dashboard reporting, and workflow automation. * Experience with tools such as Tenable Nessus, Security Center, Splunk, IBM Guardium, WebInspect, Nmap, or similar security platforms. * Experience supporting classified federal environments, national security systems, law enforcement systems, intelligence systems, or high-impact mission systems. ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law. is the federal segment of , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies. Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow. We value: * Attracting and developing top talent and high-performing teams * Fostering a culture that is engaging, accountable, and mission-driven