1

Grc Engineer Jobs in Washington (NOW HIRING)

GRC Engineer

Vienna, VA · On-site

$140K - $170K/yr

Run the GRC calendar: tabletop exercises, prepare security committee meetings, security awareness training, and annual reviews * Identify control gaps and drive remediation across Engineering, IT, HR ...

GRC Engineer III Category: Cyber Security Main location: United States, District of Columbia, Washington Position ID:J0626-1755 Employment Type: Full Time Position Description: The GRC Engineer III ...

Senior Security Engineer, GRC

Reston, VA · On-site +1

$119K - $163K/yr

Summary Join our team as a Senior Security Engineer, GRC , where you\'ll be the primary owner of our customer-facing compliance program and a trusted partner throughout the enterprise sales cycle. In ...

... Compliance (GRC) team within the IT division at the Board of Governors of Client. This role ... engineering and delivery teams to integrate security and privacy controls into agile and DevOps ...

Senior Product Manager, GRC

Mclean, VA

$127K - $168K/yr

Senior Product Manager, GRC The Opportunity: Our Product team is defining a new product-led growth ... Partner with Data Science and Engineering to define the data ingestion, labeling, security, and ...

next page

Showing results 1-20

Grc Engineer information

See Washington salary details

$67.4K

$126.4K

$229.9K

How much do grc engineer jobs pay per year?

As of Jul 29, 2026, the average yearly pay for grc engineer in Washington is $126,434.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,200.00 and $150,100.00 per year, depending on experience, location, and employer.

What are GRC Engineers?

GRC Engineers are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization’s information security and IT frameworks. They help ensure that a company’s policies and procedures meet regulatory requirements, manage risks, and align with business objectives. GRC Engineers often implement and maintain tools, conduct risk assessments, and ensure compliance through audits and reporting. Their role is critical in minimizing risks and protecting organizational assets from security threats.

Is GRC still in demand?

GRC (Governance, Risk, and Compliance) engineers are in high demand due to increasing cybersecurity regulations and the need for organizations to manage risks effectively. Skills in risk assessment, compliance frameworks, and security tools like GRC software are valuable in this field, which is expected to grow as organizations prioritize security and regulatory adherence.

What engineers make $200,000 a year?

Senior GRC (Governance, Risk, and Compliance) engineers with extensive experience, specialized skills in cybersecurity frameworks, and relevant certifications such as CISSP or CISA can earn $200,000 or more annually. Compensation varies based on industry, location, and company size, with roles often requiring expertise in risk management, compliance standards, and security tools.

What are the key skills and qualifications needed to thrive as a GRC Engineer, and why are they important?

To thrive as a GRC Engineer, you need a solid understanding of governance, risk management, and compliance frameworks, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as RSA Archer or ServiceNow GRC), risk assessment tools, and certifications like CISA or CISSP are highly valued. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating across departments and translating complex requirements. These competencies ensure that organizations can effectively manage risk, maintain regulatory compliance, and safeguard critical information assets.

What engineers make $500,000?

Senior engineers in specialized fields such as software engineering, data engineering, or cybersecurity can earn $500,000 or more annually, especially with extensive experience, advanced skills, and in high-demand industries. Executive or leadership roles like engineering managers or directors may also reach this compensation level. Achieving this often requires advanced certifications, a strong track record, and working in competitive or high-paying markets.

What are some common challenges faced by GRC Engineers when implementing new compliance frameworks?

GRC Engineers often encounter challenges such as integrating new compliance requirements with existing IT systems, ensuring consistent documentation, and keeping up with evolving regulatory standards. Collaboration with various departments—like IT, legal, and operations—is essential to map processes accurately and address potential gaps. Proactive communication and a strong understanding of both technical and regulatory aspects help GRC Engineers overcome these hurdles and support organizational compliance effectively.

What is the difference between Grc Engineer vs Security Analyst?

AspectGrc EngineerSecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, compliance, risk managementMonitoring, incident response, threat analysis
Industry UsageCorporate governance, compliance teamsSecurity operations centers, IT departments

Grc Engineers focus on establishing and maintaining governance, risk, and compliance frameworks, ensuring organizations meet regulatory standards. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity industry, Grc Engineers emphasize policy and compliance, whereas Security Analysts focus on threat detection and response.

How much does a GRC engineer make?

A GRC (Governance, Risk, and Compliance) engineer's salary typically ranges from $80,000 to $130,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in security tools and frameworks can earn higher salaries.
What are popular job titles related to Grc Engineer jobs in Washington? For Grc Engineer jobs in Washington, the most frequently searched job titles are:
What job categories do people searching Grc Engineer jobs in Washington look for? The top searched job categories for Grc Engineer jobs in Washington are:
What cities in Washington are hiring for Grc Engineer jobs? Cities in Washington with the most Grc Engineer job openings:
Infographic showing various Grc Engineer job openings in Washington as of July 2026, with employment types broken down into 92% Full Time, 4% Part Time, and 4% Contract. Highlights an 89% Physical, 4% Hybrid, and 7% Remote job distribution, with an average salary of $126,434 per year, or $60.8 per hour.

