1

Grc Government Jobs in Raleigh, NC (NOW HIRING)

Grc Government information

See Raleigh, NC salary details

$46

$68

$78

How much do grc government jobs pay per hour?

As of Aug 28, 2026, the average hourly pay for grc government in Raleigh, NC is $68.02, according to ZipRecruiter salary data. Most workers in this role earn between $65.43 and $74.76 per hour, depending on experience, location, and employer.

What is a GRC Government professional?

GRC Government professionals are experts who manage Governance, Risk, and Compliance (GRC) within government agencies or public sector organizations. Their role involves developing policies, ensuring compliance with laws and regulations, identifying and mitigating risks, and fostering transparency and accountability. They often work to align government operations with legal standards and best practices while minimizing operational risks. GRC professionals use specialized tools and frameworks to streamline and monitor processes, helping agencies achieve their strategic objectives efficiently and ethically.

What are some common challenges faced by professionals working in GRC (Governance, Risk, and Compliance) roles within government agencies?

Professionals in GRC roles within government agencies often face challenges such as navigating complex regulatory requirements, balancing multiple compliance frameworks, and ensuring consistent communication across departments. Additionally, adapting to rapidly changing legislation and maintaining up-to-date risk management practices requires continual learning and collaboration. Working closely with IT, legal, and operational teams is essential, as GRC professionals must coordinate efforts to maintain compliance and manage risk across all areas of the agency.

What are the key skills and qualifications needed to thrive as a GRC (Governance, Risk, and Compliance) professional in government, and why are they important?

To thrive as a GRC professional in government, you need a solid understanding of regulatory frameworks, risk management, compliance standards, and often a relevant degree in public administration, law, or a related field. Familiarity with GRC software tools, audit management systems, and certifications such as Certified in Risk and Information Systems Control (CRISC) or Certified Information Systems Auditor (CISA) is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for interpreting regulations and collaborating across departments. These skills and qualifications are vital to ensure government agencies operate within legal requirements, mitigate risks, and maintain public trust.

What is the difference between Grc Government vs Grc Compliance Officer?

AspectGrc GovernmentGrc Compliance Officer
CredentialsCertifications like CFE, CISA, or CISSP often preferredSimilar certifications such as CFE, CISA, or compliance-specific credentials
Work EnvironmentPrimarily in government agencies, defense, or public sectorIn corporate, financial, or consulting firms with regulatory focus
Employer & IndustryGovernment agencies, defense contractors, public sectorPrivate companies, financial institutions, consulting firms
Search & Comparison IntentUnderstanding roles in government cybersecurity and complianceComparing compliance roles across sectors, including government

Grc Government professionals focus on regulatory compliance, risk management, and cybersecurity within government agencies. Grc Compliance Officers perform similar functions but often work in private sectors or corporations. Both roles require relevant certifications and involve ensuring adherence to laws and standards, but their work environments and employer types differ.

Is GRC an entry level job?

GRC (Governance, Risk, and Compliance) roles can be entry-level or require experience depending on the specific position. Entry-level GRC jobs typically focus on basic compliance tasks and may require foundational knowledge of regulations and security principles, often supported by certifications like CISA or CISSP. More advanced roles involve managing complex risk assessments and policy development, requiring prior experience in cybersecurity or governance.

What job categories do people searching Grc Government jobs in Raleigh, NC look for?

The top searched job categories for Grc Government jobs in Raleigh, NC are:

What cities near Raleigh, NC are hiring for Grc Government jobs?

Cities near Raleigh, NC with the most Grc Government job openings:

Infographic showing various Grc Government job openings in Raleigh, NC as of June 2026, with employment types broken down into 71% Full Time, 24% Part Time, and 5% Contract. Highlights an 76% Physical, 7% Hybrid, and 17% Remote job distribution, with an average salary of $141,478 per year, or $68 per hour.

Security Assessment and Continuous Monitoring Analyst

A-TEK Inc.

Raleigh, NC • Hybrid

$110K - $120K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

This job post has expired today. Applications are no longer accepted.


Job description

Empower, Innovate, Impact!  At Team A-TEK, we EMPOWER people to drive INNOVATION that IMPACTS mission!

A-TEK operates at the intersection of mission and innovation by applying our deep domain expertise across the federal markets. Embracing our digital-first strategy, A-TEK provides enhanced capabilities in application development, digital transformation, enterprise IT, and scientific services. Our solutions are designed to modernize, automate, secure, protect, and enhance the operations of our federal clients, ensuring they stay ahead in a rapidly evolving digital landscape.

