1

Grc Government Jobs (NOW HIRING)

Associate SAP GRC Analyst

Bethpage, NY · On-site

$65K - $116K/yr

... CRM, Business Warehouse, NetWeaver, GRC and other SAP based applications. This includes ... Ensure compliance with government and corporate security/audit guidelines. * Administer and execute ...

Showing results 41-60

Grc Government information

See salary details

$48

$69

$81

How much do grc government jobs pay per hour?

As of Aug 23, 2026, the average hourly pay for grc government in the United States is $69.97, according to ZipRecruiter salary data. Most workers in this role earn between $67.31 and $76.92 per hour, depending on experience, location, and employer.

What is a GRC Government professional?

GRC Government professionals are experts who manage Governance, Risk, and Compliance (GRC) within government agencies or public sector organizations. Their role involves developing policies, ensuring compliance with laws and regulations, identifying and mitigating risks, and fostering transparency and accountability. They often work to align government operations with legal standards and best practices while minimizing operational risks. GRC professionals use specialized tools and frameworks to streamline and monitor processes, helping agencies achieve their strategic objectives efficiently and ethically.

What are some common challenges faced by professionals working in GRC (Governance, Risk, and Compliance) roles within government agencies?

Professionals in GRC roles within government agencies often face challenges such as navigating complex regulatory requirements, balancing multiple compliance frameworks, and ensuring consistent communication across departments. Additionally, adapting to rapidly changing legislation and maintaining up-to-date risk management practices requires continual learning and collaboration. Working closely with IT, legal, and operational teams is essential, as GRC professionals must coordinate efforts to maintain compliance and manage risk across all areas of the agency.

What are the key skills and qualifications needed to thrive as a GRC (Governance, Risk, and Compliance) professional in government, and why are they important?

To thrive as a GRC professional in government, you need a solid understanding of regulatory frameworks, risk management, compliance standards, and often a relevant degree in public administration, law, or a related field. Familiarity with GRC software tools, audit management systems, and certifications such as Certified in Risk and Information Systems Control (CRISC) or Certified Information Systems Auditor (CISA) is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for interpreting regulations and collaborating across departments. These skills and qualifications are vital to ensure government agencies operate within legal requirements, mitigate risks, and maintain public trust.

What is the difference between Grc Government vs Grc Compliance Officer?

AspectGrc GovernmentGrc Compliance Officer
CredentialsCertifications like CFE, CISA, or CISSP often preferredSimilar certifications such as CFE, CISA, or compliance-specific credentials
Work EnvironmentPrimarily in government agencies, defense, or public sectorIn corporate, financial, or consulting firms with regulatory focus
Employer & IndustryGovernment agencies, defense contractors, public sectorPrivate companies, financial institutions, consulting firms
Search & Comparison IntentUnderstanding roles in government cybersecurity and complianceComparing compliance roles across sectors, including government

Grc Government professionals focus on regulatory compliance, risk management, and cybersecurity within government agencies. Grc Compliance Officers perform similar functions but often work in private sectors or corporations. Both roles require relevant certifications and involve ensuring adherence to laws and standards, but their work environments and employer types differ.

Is GRC an entry level job?

GRC (Governance, Risk, and Compliance) roles can be entry-level or require experience depending on the specific position. Entry-level GRC jobs typically focus on basic compliance tasks and may require foundational knowledge of regulations and security principles, often supported by certifications like CISA or CISSP. More advanced roles involve managing complex risk assessments and policy development, requiring prior experience in cybersecurity or governance.
More about Grc Government jobs

What cities are hiring for Grc Government jobs?

Cities with the most Grc Government job openings:

What states have the most Grc Government jobs?

States with the most job openings for Grc Government jobs include:

What job categories do people searching Grc Government jobs look for?

The top searched job categories for Grc Government jobs are:

Infographic showing various Grc Government job openings in the United States as of August 2026, with employment types broken down into 71% Full Time, and 29% Contract. Highlights an 72% In-person, 14% Hybrid, and 14% Remote job distribution, with an average salary of $145,541 per year, or $70 per hour.

Governance, Risk & Compliance (GRC) Manager

Riverside Research Institute

Beavercreek, OH • On-site

$145K - $170K/yr

Full-time

Re-posted 13 days ago


Job description

Riverside Research is an independent National Security Nonprofit dedicated to research and development in the national interest. We provide high-end technical services, research and development, and prototype solutions to some of the countrys most challenging technical problems.
All Riverside Research opportunities require U.S. Citizenship.

The Manager, Governance, Risk & Compliance (GRC) leads Riverside Research's Governance, Risk, and Compliance program supporting the organization's unclassified enterprise and research information systems. Reporting to the Director of Information Security, this position is responsible for maintaining and continuously maturing Riverside's cybersecurity governance framework, enterprise risk management program, and regulatory compliance initiatives.

