1

Grc Engineer Jobs in Virginia (NOW HIRING)

Required Qualifications * 5+ years of experience as a ServiceNow Application Developer, including ... Certified Implementation Specialist - Risk and Compliance (GRC). * Experience with ServiceNow ...

GRC Analyst

Fairfax, VA · On-site

$75 - $95/hr

Two or more years in GRC, security compliance, audit support, or a closely related role ... Gather and organize evidence from engineering, DevSecOps, and operations leads. * Convert ...

Cybersecurity Engineer Job Locations US-VA-Tysons ID 2026-14452 # of Openings 1 Overview We are ... Lead or support GRC program activities including control implementation planning, risk assessments ...

Overview We are looking for a Cybersecurity Engineer to design and guide secure system ... Lead or support GRC program activities including control implementation planning, risk assessments ...

Overview We are looking for a Cybersecurity Engineer to design and guide secure system ... Lead or support GRC program activities including control implementation planning, risk assessments ...

We are looking for a Cybersecurity Engineer to design and guide secure system architectures that ... Lead or support GRC program activities including control implementation planning, risk assessments ...

ServiceNow Developer

Mclean, VA · On-site

$55.50 - $76.25/hr

Senior Developer will be part of the Enterprise Risk Management Technologies Team and will be ... Design, develop, and implement ServiceNow GRC modules in alignment with solution requirements.

next page

Showing results 1-20

Grc Engineer information

See Virginia salary details

$59K

$110.7K

$201.3K

How much do grc engineer jobs pay per year?

As of Aug 30, 2026, the average yearly pay for grc engineer in Virginia is $110,674.00, according to ZipRecruiter salary data. Most workers in this role earn between $79,800.00 and $131,400.00 per year, depending on experience, location, and employer.

What is a GRC engineer?

GRC Engineers are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization’s information security and IT frameworks. They help ensure that a company’s policies and procedures meet regulatory requirements, manage risks, and align with business objectives. GRC Engineers often implement and maintain tools, conduct risk assessments, and ensure compliance through audits and reporting. Their role is critical in minimizing risks and protecting organizational assets from security threats.

What are the key skills and qualifications needed to thrive as a GRC engineer?

To thrive as a GRC Engineer, you need a solid understanding of governance, risk management, and compliance frameworks, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as RSA Archer or ServiceNow GRC), risk assessment tools, and certifications like CISA or CISSP are highly valued. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating across departments and translating complex requirements. These competencies ensure that organizations can effectively manage risk, maintain regulatory compliance, and safeguard critical information assets.

What are some common challenges faced by GRC engineers when implementing new compliance frameworks?

GRC Engineers often encounter challenges such as integrating new compliance requirements with existing IT systems, ensuring consistent documentation, and keeping up with evolving regulatory standards. Collaboration with various departments—like IT, legal, and operations—is essential to map processes accurately and address potential gaps. Proactive communication and a strong understanding of both technical and regulatory aspects help GRC Engineers overcome these hurdles and support organizational compliance effectively.

What is the difference between Grc Engineer vs Security Analyst?

AspectGrc EngineerSecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, compliance, risk managementMonitoring, incident response, threat analysis
Industry UsageCorporate governance, compliance teamsSecurity operations centers, IT departments

Grc Engineers focus on establishing and maintaining governance, risk, and compliance frameworks, ensuring organizations meet regulatory standards. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity industry, Grc Engineers emphasize policy and compliance, whereas Security Analysts focus on threat detection and response.

Are GRC engineer jobs hard to get?

GRC (Governance, Risk, and Compliance) engineer jobs can be competitive, especially for entry-level positions, but having relevant skills in cybersecurity, risk management, and certifications like CISSP or CISA can improve chances. The difficulty of securing a GRC engineer role depends on experience, education, and the demand within the industry or organization. Strong knowledge of compliance frameworks and tools is often required to stand out.

How much do GRC engineers make?

GRC (Governance, Risk, and Compliance) engineers typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in cybersecurity tools and frameworks can earn higher salaries, often exceeding $150,000.

