1

Grc Risk Analyst Jobs in Maryland (NOW HIRING)

RMF and Authorization Lead

Rockville, MD · Hybrid

$165K - $185K/yr

... GRC platform. * Lead POA&M management, residual risk analysis, risk reporting, and remediation tracking. * Support cloud and FedRAMP documentation, control inheritance analysis, and shared ...

Security Analyst

Columbia, MD · Hybrid

$55 - $60/hr

Description Position Overview The Information Security Analyst II (GRC) provides support for Governance, Risk, and Compliance activities aligned to NIST CSF, NIST SP 800-53, HIPAA Security Rule, and ...

... Risk and Compliance (GRC) tools * Demonstrated ability to interpret and apply NIST SP 800-53 security controls in cloud environments * Strong analytical and technical writing skills with the ability ...

... GRC tools * Familiarity with cloud security documentation, including SSPs, SARs, RARs, and POA&Ms * Ability to analyze complex cloud architectures and provide accurate risk assessments * Strong ...

... GRC tools * Familiarity with cloud security documentation, including SSPs, SARs, RARs, and POA&Ms * Ability to analyze complex cloud architectures and provide accurate risk assessments * Strong ...

... GRC tools * Familiarity with cloud security documentation, including SSPs, SARs, RARs, and POA&Ms * Ability to analyze complex cloud architectures and provide accurate risk assessments * Strong ...

Cloud SCA-R, Mid

Fort George G Meade, MD · On-site

$72.75 - $96.50/hr

... Risk and Compliance (GRC) tools * Demonstrated ability to interpret and apply NIST SP 800-53 security controls in cloud environments * Strong analytical and technical writing skills with the ability ...

Cloud SCA-R, Mid

Fort George G Meade, MD · On-site

$72.75 - $96.50/hr

... Risk and Compliance (GRC) tools * Demonstrated ability to interpret and apply NIST SP 800-53 security controls in cloud environments * Strong analytical and technical writing skills with the ability ...

Cloud SCA-R, Mid

Fort George G Meade, MD · On-site

$72.75 - $96.50/hr

... Risk and Compliance (GRC) tools * Demonstrated ability to interpret and apply NIST SP 800-53 security controls in cloud environments * Strong analytical and technical writing skills with the ability ...

Showing results 41-60

Grc Risk Analyst information

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What job categories do people searching Grc Risk Analyst jobs in Maryland look for?

The top searched job categories for Grc Risk Analyst jobs in Maryland are:

What cities in Maryland are hiring for Grc Risk Analyst jobs?

Cities in Maryland with the most Grc Risk Analyst job openings:

Infographic showing various Grc Risk Analyst job openings in Maryland as of August 2026, with employment types broken down into 1% As Needed, 86% Full Time, 10% Part Time, and 3% Contract. Highlights an 88% Physical, 4% Hybrid, and 8% Remote job distribution.

Director, Technology Risk & Digital Enablement

McCormick & Company

Hunt Valley, MD • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 14 days ago


McCormick & Company rating

8.2

Company rating: 8.2 out of 10

Based on 45 frontline employees who took The Breakroom Quiz

70th of 445 rated food and drinks producers


Job description

You may know McCormick as a leader in herbs, spices, seasonings, and condiments - and we're only getting started. At McCormick, we're always looking for new people to bring their unique flavor to our team.
McCormick employees - all 14,000 of us across the world - are what makes this company a great place to work.
We are looking to hire a Director, Technology Risk & Digital Enablement to join the Global Risk and Audit Management (GRAM) team based at our Global Headquarters in Hunt Valley, Maryland. The position is hybrid eligible (50% onsite per month).
What We Bring To The Table:
The best people deserve the best rewards. In addition to the benefits you'd expect from a global leader (401k, health insurance, paid time off, etc.) we also offer:
• Competitive compensation
• Career growth opportunities
• Flexibility and Support for Diverse Life Stages and Choices
• Wellbeing programs including Physical, Mental and Financial wellness
• Tuition assistance
We have embarked on an exciting journey to transform and integrate our Enterprise Risk and Internal Audit capabilities and align with McCormick's strategic priorities. Director, Technology Risk & Digital Enablement is a key leadership role reporting to the Chief Risk & Audit Officer (CRAO), and responsible for owning and advancing the full technology risk agenda within GRAM. This individual serves as the strategic leader in advancing global technology and cyber risk coverage while simultaneously acting as the function's digital transformation champion - driving the adoption of analytics, automation, and emerging technologies to make audit activities smarter, faster, and more impactful.
This is a dual-mandate role: one foot firmly in risk and assurance, the other driving innovation. The successful candidate will be as comfortable presenting technology risk insights to the Audit Committee as they are building a data analytics roadmap with audit teams.
Responsibilities
Technology Risk & Audit Leadership
  • Lead and own all GRAM workstreams related to global Technology Risk Universe, ensuring comprehensive coverage of IT, cyber, data, cloud, AI, and third-party technology risks.
  • Lead the planning, execution, and reporting of all technology advisory and assurance initiatives across infrastructure, applications, cybersecurity, data governance, and emerging technology.
  • Serve as GRAM function's primary interface with the Technology leadership team incl. CTO, CISO, and others.
  • Serve as the in-house expert on all Technology matters related to Sarbanes-Oxley (SOX), corporate governance and enterprise risks and provide expert opinion on technology risk matters to the CARO, Audit Committee, and senior management, translating complex technical risks into clear business language.
  • Collaborate closely with other members of GRAM leadership team to ensure that risk management activities are well-defined, coordinated, risk-based, and executed
  • Stay current with the evolving technology risk landscape (e.g., cloud, AI/ML risk, ransomware, third-party digital risk) and ensure risk mitigation and audit plans remain relevant and forward-looking.
  • Oversee quality assurance on technology audit engagements, ensuring findings are well-evidenced, rated consistently, and linked to business impact.