$140K - $170K/yr

Full-time

Re-posted 25 days ago


Job description

About Antithesis
We provide a platform that helps engineering teams identify and resolve bugs that traditional testing approaches miss. Antithesis runs your entire system in a deterministic simulation, breaks it in every way imaginable, and hands you a root cause and a perfect reproduction - no flaky tests, no false positives, no "works on my machine". This allows engineering teams to debug faster and ship with greater confidence.
The rise of AI-generated code has made what we do more important than ever. Agents can write code faster than any human - but faster code isn't better code if it's buggy, stuck in review, or issues are slipping through the cracks undetected. The verification bottleneck is real and it's growing. This is exactly the problem Antithesis exists to solve. We've been quietly reinventing how the world thinks about software reliability, and we're just getting started.
We're well-funded, deeply technical, and building a platform that tackles one of the most complex yet important problems in modern software engineering. If that sounds like fun to you, keep reading.
About the Role
We are looking for our first dedicated GRC hire. This is an ownership, hands-on role.
You will build and run our compliance program end-to-end - not as a support function, but as a core part of how we earn and keep customer trust. At a company like ours, where enterprise customers need to trust us with their most sensitive infrastructure, GRC is a sales function as much as it is an operational one.
A note on what we mean by "ownership." This is not a role where you maintain a checklist someone else built. You will own the GRC calendar, the Vanta instance, the policy library, the audit evidence, and the security questionnaire queue. If something in our compliance posture is broken, that's yours to fix. If a deal is stalling because a prospect has a 40-question security questionnaire, you're the one who unblocks it.
This is an individual contributor role. It is not a CISO, not a security engineering role, and not a penetration tester. You will not own security architecture or vulnerability management - but you will need strong enough relationships with the people who do to keep those programs feeding your compliance work on time.
This role will initially report to the VP, Strategic Initiatives within the Operations team, with a strong dotted line to the Head of Infrastructure. Within the first ~3-6 months, we will collaboratively identify the long-term reporting structure for this role. This role will work closely with Operations, Legal, People (HR), Engineering, and IT.
What You'll Own
SOC 2 & Audit Management
  • Own our SOC 2 audit end-to-end, including the transition from point-in-time to a rolling 12-month window
  • Serve as the primary liaison with our external auditors
  • Maintain the evidence repository and ensure controls are documented, tested, and current
  • Own and maintain Vanta as the system of record for our compliance program

Policy & Controls
  • Maintain and continuously improve our policy library - keeping policies accurate, readable, and actually followed
  • Run the GRC calendar: tabletop exercises, prepare security committee meetings, security awareness training, and annual reviews
  • Identify control gaps and drive remediation across Engineering, IT, HR, and Operations

Trust Center & Customer-Facing Compliance
  • Own and maintain our trust center
  • Manage the inbound security questionnaire queue for enterprise sales - turn these around quickly and accurately with a sales-forward mindset to accelerate deals
  • Be the go-to resource for enterprise prospects who need to understand our security and compliance posture
  • Support vendor security reviews on both sides: evaluating vendors we onboard and participating in customer-side reviews of us

Risk Management
  • Maintain the risk register and lead regular risk review cadences
  • Identify, document, and escalate risks across people, vendors, and infrastructure

Additional
  • Support penetration testing, vulnerability management, and security architecture - Engineering and Infra lead these, but you keep them on-track and ensure findings are tracked and remediated
  • Lay groundwork for future frameworks as the business requires: e.g., ISO 27001, GDPR, FedRAMP
  • Support Legal and commercial contracting on security-related clauses and DPAs
  • Support HR policy development in partnership with the Head of HR, including security-related employee policies, acceptable use, and onboarding/offboarding procedures
Who You'll Work With
You will interface regularly with Engineering & Infrastructure, Legal, HR, Finance, and Operations. You will represent Antithesis externally in front of enterprise buyers, auditors, and security-conscious prospects.
Requirements
Required
  • 3-5 years of GRC, compliance, or IT audit experience, ideally in a SaaS or highly technical environment
  • Hands-on experience with multiple SOC 2 audits - not advisory, not adjacent, but in the room with the auditors and owning the evidence
  • Ability to go deep on our technical architecture, understand what we do and why - including bespoke features of our environment such as NixOS
  • SRE, security engineering, engineering or equivalent technical background (education and/or experience)
  • Experience with AWS and GCP infrastructure, and Infrastructure as code (IaC)
  • Strong written communication (including customer-facing communications) and comfortable writing policy, not just reviewing it
  • Ability to learn quickly in a fast-paced, high-growth environment

Nice to Have
  • Relevant certifications: CISA, CISSP, CISM, CCSK, or similar
  • Familiarity with ISO 27001, GDPR, or FedRAMP frameworks
  • Experience supporting Legal on DPAs or commercial security schedules
  • Experience owning or heavily using a GRC tool (Vanta preferred)