Is GRC engineer an entry-level job?

A GRC (Governance, Risk, and Compliance) engineer is typically an intermediate to senior role that requires relevant experience and knowledge of security frameworks, compliance standards, and risk management tools. Entry-level positions may be available but often require foundational skills, certifications, or internships in cybersecurity or IT governance.

What job categories do people searching Grc Engineer jobs in Virginia look for?

The top searched job categories for Grc Engineer jobs in Virginia are:

What cities in Virginia are hiring for Grc Engineer jobs?

Cities in Virginia with the most Grc Engineer job openings:

Infographic showing various Grc Engineer job openings in Virginia as of August 2026, with employment types broken down into 100% Contract. Highlights an 100% In-person job distribution, with an average salary of $110,674 per year, or $53.2 per hour.

Cybersecurity Engineer - GRC / RSA Archer

Richmond, VA • On-site

Electrosoft
Network Security • 51 - 200 employees

$120K - $125K/yr

Full-time

Posted 10 days ago


Job description

Electrosoft Services, LLC is an award-winning company that provides comprehensive technology-based solutions and services to federal customers. While cybersecurity is our specialty, we also focus on ICAM, Zero Trust, digital engineering and transformation, and enterprise AI and intelligent automation. We always seek to delight our customers, so we retain highly qualified employees and offer them meaningful work, growth opportunities, and work-life balance. What sets us apart from all other contractors is the sense of teamwork our employees feel - and the knowledge that outstanding effort is recognized and rewarded. The camaraderie we share emanates from Lunch & Learn sessions where we explore new ideas together, fun group activities ranging from escape rooms to miniature golf, and much, much more. If we've described you and your dream workplace, please apply and share in the many benefits and opportunities we offer.
Cybersecurity Engineer - GRC / RSA Archer
Position Summary
Electrosoft is seeking a Cybersecurity Engineer to support Governance, Risk Management, and Compliance (GRC) cybersecurity workflows within a DoD environment. The engineer will provide technical, systems, database, application, and information assurance support for the RSA Archer GRC platform and associated infrastructure.
This position will support the sustainment, enhancement, integration, testing, deployment, and lifecycle management of GRC solutions supporting DLA Cybersecurity.
Key Responsibilities
  • Provide technical, software engineering, programming, analytical, and systems support for the GRC workflow environment.
  • Maintain and troubleshoot GRC applications, servers, databases, interfaces, modules, reports, and related infrastructure.
  • Configure and modify application workflows, modules, batch programs, interfaces, reports, and documentation.
  • Analyze and resolve application, operating system, database, network, and GRC platform deficiencies.
  • Install, patch, maintain, and support Microsoft SQL databases.
  • Establish test environments and conduct testing to validate application changes and maintain program and data integrity.
  • Support GRC system architecture, development environments, database performance, and mid-tier infrastructure.
  • Identify and resolve information assurance weaknesses and vulnerabilities.
  • Support GRC application upgrades, technology refreshes, lifecycle management, and product version standardization.
  • Develop and maintain upgrade roadmaps and coordinate with enterprise architecture stakeholders.
  • Support disaster recovery planning and recovery testing for mission-critical GRC systems.
  • Perform requirements analysis and develop technical solutions supporting cybersecurity workflow integration.
  • Develop prototypes and support user acceptance testing prior to production deployment.
  • Develop technical specifications, SOPs, training materials, system documentation, and analysis reports.
  • Provide training and technical briefings to Government personnel and distributed users.

Basic Qualifications:
  • Seven (7) years of relevant IT experience
  • DOD Secret Clearance
  • Must be eligible for IT I
  • Relevant certification meeting DOD 8570/8140 IAT level III
  • Relevant certification meeting DOD 8570/8140 CND-IS
  • Computing Environment: Certified in Microsoft Windows Server 2016 or 2019. RSA Archer Certified Administrator

Pay Range
$120,000-$125,000 USD
Electrosoft is an Equal Opportunity Employer/Veterans/Disabled