1

Grc Project Manager Jobs in Colorado (NOW HIRING)

Deliver documentation for all assigned tasks/projects; keep content current, accurate, compliant ... Experience using Bison GRC, Xacta 360, or similar GRC platforms to manage controls, evidence, and ...

... project scope. * Support the design, configuration, prototyping, testing, and implementation of GRC, compliance, financial crime, and risk management technology solutions. * Assist with system ...

Deliver documentation for all assigned tasks/projects; keep content current, accurate, compliant ... Experience using Bison GRC, Xacta 360, or similar GRC platforms to manage controls, evidence, and ...

Excellent organizational and project management skills * Strong written and verbal communication ... Knowledge of GRC tools and methodologies * Industry certifications such as CISA, CIPP, or Security ...

Basic Understanding of SAP security and GRC (governance,riskand compliance) * Proven experience managing project financials and delivering within budget * Strong people management skills: mentoring ...

Growth Leader, Risk Services

Denver, CO · On-site

$151K - $195K/yr

Knowledge of GRC/IT Assurance services. * Proficiency with HubSpot or a comparable marketing ... Excellent cross-functional collaboration, project management, and communication skills. * Bachelor ...

Hands-on experience with program management and GRC documentation tools including Jira, Confluence (Atlassian suite), MS Project, enterprise GRC platforms, and MS Visio or Lucidchart. * Strong ...

Sr. Cybersecurity Operational Risk Officer

Denver, CO · On-site

$102K - $132K/yr

... GRC preferred Project management, Agile experience preferred Tactical Skills Demonstrated experience working with regulatory agencies, guidelines and requirements Strong ability to work with all ...

Agile Scrum Master

Denver, CO · On-site

$53 - $70.75/hr

Experience partnering with Technical Project or Program Managers or similar cross-functional ... Familiarity with IT service management or GRC tooling. * Exposure to scaled Agile frameworks (e.g ...

Agile Scrum Master

Denver, CO · On-site

$53 - $70.75/hr

Experience partnering with Technical Project or Program Managers or similar cross-functional ... Familiarity with IT service management or GRC tooling. * Exposure to scaled Agile frameworks (e.g ...

Coordinate on special projects with members of the I/A teams from Mexico, Europe, Australia, where ... SAP GRC exposure a plus. * Strong in performing data analytical procedures in order to find the ...

Showing results 21-40

Grc Project Manager information

How does a GRC Project Manager typically collaborate with cross-functional teams to implement compliance initiatives?

A GRC Project Manager works closely with departments such as IT, Legal, Risk, and Internal Audit to ensure that governance, risk management, and compliance initiatives are effectively integrated across the organization. This role involves facilitating regular meetings, aligning project goals with organizational policies, and clearly communicating regulatory requirements to various stakeholders. The GRC Project Manager often serves as a liaison, translating technical or legal concepts into actionable tasks for different teams, and ensuring that project milestones are met while maintaining compliance standards.

What are the key skills and qualifications needed to thrive as a GRC Project Manager, and why are they important?

To thrive as a GRC Project Manager, you need expertise in governance, risk management, compliance frameworks, and project management methodologies, often supported by a bachelor's degree and certifications like PMP or CISA. Familiarity with GRC software platforms, risk assessment tools, and regulatory compliance systems is typically required. Exceptional organizational, leadership, and stakeholder communication skills help drive cross-functional projects and adapt to changing regulatory landscapes. These competencies are crucial for ensuring projects meet compliance objectives, mitigate risks, and deliver organizational value.

What is the difference between Grc Project Manager vs Grc Analyst?

AspectGrc Project ManagerGrc Analyst
CertificationsISO 27001 Lead Implementer, PMP, CISACISA, CRISC, CISSP
Work EnvironmentOversees projects, manages teams, coordinates compliance effortsAnalyzes risks, assesses controls, supports compliance activities
Employer & Industry UsageFinancial, healthcare, technology sectorsFinancial institutions, consulting firms, tech companies
Search & Comparison IntentUnderstanding project management roles in GRCUnderstanding analytical roles supporting GRC projects

The Grc Project Manager focuses on leading GRC initiatives, managing teams, and ensuring project delivery. The Grc Analyst supports these efforts by analyzing risks, evaluating controls, and providing compliance insights. Both roles require similar certifications and are integral to GRC efforts, but they differ in scope and responsibilities within organizations.

