1

Grc Risk Analyst Jobs in Maryland (NOW HIRING)

The GRC Analyst supports the administration of Information Security Governance, Risk, and Compliance programs, including policy exception management and enterprise risk register activities using ...

The GRC Analyst supports the administration of Information Security Governance, Risk, and Compliance programs, including policy exception management and enterprise risk register activities using ...

The Senior Risk Manager, GRC Systems, will play a pivotal role in shaping how operational risk ... Support executive-level reporting and insights, including dashboards and analysis of risk trends ...

IRC Analyst

Westminster, MD ยท On-site

$70K - $110K/yr

Prepare risk assessments and generate risk and control matrices (RACM); update GRC systems with ... Analyze transactions, documentation, and reporting to assess adequacy and process effectiveness.

IRC Analyst

Westminster, MD ยท Hybrid

$70K - $110K/yr

Prepare risk assessments and generate risk and control matrices (RACM); update GRC systems with ... Analyze transactions, documentation, and reporting to assess adequacy and process effectiveness.

Cyber Risk / Compliance Analyst work, ISO and risk-platform support, evidence coordination, client ... GRC or trust-management platforms such as Vanta, Archer, ServiceNow GRC, OneTrust, Drata, or ...

... Risk Management. Transformationsprojekte: Du unterstutzt bei der Analyse bestehender Prozesse, ... GRC oder IT-Transformation mit Fokus auf ServiceNow sowie praktische Erfahrung in der Konfigration ...

Identifies systemic issues through data analysis, develops recommendations to improve operational ... Experience with risk management, governance, risk and compliance (GRC), contract management, or ...

Risk Management Coordinator

Laurel, MD ยท On-site

$70 - $90/hr

Identifies systemic issues through data analysis, develops recommendations to improve operational ... Experience with risk management, governance, risk and compliance (GRC), contract management, or ...

next page

Showing results 1-20

Grc Risk Analyst information

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What job categories do people searching Grc Risk Analyst jobs in Maryland look for?

The top searched job categories for Grc Risk Analyst jobs in Maryland are:

What cities in Maryland are hiring for Grc Risk Analyst jobs?

Cities in Maryland with the most Grc Risk Analyst job openings:

Infographic showing various Grc Risk Analyst job openings in Maryland as of August 2026, with employment types broken down into 1% As Needed, 86% Full Time, 10% Part Time, and 3% Contract. Highlights an 88% Physical, 4% Hybrid, and 8% Remote job distribution.

Jr. GRC Analyst

System One

Rockville, MD โ€ข On-site

Contractor

Re-posted 8 days ago


Job description

JUNIOR GRC ANALYST ROCKVILLE, MD - HYBRID LONG TERM CONTRACT SEEKING SOMEONE WHO HAS WORKED WITH THE SERVICENOW GRC APPLICATION Overview:
  • The GRC Analyst supports the administration of Information Security Governance, Risk, and Compliance programs, including policy exception management and enterprise risk register activities using ServiceNow Integrated Risk Management (IRM).
Working under the guidance of Information Security leadership, the analyst will apply established risk assessment methodologies, workflows, and reporting processes to support enterprise cybersecurity governance and risk management initiatives. This role provides hands-on experience in information security governance, risk analysis, policy exception management, enterprise risk management, and ServiceNow IRM. Key Responsibilities: Policy Exception Management
  • Review policy exception requests for completeness and required documentation.
  • Validate business justifications and request additional information as needed.
  • Maintain exception records and track approvals in ServiceNow.
  • Monitor expiration dates, coordinate renewals, and produce status reports.
Risk Analysis
  • Conduct risk evaluations using established methodologies and templates.
  • Assess business impact, likelihood, and overall risk.
  • Identify compensating controls and document risk analyses.
  • Prepare risk-based recommendations for management review.
  • Maintain analysis records in ServiceNow.
Enterprise Risk Register Administration
  • Create, update, and maintain risk records.
  • Track risks identified through assessments, penetration tests, vulnerability scans, security incidents, and other approved sources.
  • Monitor mitigation activities, due dates, and risk status.
  • Maintain supporting documentation and generate reports.
ServiceNow IRM Administration
  • Process policy exceptions.
  • Maintain risk register records.
  • Track approvals and workflows.
  • Generate reports and dashboards.
Stakeholder Support
  • Communicate with IT staff, business stakeholders, system owners, managers, and security teams.
  • Provide professional customer service and clear written and verbal communication.
Education
  • Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, Business Information Systems, or a related field.
Preferred Certifications - at least one
  • CompTIA Security+
  • ISACA IT Risk Fundamentals
  • NIST Cybersecurity Framework (NCSF) Practitioner
  • CISM Fundamentals
  • Cybersecurity, audit, or compliance-related certifications
Experience: Required
  • One (1) year of experience in Information Security, IT Governance, Risk Management, Compliance, Audit, Information Technology, or a related field; or
  • Recent graduate with relevant internship or equivalent experience.
Preferred
  • ServiceNow experience
  • Microsoft 365 proficiency
  • GRC program experience
  • Technical documentation experience
  • Customer service and project coordination experience
Knowledge & Skills:
  • Basic understanding of cybersecurity, risk management, information security, NIST Cybersecurity Framework, and compliance concepts.
  • Strong analytical, organizational, and critical-thinking skills.
  • Excellent written and verbal communication skills.
  • Attention to detail and ability to manage multiple priorities.
  • Ability to work independently and learn new technologies quickly.
Deliverables:
  • Policy exception reviews and tracking records
  • Risk analyses and recommendations
  • Risk register entries and updates
  • Monthly metrics and quarterly reports
  • Executive dashboards
  • ServiceNow documentation and reporting artifacts
#M1 #LI-CB3 Ref: #851-Rockville-S1


System One logo

About System One

Sourced by ZipRecruiter

System One helps employers get work done more efficiently and economically without compromising quality. Over our 35+ year history, we've helped connect thousands of talented people with innovative companies. The excitement of a perfect fit motivates us every single day.

Industry

Business consulting services and recruiting and staffing services

Company size

5,001 - 10,000 Employees

Headquarters location

Pittsburgh, PA, US