1

Grc Government Jobs (NOW HIRING)

Senior GRC Analyst

Palo Alto, CA · On-site

$117K - $151K/yr

S. federal government-related programs; ability to obtain or support federal security clearance processes is a plus. (REQ ID: 2761) #LI-NJ1

GRC Lead

San Francisco, CA · On-site

$21.25 - $26/hr

Automated construction permitting for a sovereign government → 80% faster, unlocking $375M+ in ... As our GRC Lead, you'll own the governance, risk, and compliance program end-to-end - and treat it ...

By unifying SecOps and GRC, this leader ensures timely threat mitigation, streamlined audit processes, and the secure delivery of cloud services to government agencies at all levels. The value you ...

The Public Sector GRC Lead role is part of Informatica's Security and Compliance organization ... Hands-on experience with government cloud environments such as AWS GovCloud, Azure Government, or ...

The Public Sector GRC Lead role is part of Informatica's Security and Compliance organization ... Hands-on experience with government cloud environments such as AWS GovCloud, Azure Government, or ...

next page

Showing results 1-20

Grc Government information

See salary details

$48

$69

$81

How much do grc government jobs pay per hour?

As of Jun 17, 2026, the average hourly pay for grc government in the United States is $69.97, according to ZipRecruiter salary data. Most workers in this role earn between $67.31 and $76.92 per hour, depending on experience, location, and employer.

What is GRC in government?

GRC in government refers to Governance, Risk Management, and Compliance roles that focus on ensuring government agencies adhere to laws, regulations, and policies. Professionals in GRC roles develop frameworks, conduct audits, and implement controls to manage risks and maintain organizational integrity. Knowledge of regulatory standards and security tools is often essential for these positions.

What jobs pay 500,000 a year in the US?

In the field of GRC (Governance, Risk, and Compliance), senior executive roles such as Chief Risk Officer, Chief Compliance Officer, or Chief Governance Officer can reach or exceed a $500,000 annual salary, especially in large organizations or financial institutions. These positions typically require extensive experience, advanced certifications, and strong leadership skills, often involving strategic decision-making and regulatory oversight.

What are GRC Government professionals?

GRC Government professionals are experts who manage Governance, Risk, and Compliance (GRC) within government agencies or public sector organizations. Their role involves developing policies, ensuring compliance with laws and regulations, identifying and mitigating risks, and fostering transparency and accountability. They often work to align government operations with legal standards and best practices while minimizing operational risks. GRC professionals use specialized tools and frameworks to streamline and monitor processes, helping agencies achieve their strategic objectives efficiently and ethically.

What jobs pay $10,000 a month without a degree?

In the GRC (Governance, Risk, and Compliance) field, some roles such as cybersecurity consultants, compliance managers, or risk analysts can earn $10,000 or more monthly with relevant experience and certifications like CISSP or CISA. Many high-paying GRC jobs focus on skills, industry knowledge, and certifications rather than formal degrees, especially in consulting or senior positions.

What are some common challenges faced by professionals working in GRC (Governance, Risk, and Compliance) roles within government agencies?

Professionals in GRC roles within government agencies often face challenges such as navigating complex regulatory requirements, balancing multiple compliance frameworks, and ensuring consistent communication across departments. Additionally, adapting to rapidly changing legislation and maintaining up-to-date risk management practices requires continual learning and collaboration. Working closely with IT, legal, and operational teams is essential, as GRC professionals must coordinate efforts to maintain compliance and manage risk across all areas of the agency.

Is GRC high paying?

GRC (Governance, Risk, and Compliance) roles are generally considered to offer competitive salaries, especially for professionals with certifications like CISSP or CISA and experience in cybersecurity or regulatory compliance. Salaries vary based on industry, location, and experience level but tend to be above average compared to many entry-level positions.

What are the key skills and qualifications needed to thrive as a GRC (Governance, Risk, and Compliance) professional in government, and why are they important?

To thrive as a GRC professional in government, you need a solid understanding of regulatory frameworks, risk management, compliance standards, and often a relevant degree in public administration, law, or a related field. Familiarity with GRC software tools, audit management systems, and certifications such as Certified in Risk and Information Systems Control (CRISC) or Certified Information Systems Auditor (CISA) is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for interpreting regulations and collaborating across departments. These skills and qualifications are vital to ensure government agencies operate within legal requirements, mitigate risks, and maintain public trust.

What is the difference between Grc Government vs Grc Compliance Officer?

AspectGrc GovernmentGrc Compliance Officer
CredentialsCertifications like CFE, CISA, or CISSP often preferredSimilar certifications such as CFE, CISA, or compliance-specific credentials
Work EnvironmentPrimarily in government agencies, defense, or public sectorIn corporate, financial, or consulting firms with regulatory focus
Employer & IndustryGovernment agencies, defense contractors, public sectorPrivate companies, financial institutions, consulting firms
Search & Comparison IntentUnderstanding roles in government cybersecurity and complianceComparing compliance roles across sectors, including government

Grc Government professionals focus on regulatory compliance, risk management, and cybersecurity within government agencies. Grc Compliance Officers perform similar functions but often work in private sectors or corporations. Both roles require relevant certifications and involve ensuring adherence to laws and standards, but their work environments and employer types differ.

