1

Grc Engineer Jobs in Baltimore, MD (NOW HIRING)

The role is not intended to be a hands-on vulnerability engineering role; rather, it ensures the ... Cyber GRC support for policies, controls, cyber risk tracking, audit coordination, exceptions, and ...

Lead the assessment, configuration, and deployment of ServiceNow IRM, GRC, and SecOps modules ... BA/BS Degree in Computer Science, Cyber Security, Information Security, Engineering, Information ...

Provide architecture and engineering teams with a governed, extensible platform for business ... Equip Cyber and GRC teams with automation pipelines, policy attestation workflows, and operational ...

next page

Showing results 1-20

Grc Engineer information

See Baltimore, MD salary details

$59.1K

$110.9K

$201.7K

How much do grc engineer jobs pay per year?

As of Aug 30, 2026, the average yearly pay for grc engineer in Baltimore, MD is $110,922.00, according to ZipRecruiter salary data. Most workers in this role earn between $80,000.00 and $131,700.00 per year, depending on experience, location, and employer.

What is a GRC engineer?

GRC Engineers are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization’s information security and IT frameworks. They help ensure that a company’s policies and procedures meet regulatory requirements, manage risks, and align with business objectives. GRC Engineers often implement and maintain tools, conduct risk assessments, and ensure compliance through audits and reporting. Their role is critical in minimizing risks and protecting organizational assets from security threats.

What are the key skills and qualifications needed to thrive as a GRC engineer?

To thrive as a GRC Engineer, you need a solid understanding of governance, risk management, and compliance frameworks, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as RSA Archer or ServiceNow GRC), risk assessment tools, and certifications like CISA or CISSP are highly valued. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating across departments and translating complex requirements. These competencies ensure that organizations can effectively manage risk, maintain regulatory compliance, and safeguard critical information assets.

What are some common challenges faced by GRC engineers when implementing new compliance frameworks?

GRC Engineers often encounter challenges such as integrating new compliance requirements with existing IT systems, ensuring consistent documentation, and keeping up with evolving regulatory standards. Collaboration with various departments—like IT, legal, and operations—is essential to map processes accurately and address potential gaps. Proactive communication and a strong understanding of both technical and regulatory aspects help GRC Engineers overcome these hurdles and support organizational compliance effectively.

What is the difference between Grc Engineer vs Security Analyst?

AspectGrc EngineerSecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, compliance, risk managementMonitoring, incident response, threat analysis
Industry UsageCorporate governance, compliance teamsSecurity operations centers, IT departments

Grc Engineers focus on establishing and maintaining governance, risk, and compliance frameworks, ensuring organizations meet regulatory standards. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity industry, Grc Engineers emphasize policy and compliance, whereas Security Analysts focus on threat detection and response.

Are GRC engineer jobs hard to get?

GRC (Governance, Risk, and Compliance) engineer jobs can be competitive, especially for entry-level positions, but having relevant skills in cybersecurity, risk management, and certifications like CISSP or CISA can improve chances. The difficulty of securing a GRC engineer role depends on experience, education, and the demand within the industry or organization. Strong knowledge of compliance frameworks and tools is often required to stand out.

How much do GRC engineers make?

GRC (Governance, Risk, and Compliance) engineers typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in cybersecurity tools and frameworks can earn higher salaries, often exceeding $150,000.

Is GRC engineer an entry-level job?

A GRC (Governance, Risk, and Compliance) engineer is typically an intermediate to senior role that requires relevant experience and knowledge of security frameworks, compliance standards, and risk management tools. Entry-level positions may be available but often require foundational skills, certifications, or internships in cybersecurity or IT governance.

What job categories do people searching Grc Engineer jobs in Baltimore, MD look for?

The top searched job categories for Grc Engineer jobs in Baltimore, MD are:

What cities near Baltimore, MD are hiring for Grc Engineer jobs?

Cities near Baltimore, MD with the most Grc Engineer job openings:

Infographic showing various Grc Engineer job openings in Baltimore, MD as of August 2026, with employment types broken down into 100% Contract. Highlights an 100% In-person job distribution, with an average salary of $110,922 per year, or $53.3 per hour.

Cyber GRC Specialist

Brown Advisory

Baltimore, MD • On-site

Full-time

Medical, Dental, Vision, Life, Retirement

Posted 22 days ago


Job description

Company Overview


Every firm has a culture - the values, beliefs, methodology, attitudes and standards that reflect an organization's DNA. But the truly inspiring firms - the game-changers, the industry leaders and the disruptors - have cultures that propel them to innovate and stand out. At Brown Advisory, we aim to be one of those inspired firms. Over the years, we have purposefully built and nurtured our client-first culture.

Brown Advisory is an independent investment management and strategic advisory firm committed to delivering a combination of first-class performance, strategic advice and the highest level of client service. The firm's clients-including individuals, families, family offices, endowments, foundations, charities, institutions, consultants, and financial intermediaries-are served by over 1,000 colleagues worldwide, all of whom are equity owners of the firm.

Brown Advisory is currently seeking a Cyber GRC Specialist to support and mature the firm's governance, risk, compliance, and control-management routines. This blended role is designed for someone who can translate security requirements into practical business processes, drive evidence and accountability, and communicate clearly with technical and non-technical stakeholders.