Our work is fueled by a passion to serve our clients' needs and to protect the safety and welfare of Americans. That passion shapes how we nurture our most valuable asset – Our Employees. A-TEK actively cultivates the talent that drives our success and fosters a creative, challenging, and mission-driven work environment for current and future employees.

The Security Assessment and Continuous Monitoring Analyst supports annual security assessments, continuous monitoring, POA&M management, cybersecurity documentation, vulnerability and risk tracking, GRC platform updates, and authorization sustainment for an HHS-affiliated agency. This individual collects and validates evidence, maintains accurate records, tracks findings, and keeps authorization packages ready for Government and independent assessor review. Must be able to support hybrid work requirements in the Washington, DC metropolitan area or Research Triangle area.

Responsibilities

  • Support security control assessments for three primary authorization boundaries.
  • Collect, organize, validate, and maintain assessment evidence and control implementation documentation.
  • Coordinate assessment schedules, interviews, demonstrations, evidence requests, and assessor communications.
  • Track findings from identification through remediation, validation, closure, or POA&M acceptance.
  • Update POA&M status in the designated GRC platform within five business days of a status change.
  • Perform continuous monitoring activities and maintain supporting documentation and evidence.
  • Reconcile GRC records against system inventories, authorization artifacts, and operational information.
  • Support the annual review cycle for system documentation and authorization artifacts.
  • Monitor vulnerabilities, configuration changes, control status, and risk indicators.
  • Support security impact analyses within 10 business days after identification of a change request.
  • Prepare risk reports within 10 business days after assessments, major changes, or other triggering events.
  • Support cloud and FedRAMP artifact reviews, control inheritance analysis, and continuous monitoring.
  • Assist with system onboarding, decommissioning, data calls, audits, and cybersecurity reporting.
  • Apply quality checks that promote accurate documentation and 98 percent GRC data accuracy.

Required Experience and Qualifications 

  • Demonstrated experience supporting Federal RMF, A&A, security assessments, and continuous monitoring.
  • Knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, FISMA, and POA&M requirements.
  • Experience collecting and evaluating security control evidence.
  • Experience maintaining SSPs, SARs, POA&Ms, risk records, and related cybersecurity artifacts.
  • Understanding of vulnerability management, configuration management, and security impact analysis.
  • Strong analytical, documentation, and stakeholder communication skills.
  • Ability to manage concurrent priorities and meet time sensitive assessment and reporting deadlines.
  • Ability to support hybrid work requirements in the Washington, DC metropolitan area or Research Triangle area.
  • Education and experience that satisfy the proposed GSA labor category.

Preferred Experience and Qualifications

  • Experience supporting HHS or another Federal health agency.
  • Experience using JCAM or a comparable Federal GRC platform.
  • Experience with cloud and FedRAMP artifacts, control inheritance, and shared responsibility models.
  • Experience supporting independent assessors and addressing assessment findings.
  • Experience in maintaining accurate system inventory and authorization data.
  • CAP/CGRC, Security+, CISSP, CISM, or an applicable cloud security certification.

Compensation

 Salary Range: $110,000 – $120,000 annually (commensurate with experience) 
Benefits: Health, dental, and vision insurance; 401(k) with employer match; paid time off; professional development opportunities. 

Why Join Us? 

This is an opportunity to make a direct impact on healthcare data processes that support critical regulatory functions. You will collaborate with dedicated professionals, work on meaningful projects, and contribute to improvements in public health systems. 

Candidates may use tools (including AI) for proofreading or formatting; however, using any tool to fabricate, exaggerate, or misrepresent qualifications, experience, or work product is not permitted. We may assess application materials for job-related technical depth, internal consistency, and demonstrated hands-on experience, including through follow-up questions, skills assessments, or reference checks. Verification of education may be requested before or during the hiring process.

For security and identity verification purposes, participants may be asked to temporarily disable virtual backgrounds during portions of the call.

Misrepresentation or falsification may result in removal from further consideration. Candidates who need a reasonable accommodation in the application or interview process may request one.

A-TEK, Inc. is an Equal Opportunity/Affirmative Action employer.  All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or status as a qualified individual with a disability, or Vietnam era or other protected Veteran status.