More about Grc Government jobs
What cities are hiring for Grc Government jobs? Cities with the most Grc Government job openings:
What states have the most Grc Government jobs? States with the most job openings for Grc Government jobs include:
What job categories do people searching Grc Government jobs look for? The top searched job categories for Grc Government jobs are:
Senior GRC Analyst

Senior GRC Analyst

Workato

Palo Alto, CA • On-site

$117K - $151K/yr

Other

Posted 28 days ago


Job description

Responsibilities

Workato is seeking a detail-oriented, driven, and technically experienced Senior GRC Analyst to strengthen and advance its security governance, risk, and compliance (GRC) program - with a primary focus on FedRAMP authorization and ongoing federal compliance operations.

This role will lead FedRAMP readiness, authorization, and continuous monitoring activities in alignment with NIST 800-53 requirements, while also supporting broader compliance frameworks including ISO 27001, NIST 800-171, PCI-DSS, and IRAP. The ideal candidate will bring deep federal compliance expertise combined with strong analytical, communication, and problem-solving skills to evaluate controls, identify gaps, and drive improvements across security domains.

In this role, you will also be responsible for:

  • Leading FedRAMP authorization efforts - including System Security Plan (SSP) development, Security Assessment Report (SAR) review, Plan of Action & Milestones (POA&M) management, and preparation for Third Party Assessment Organization (3PAO) engagements

  • Owning continuous monitoring (ConMon) activities in accordance with FedRAMP requirements, including monthly vulnerability scanning, incident reporting, and annual assessments

  • Maintain and update FedRAMP authorization documentation, including SSP, CIS, CRM, and associated artifacts

  • Lead internal and external audits for frameworks including FedRAMP (NIST 800-53), ISO 27001/27701, PCI-DSS, NIST 800-171, and IRAP

  • Coordinate with process owners, control owners, 3PAOs, and federal agency stakeholders to ensure findings are tracked and remediated

  • Conduct risk assessments, security audits, and third-party/vendor risk reviews with a focus on FedRAMP boundary and supply chain risk

  • Review contracts to ensure security and compliance requirements - including FedRAMP flow-down clauses - are met

  • Identify control gaps and recommend improvements to enhance the organization's federal security posture

  • Communicate FedRAMP requirements, risks, and compliance status clearly to both technical and non-technical stakeholders, including federal agency customers

  • Perform regular user access reviews aligned to least-privilege and FedRAMP AC control requirements

  • Develop and track remediation plans for identified risks and POA&M items

  • Maintain and update the risk register with federal risk considerations

  • Oversee vendor and subservice provider security assurance processes relevant to the FedRAMP authorization boundary

  • Collaborate with engineering, infrastructure, and product teams to design and implement controls aligned with NIST 800-53 baselines

  • Support federal-facing sales and customer success discussions with compliance expertise

  • Explore and leverage AI/automation tools to enhance, streamline, or scale GRC and ConMon workflows

  • Build strong working relationships across departments and with federal agency AOs (Authorizing Officials)

  • Take on additional responsibilities as needed

RequirementsQualifications / Experience / Technical Skills
  • 8+ years of experience in cybersecurity, audits, risk management, compliance, or remediation

  • Hands-on FedRAMP experience required - including direct involvement in FedRAMP authorization (Moderate or High baseline preferred), SSP authoring, POA&M management, or 3PAO coordination

  • Deep familiarity with NIST 800-53 Rev 5 control families and FedRAMP-specific overlays, guidance, and templates

  • Experience working with cloud platforms such as AWS GovCloud, Azure Government, or Google Cloud (government regions)

  • Proven ability to negotiate and prioritize risk remediation with internal and federal stakeholders

  • Bachelor's degree in Information Systems, Computer Science, Information Security, or a related field

  • Strong understanding of security controls in cloud environments, including boundary definition, encryption, access control, and vulnerability management

  • Familiarity with NIST 800-171 and CMMC as complementary federal frameworks

  • Experience auditing frameworks such as PCI-DSS, SOC 2, and ISO 27001/27701

  • Relevant certifications strongly preferred: CISSP, CISA, FedRAMP-specific training (e.g., FedRAMP PMO courses), or similar

  • Ability to manage multiple priorities independently with minimal supervision

Soft Skills / Personal Characteristics
  • Strong communication skills with the ability to translate federal compliance requirements into technical actions and executive-level summaries

  • High energy and adaptability in a fast-paced, high-stakes compliance environment

  • Strong collaboration and knowledge-sharing mindset across engineering, legal, and customer-facing teams

  • Excellent time management and organizational skills - particularly for managing concurrent ConMon and audit cycles

  • High attention to detail, integrity, and ethical standards consistent with handling federal data and programs

  • Willingness to learn and take on new challenges as Workato's federal footprint grows

Nice to Have
  • This position requires overlap with U.S. Pacific Time (PST) working hours. 

  • Strong hands-on experience with FedRAMP, NIST 800-53, ISO 27001, NIST 800-171, PCI-DSS, SOC 2, and potentially IRAP is required.

  • May involve some international travel.

  • Must be eligible to work on U.S. federal government-related programs; ability to obtain or support federal security clearance processes is a plus.

 

(REQ ID: 2761)

#LI-NJ1