Is GRC a GRC Project Manager entry-level job?

A GRC Project Manager role is typically not entry-level; it usually requires several years of experience in governance, risk management, and compliance, along with project management skills. Entry-level positions in GRC may be titled GRC Analyst or Coordinator, with the Project Manager role demanding more advanced knowledge and leadership abilities.

What are popular job titles related to Grc Project Manager jobs in Colorado?

For Grc Project Manager jobs in Colorado, the most frequently searched job titles are:

What cities in Colorado are hiring for Grc Project Manager jobs?

Cities in Colorado with the most Grc Project Manager job openings:

Infographic showing various Grc Project Manager job openings in Colorado as of June 2026, with employment types broken down into 84% Full Time, 15% Part Time, and 1% Contract. Highlights an 81% Physical, 6% Hybrid, and 13% Remote job distribution.

Cyber Security Engineer III

Cherokee Federal

Denver, CO • On-site

Other

Medical, Dental, Vision, Retirement

Re-posted 8 days ago


Job description


Cyber Security Engineer III
The Cyber Security Engineer III supports Reclamation IT systems and performs security and privacy tasks aligned to NIST SP 800-37 Rev. 2 (RMF) and task order requirements. Work is executed during the period of performance and is reviewed weekly for completeness of tasks and objectives. The ISSO receives direct or indirect technical direction from the COR and/or TSAL. The ISSO produces and maintains government-required cybersecurity and privacy documentation, keeps system records current in the Bison GRC tool (and other designated repositories), and communicates clearly in English using Reclamation-approved terms and formats. All deliverables are Government property and are stored electronically on designated network drives.
Compensation & Benefits:
Estimated Starting Salary Range for Cyber Security Engineer III: TBD
Pay commensurate with experience.
Full time benefits include Medical, Dental, Vision, 401K and other possible benefits as provided. Benefits are subject to change with or without notice.
Cyber Security Engineer III Responsibilities Include:
  • Maintain the operational cybersecurity posture for assigned IT systems and advise system owners and the Enterprise ISSM on risk, changes, and security status.
  • Execute RMF/ATO (A&A) activities for assigned systems, including required documentation, assessments, and ongoing compliance tasks.
  • Develop, update, and maintain the System Security and Privacy Plan (SSPP) and all supporting artifacts, to include (as applicable): configuration management, contingency planning and after-action reporting, continuous monitoring, incident response plans/contact lists and after-action reporting, interconnection security agreements, POA&Ms, privacy artifacts (PTA/PIA), risk assessments, control baselines and inheritance, security/business impact analyses, control implementation statements, technical/system narratives, inventories, network/system boundary diagrams, supply chain risk management documentation, and SaaS attestations/workbooks.
  • Perform continuous monitoring of security controls, including tracking Reclamation-defined metrics, reviewing audit logs, identifying/responding to vulnerabilities, and addressing Organizational Assessment (OA) metrics.
  • Conduct technical vulnerability assessments; prioritize, track, and validate remediation activities with technical teams.
  • Manage the POA&M lifecycle: create POA&Ms for newly identified weaknesses, coordinate milestones/dates with technical staff, and update POA&Ms in Bison GRC (at least monthly for audit-related POA&Ms and quarterly for all others). Collect evidence and complete WCVFs when closing POA&Ms or pursuing risk acceptance.
  • Support and participate in incident response activities for assigned systems.
  • Participate in contingency, recovery, and incident response training and tests; produce/maintain related evidence and after-action documentation.
  • Perform cybersecurity impact analysis for system changes and support change control by reviewing change requests, identifying security impacts, approving/denying as required, ensuring procedures are followed, and updating hardware/software inventories.
  • Conduct cybersecurity impact reviews for new software requests.
  • Execute annual assurance/assessment tasks: update FISMA/RMF documentation on required schedules, perform Internal Control Reviews (ICRs), and ensure control tailoring remains aligned with the applicable baseline.
  • Participate in security assessments and audits; provide required access, documentation, and system information to assessors/auditors.
  • Develop and maintain system standard operating procedures (SOPs) aligned to security control requirements.
  • Provide Quarterly Cybersecurity Briefings to System Owners for assigned systems.
  • Support federal staff by providing expertise/training to Reclamation ISSOs and advising on RMF requirements for new systems or significant changes before production deployment.
  • Provide technical cybersecurity input across operational projects throughout the SDLC.
  • Deliver documentation for all assigned tasks/projects; keep content current, accurate, compliant with current standards, and maintained in approved formats and repositories (including Bison GRC).

