1

Grc Risk Analyst Jobs in Washington (NOW HIRING)

The GRC Analyst supports the administration of Information Security Governance, Risk, and Compliance programs, including policy exception management and enterprise risk register activities using ...

The GRC Analyst supports the administration of Information Security Governance, Risk, and Compliance programs, including policy exception management and enterprise risk register activities using ...

Jr. GRC Analyst

Rockville, MD ยท On-site

$35 - $40/hr

The GRC Analyst supports the administration of Information Security Governance, Risk, and Compliance programs, including policy exception management and enterprise risk register activities using ...

next page

Showing results 1-20

Grc Risk Analyst information

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.
What job categories do people searching Grc Risk Analyst jobs in Washington look for? The top searched job categories for Grc Risk Analyst jobs in Washington are:
What cities in Washington are hiring for Grc Risk Analyst jobs? Cities in Washington with the most Grc Risk Analyst job openings:
Infographic showing various Grc Risk Analyst job openings in Washington as of July 2026, with employment types broken down into 64% Full Time, 12% Part Time, and 24% Contract. Highlights an 61% Physical, 5% Hybrid, and 34% Remote job distribution.

Information Security Governance, Risk & Compliance (GRC) Analyst

Cyquent, Inc.

Rockville, MD โ€ข On-site

Other

This job post hasย expired 1 day ago.ย Applications are no longer accepted.


Job description

Job Title:  Information Security Governance, Risk & Compliance (GRC) Analyst

Location:  Rockville, MD (Hybrid/Onsite)

Job Type:  Contract / Full Time

Client: Direct Client

Certificates are mandatory to Submit.

 

Required Qualifications

  • Bachelor''''s degree in Cybersecurity, Information Systems, Information Technology, Computer Science, Business Information Systems, or a related field.
  • Minimum 3+ year of experience in Information Security, Cybersecurity, Governance, Risk & Compliance (GRC), Risk Management, IT Audit, Compliance, or Information Technology.
  • entry level candidates with relevant internships are encouraged to apply.

Required Skills

  • ServiceNow (IRM preferred)
  • Governance, Risk & Compliance (GRC)
  • Information Security
  • Risk Management
  • Information Security Policy Exceptions
  • Enterprise Risk Register
  • Risk Analysis & Risk Assessment
  • Cybersecurity Principles
  • NIST Cybersecurity Framework (CSF)
  • Microsoft Office 365
  • Technical Documentation
  • Customer Service
  • Excellent Written & Verbal Communication

Responsibilities

  • Administer Information Security Policy Exception requests.
  • Perform risk assessments and document findings.
  • Maintain the Enterprise Risk Register using ServiceNow IRM.
  • Track risk mitigation activities, approvals, and documentation.
  • Generate reports, dashboards, and risk metrics.
  • Collaborate with IT teams, business stakeholders, and Information Security leadership.

Preferred Certifications

  • CompTIA Security+
  • CISM Fundamentals (CISM-F)
  • NIST Cybersecurity Framework (NCSF) Practitioner
  • ISACA IT Risk Fundamentals
  • ISACA Cybersecurity Audit Certificate
  • HIPAA Security/Compliance Certification

Cyquent logo

About Cyquent

Sourced by ZipRecruiter

Cyquent is a Technology Enabler, providing end-to-end IT Solutions and Services. Founded in 2001, we have spent the last two decades curating our processes and expertise. Our focus on providing solutions and not just technology has been the prime distinguishing factor in the success of our clients, and therefore, in our success as well. At Cyquent, we recognize that change is the only constant. We understand that staying on top of emerging technology trends is essential for driving innovation and helping our clients accomplish their business goals.

Company size

51 - 200 Employees

Headquarters location

Rockville, MD, US

Year founded

2001

Social media