As part of a lean Information Security team within a mid-sized financial services organization, this individual will serve as a central coordinator for cyber risk, policy management, control testing, audit readiness, client and regulatory response support, and vulnerability remediation governance. The role is not intended to be a hands-on vulnerability engineering role; rather, it ensures the process, ownership, exceptions, reporting, and governance routines are working.

Blended Role Coverage

Primary emphasis: Cyber GRC support for policies, controls, cyber risk tracking, audit coordination, exceptions, and governance routines.

Blended coverage: Cyber Risk / Compliance Analyst work, ISO and risk-platform support, evidence coordination, client/regulatory response support, communications, and vulnerability governance.

Duties and Responsibilities

  • Support and mature core cyber governance routines, including policy management, control ownership, risk acceptance, exception handling, standards maintenance, and periodic leadership reporting.

  • Maintain the cyber risk register and partner with technology and business owners to document risk decisions, remediation plans, due dates, dependencies, and residual risk.

  • Serve as a key administrator and process contributor for ISO and security-risk management platforms such as Vanta or similar tools.

  • Coordinate evidence collection, control testing, audit requests, client due diligence responses, regulatory requests, and recurring compliance deliverables.

  • Translate ISO 27001, regulatory, client, and internal security expectations into practical controls and operating procedures appropriate for Brown Advisory's size and risk profile.

  • Facilitate cross-functional communications for security change, SaaS inventory, policy enforcement, control adoption, and risk remediation.

  • Coordinate vulnerability management governance, including scan-result intake, prioritization routines, remediation tracking, exception handling, and reporting.

  • Partner with security engineers, infrastructure teams, application owners, Compliance, Legal, Operations, and Client Service to close control gaps in a business-aligned manner.

  • Develop clear metrics for control effectiveness, audit readiness, exceptions, overdue remediation, and recurring governance activities.

  • Identify process improvements that make security governance more repeatable, transparent, and useful without creating unnecessary bureaucracy.

Preferred Qualifications

  • Bachelor's degree in cyber security, information systems, risk management, business, or a relevant field preferred; equivalent professional experience will be considered.

  • 3-6 years of experience in cyber GRC, information security, technology risk, IT audit, compliance, or related control-management work preferred.

  • Working knowledge of ISO 27001, SOC 2, NIST CSF, CIS Controls, SEC/FINRA expectations, privacy requirements, or comparable control frameworks.

  • Experience supporting audits, evidence collection, control testing, policy updates, issue tracking, or risk-register maintenance in a regulated environment; financial services experience preferred.

  • CISA, CRISC, CISM, Security+, ISO 27001 Foundation/Lead Implementer, or similar professional designation preferred but not required.

Technical Skills

  • Cyber risk registers, exception management, control testing, evidence management, policy lifecycle management, and audit coordination.

  • GRC or trust-management platforms such as Vanta, Archer, ServiceNow GRC, OneTrust, Drata, or similar tools.

  • Vulnerability management governance, including prioritization, remediation tracking, aging analysis, exception workflows, and executive reporting.

  • Strong knowledge of cyber security controls across identity, endpoint, cloud, network, data protection, application security, and third-party risk.

  • Excellent writing, facilitation, and stakeholder-management skills, including the ability to turn technical risk into clear business language.

  • Practical judgment about when to enforce, when to escalate, and when to help the business find a workable control path.

  • Demonstrates curiosity and a continuous improvement mindset by identifying opportunities to enhance processes, improve efficiency, and thoughtfully leverage new technologies and tools, including AI-enabled productivity solutions

Personal Attributes

  • Take ownership and move initiatives forward without constant oversight.

  • Balance technical depth, process discipline, and sound business judgment.

  • Approach risk management pragmatically rather than theoretically.

  • Thrive in collaborative, high-accountability environments.

  • Communicate clearly with technical and non-technical colleagues.

  • Bring an entrepreneurial mindset to building and improving security capabilities.

Applicants must be authorized to work in the United States without the need for current or future employer-sponsored work authorization (e.g., H-1B , O-1, F-1 (OPT), TN, or any other non-immigrant visa classifications that require employer support or sponsorship).

MD Salary: $95-$115k. Commensurate with experience and location. Does not include bonus or long term incentive eligibility (if applicable).

DC Salary: $104.5K-$126.5K. Commensurate with experience and location. Does not include bonus or long-term incentive eligibility (if applicable).

Benefits


At Brown Advisory we offer a competitive compensation package, including full benefits.
Medical
Dental
Vision
Wellness program participation incentive
Financial wellness program
Fitness event fee reimbursement
Gym membership discounts
Colleague Assistance Program
Telemedicine Program (for those enrolled in Medical)
Adoption Benefits
Daycare late pick-up fee reimbursement
Basic Life & Accidental Death & Dismemberment Insurance
Voluntary Life & Accidental Death & Dismemberment Insurance
Short Term Disability
Paid parental leave
Group Long Term Disability
Pet Insurance
401(k) (50% employer match up to IRS limit, 4 year vesting)

Brown Advisory is an Equal Employment Opportunity Employer.