Minimum Requirements
  • Bachelor's Degree in Cyber Security, MIS, IT or similar Information Technology degree
  • Demonstrated ISSO (or equivalent) experience performing FISMA/RMF activities aligned to NIST SP 800-37 Rev. 2, including A&A/ATO support and continuous monitoring.
  • Proven ability to develop and maintain SSPP/SSP and related system security/privacy documentation (e.g., contingency, incident response, configuration management, continuous monitoring, risk assessments, inventories, diagrams, POA&M).
  • Experience performing control monitoring, vulnerability review/triage, remediation tracking, and audit support.
  • Working knowledge of federal privacy requirements, including PTA/PIA and PII protection.
  • Strong written and verbal communication skills; ability to brief system owners and security leadership on cybersecurity posture and risk.
  • Experience drafting policies, procedures, standards, SOPs, and instructional materials.
  • Experience working effectively in a civilian federal government environment and with interagency stakeholders.
  • Ability to follow government documentation standards, maintain records in designated repositories, and deliver weekly/recurring status-driven outputs.

Preferred Qualifications
  • Experience implementing RMF for cloud-hosted systems and/or SaaS solutions, including SaaS attestation artifacts.
  • Experience using Bison GRC, Xacta 360, or similar GRC platforms to manage controls, evidence, and POA&Ms under continuous monitoring.
  • Knowledge/experience with GIS environments.
  • Knowledge/experience supporting Operational Technology (OT) systems.
  • Certifications: CISSP, CISM, and/or CAP.
  • Mut pass pre-employment requirements of Cherokee Federal.

Company Information:
Cherokee Nation System Solutions (CNSS) is a part of Cherokee Federal - the division of tribally owned federal contracting companies owned by Cherokee Nation Businesses. As a trusted partner for more than 60 federal clients, Cherokee Federal LLCs are focused on building a brighter future, solving complex challenges, and serving the government's mission with compassion and heart. To learn more about CNSS, visit cherokee-federal.com.
#CherokeeFederal #LI-IG
Cherokee Federal is a military friendly employer. Veterans and active military transitioning to civilian status are encouraged to apply.
Legal Disclaimer: Cherokee Federal is an equal opportunity employer. Please visit cherokee-federal.com/careers for information regarding our Affirmative Action and Equal Opportunity Employer Statement, and Accommodation request.
Many of our job openings require access to government buildings or military installations. Candidates must pass pre-employment qualifications of Cherokee Federal.
Please Note:This position is pending a contract award.If you are interested in a future with Cherokee Federal, APPLY TODAY!Although this is not an approved position, we are accepting applications for this future and anticipated need.

Cherokee Federal logo

About Cherokee Federal

Sourced by ZipRecruiter

Cherokee Federal - a division of Cherokee Nation Businesses - is a team of tribally owned federal contracting companies focused on building solutions, solving complex challenges, and serving the nation's mission around the globe for more than 60 federal clients. Our team of companies manages nearly 1,000 projects of all sizes across the construction, consulting, engineering and manufacturing, health, and technology portfolios. Since 2012, the Cherokee Federal team of companies has won more than $5 billion in government contracts. Our 3,000+ employees work in 26 countries, 50 states and 2 U.S. territories. Why choose Cherokee Federal? Visit our website and learn about the great reasons to join our team. cherokee-federal.com

Industry

Architectural services

Company size

1,001 - 5,000 Employees

Headquarters location

Tulsa, OK, US

Year founded

1969

Social media