This role serves as both a people leader and technical contributor, providing leadership for a team of GRC professionals while partnering across Information Security, Information Technology, Contracts, Human Resources, Finance, Legal, and Business Operations to ensure cybersecurity and compliance objectives align with organizational and customer requirements.

The Manager owns Riverside's Cybersecurity Maturity Model Certification (CMMC) program, leading continuous readiness activities, regulatory assessments, governance initiatives, and enterprise risk management efforts to maintain the organization's strong cybersecurity posture and support Department of Defense mission requirements.


  • Lead Riverside Research's Governance, Risk, and Compliance (GRC) program supporting the enterprise cybersecurity strategy, governance framework, and compliance objectives.
  • Own Riverside's Cybersecurity Maturity Model Certification (CMMC) program, ensuring continuous readiness for annual affirmations and Certified Third-Party Assessment Organization (C3PAO) assessments.
  • Lead and mentor a team of GRC Analysts, establishing priorities, developing staff, and fostering a culture of accountability, collaboration, and continuous improvement.
  • Develop, maintain, and govern enterprise cybersecurity policies, standards, procedures, and supporting documentation.
  • Lead Riverside's Enterprise Risk Management (ERM) program by facilitating risk identification, assessment, mitigation planning, and executive reporting.
  • Drive continuous monitoring activities through operational oversight, technical auditing, internal control assessments, and compliance reviews to ensure adherence to regulatory, contractual, and organizational security requirements.
  • Manage corrective action plans, findings, Plans of Action & Milestones (POA&Ms), and remediation activities through closure.
  • Provide governance oversight for cybersecurity programs including identity and access management, vulnerability management, configuration management, incident response, security awareness, external information sharing, third-party risk management, and data protection.
  • Partner with Information Technology and Information Security teams to ensure enterprise architecture and technology solutions align with cybersecurity strategy, regulatory requirements, and organizational risk tolerance.
  • Maintain awareness of evolving FAR, DFARS, CMMC, NIST, and Department of Defense cybersecurity requirements, advising leadership on regulatory changes and organizational impacts.
  • Develop executive dashboards, metrics, and reports that communicate cybersecurity posture, enterprise risk, and compliance status to senior leadership.
  • Collaborate with business stakeholders including Contracts, Human Resources, Finance, Legal, Marketing, and Business Operations to integrate cybersecurity governance into business processes.
  • Serve as a trusted advisor to leadership by translating cybersecurity, compliance, and enterprise risk into actionable business recommendations.

Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, Business, or a related discipline.
  • Twelve (12) years of progressively responsible experience in cybersecurity, information assurance, governance, risk, compliance, or related disciplines, including at least three (3) years of leadership experience managing technical teams or enterprise cybersecurity programs.
  • Demonstrated success leading external security assessments, regulatory audits, or certification efforts within a regulated industry such as the Defense Industrial Base, government contracting, financial services, healthcare, or telecommunications.
  • Strong knowledge of Cybersecurity Maturity Model Certification (CMMC), NIST SP 800-171, Department of Defense Controlled Unclassified Information (CUI) requirements, and applicable FAR and DFARS cybersecurity clauses.
  • Experience developing and maintaining cybersecurity governance programs, policies, standards, and enterprise compliance initiatives.
  • Strong understanding of enterprise information technology including Microsoft 365, Microsoft Entra ID, Microsoft Azure, Amazon Web Services (AWS), virtualization, and hybrid infrastructure.
  • Excellent written, verbal, and presentation skills with the ability to communicate complex technical concepts to executive leadership and non-technical stakeholders.
  • Demonstrated ability to lead cross-functional initiatives, influence organizational change, and build collaborative relationships across multiple business functions.
  • Must live or relocate to a commutable distance of Beavercreek, Ohio

Preferred Qualifications
  • Experience maintaining a certified CMMC Level 2 environment.
  • Experience leading Certified Third-Party Assessment Organization (C3PAO) assessments and/or DIBCAC assessments.
  • Experience leading Enterprise Risk Management (ERM) programs.
  • Experience with cloud security, Data Loss Prevention (DLP), Third-Party Risk Management, Cyber Supply Chain Risk Management (C-SCRM).
  • Industry certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified in Governance, Risk and Compliance (CGRC), or Certified Cloud Security Professional (CCSP).

$140,000- $170,000 This represents the typical compensation range for this position based on experience, location and other factors.
Riverside Research Institute is a not-for-profit, technology-oriented defense company, where service to our customers and support of our staff is our overall mission. Riverside is an affirmative action-equal opportunity employer and complies with all applicable federal, state, and local laws regarding recruitment and hiring. Riverside offers comprehensive compensation and benefit packages to our employees.
Riverside bases its employment decisions solely on technical experience, qualifications and other job-related criteria related to our organizational purpose as a not-for-profit company, and without regard to race, color, religion, age, sex marital status, sexual orientation, national origin, physical or mental disability, veterans status or any other status legally protected by applicable federal, state, and local law.