Digital Enablement & Innovation
  • Champion the adoption of digital tools and capabilities within Internal Audit, including data analytics, automation/AI-assisted audit techniques, and continuous monitoring.
  • Define and execute a multi-year Digital Enablement Roadmap for the GRAM function, with measurable milestones and efficiency outcomes.
  • Partner with Data & Analytics, IT, and external vendors to build and sustain function-specific data pipelines, dashboards, and automated testing capabilities.
  • Identify and pilot emerging technologies (e.g., natural language processing for document review, anomaly detection, GRC platform enhancements).
  • Embed data-driven risk management techniques into engagements, helping teams move from sample-based testing to population-level analysis.
  • Track and report on digital enablement ROI - efficiency gains, risk coverage expansion, and quality improvements.

People Leadership & Capability Building
  • Recruit and retain top technology risk talent, building a team that blends deep technical expertise with strong business acumen.
  • Lead, mentor, and develop a team of technology risk professionals (in-house and co-source provider), fostering a culture of continuous learning and innovation.
  • Build digital literacy and data analytics skills across the broader audit function through training, coaching, and hands-on engagement.
  • Act as a role model for intellectual curiosity and agile ways of working within a traditionally structured audit environment.

Candidate profile
  • Bachelor's degree in Information Systems or related field.
  • Required: CISA, CISM, CISSP certification or quivalent. Preferred CIA, CPA or equivalent.
  • 10+ years of progressive experience in technology audit, IT risk management, or information security, with at least 4 years in a leadership role, including interaction with senior management.
  • Experience managing cross-regional or multi-country audit programs, with specific exposure to emerging markets with regions.
  • Strong track record of leading high-performing audit teams and developing talent at all levels.
  • Exceptional communication, influencing, and executive presence skills - ability to present complex risk and audit topics to C-suite and Board audiences.
  • Proficiency with audit management and GRC technology platforms (e.g., Optro, Workiva, Archer, or equivalent).
  • Large, multi-brand, global, public company experience preferred.
  • M&A experience preferred.
  • Thorough knowledge of IT Operational Functions including IAM, Asset Management, Cybersecurity, Data Privacy.
  • Demonstrated experience leading or materially contributing to a digital transformation or data analytics program within an audit or risk function.
  • Thorough understanding of internal auditing standards, PCAOB auditing standards, COSO, SOX, US GAAP and risk assessment practice.
  • Robust understanding of regulatory and external requirements as they relate to IT, privacy and cybersecurity for regulations such as GDPR, NERC-CIP and SOX.
  • Proven track-record of implementing technology enablers such as data analytics, AI, etc. to modernize risk & audit capabilities.
  • Proven ability to handle scale, change agenda, pace and overall complexity.
  • Experience implementing and managing change within an organization, taking steps to remove barriers or to accelerate its pace.
  • Track record of working alongside business leaders, positioning internal audit as a strategic partner, identifying and helping mitigate risk.
  • Superior business acumen; ability to build strong relationships and trust with company leadership and business process owners.
  • Broad understanding of the inter-dependency between operational, technological, strategic and reputational risks as well as general compliance standards.
  • Professional, self-starter, solution-minded, results oriented and approachable.
  • Strong analytical and problem-solving skills with attention to detail and customer focus.
  • Excellent organizational, time management and prioritization skills.
  • Commitment to maintaining a high degree of discretion and confidentiality.

#LI-DNI
Base Salary: $140,610-253,080
Base salary compensation will be determined based on factors such as geographic location, skills, education, experience for this role, and/or internal equity of our current employees as part of any final offer. This position is also eligible to participate in McCormick's Incentive Bonus (MIB) Plan/ McCormick's Sales Incentive Bonus (SIB) Plan/ McCormick's Dividend Program. In addition to a competitive compensation package, permanent employees of McCormick are eligible for our extensive Total Rewards programs that include:
- Comprehensive health plans covering medical, vision, dental, life and disability benefits
- Family-friendly benefits such as paid parental leave, fertility benefits, Employee Assistance Program, and caregiver support
- Retirement and investment programs including 401(k) and profit-sharing plans
McCormick & Company is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected veteran status, age, or any other characteristic protected by law.
As a general policy, McCormick does not offer employment visa sponsorships upon hire or in the future.
#LI-DNI
WHY WORK AT MCCORMICK?
As a McCormick employee you'll be empowered to focus on more than your individual responsibilities. You'll have the opportunity to be part of something bigger than yourself-to have a say in where the company is going and how it's growing.
Between our passion for flavor, our 130-year history of leadership and integrity, the competitive and comprehensive benefits we offer, and our culture, which is built on respect and opportunities for growth, there are many reasons to join us at McCormick.

What McCormick & Company employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom