1

Grc Risk Analyst Jobs in Baltimore, MD (NOW HIRING)

... GRC tools * Familiarity with cloud security documentation, including SSPs, SARs, RARs, and POA&Ms * Ability to analyze complex cloud architectures and provide accurate risk assessments * Strong ...

... Risk and Compliance (GRC) tools * Demonstrated ability to interpret and apply NIST SP 800-53 security controls in cloud environments * Strong analytical and technical writing skills with the ability ...

... GRC tools * Familiarity with cloud security documentation, including SSPs, SARs, RARs, and POA&Ms * Ability to analyze complex cloud architectures and provide accurate risk assessments * Strong ...

Cloud SCA-R, Mid

Fort George G Meade, MD

$72.75 - $96.50/hr

... Risk and Compliance (GRC) tools * Demonstrated ability to interpret and apply NIST SP 800-53 security controls in cloud environments * Strong analytical and technical writing skills with the ability ...

Cloud SCA-R, Mid

Fort George G Meade, MD ยท On-site

$72.75 - $96.50/hr

... Risk and Compliance (GRC) tools * Demonstrated ability to interpret and apply NIST SP 800-53 security controls in cloud environments * Strong analytical and technical writing skills with the ability ...

Showing results 21-40

Grc Risk Analyst information

See Baltimore, MD salary details

$15

$40

$65

How much do grc risk analyst jobs pay per hour?

As of Aug 9, 2026, the average hourly pay for grc risk analyst in Baltimore, MD is $40.23, according to ZipRecruiter salary data. Most workers in this role earn between $29.62 and $48.94 per hour, depending on experience, location, and employer.

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.
What job categories do people searching Grc Risk Analyst jobs in Baltimore, MD look for? The top searched job categories for Grc Risk Analyst jobs in Baltimore, MD are:
What cities near Baltimore, MD are hiring for Grc Risk Analyst jobs? Cities near Baltimore, MD with the most Grc Risk Analyst job openings:
Infographic showing various Grc Risk Analyst job openings in Baltimore, MD as of August 2026, with employment types broken down into 1% As Needed, 88% Full Time, 8% Part Time, and 3% Contract. Highlights an 88% Physical, 4% Hybrid, and 8% Remote job distribution, with an average salary of $83,674 per year, or $40.2 per hour.

Cloud SCA-R, Senior

AGE Solutions

Fort George G Meade, MD โ€ข On-site

$115K/yr

Full-time

Re-posted 22 days ago


Job description

AGE Solutions is looking for a Cloud SCA-R, Senior to join our team in support of an upcoming cybersecurity risk management and assessment program with our DoD customer. As a Team Lead, you will be responsible for performing analysis, conducting independent validations of assessments, and Continuous Monitoring (ConMon) for authorized CSPs and CSOs.

Individuals in this role must be available to work full-time on-site at Ft. Meade, MD.

Duties and Responsibilities Include:

  • Conduct cybersecurity assessments and validations of Cloud Service Offerings (CSOs) in support of the Department of Defense (DoD) Provisional Authorization (PA) process.
  • Evaluate Cloud Service Provider (CSP) documentation packages following government guidance and procedures, including key artifacts such as the Cloud Architecture Diagram, System Security Plan (SSP), SSP Addendum, Readiness Assessment Report (RAR), System Architecture, Security Assessment Plan (SAP), Security Assessment Report (SAR), and associated Plans of Action & Milestones (POA&Ms).
  • Review, analyze, and process additional documents including Change Requests, Extension Requests, Deviation Requests, Whitelist Requests, Corrective Action Plans, templates, process guide approvals, and continuous monitoring (ConMon) artifacts for existing Provisional Authorizations.
  • Prepare and deliver up to 30 Cloud Security Assessment Packages annually, each including validated cybersecurity controls, certifier recommendations, and a statement of residual risk.
  • Participate in technical kickoff meetings and review preliminary documentation to assess a CSP's readiness posture.
  • Analyze and provide detailed feedback on CSP submissions such as the RAR, SAP, SSP, and architectural diagrams.
  • Assess and document the operational impact of authorizations, changes, and vulnerabilities on the CSP environment.
  • Develop Cloud Security Assessment Packages in accordance with established guidelines, including the SAR, POA&M, and any Deviation Requests.
  • Draft Authorization Recommendation Memoranda outlining CSO compliance with DoD cybersecurity controls, residual risks, and technical findings.
  • Prepare formal DoD Provisional Authorization memoranda, detailing authorization length, CSO boundary, services provided, operating conditions, DoD usage considerations, and follow-on activities.
  • Validate CSO controls within eMASS or other government-provided Governance, Risk, and Compliance (GRC) tools; ensure accurate tracking in the Mission Status Report (MSR).
  • Review and verify the Customer Responsibility Matrix (CRM), ensuring proper control inheritance is reflected in eMASS/GRC systems.
  • Upload authorization conditions as system-level POA&Ms in eMASS and monitor their resolution.
  • Organize and associate all received documentation with applicable security controls within eMASS.
  • Maintain and update the DoD Cloud Process Guide, including all checklists, templates, forms, and guidance documents.
  • Assist in developing internal requirements and how-to guides for assessors conducting CSP validations.
  • Document and refine assessment procedures and validation best practices to align with DoDI 8510.01 and the DoD Cloud Computing Security Requirements Guide (SRG).
  • Contribute to the ongoing development and annual updates of the DoD Cloud Assessment Process Guides as requested by the Government.

Requirements:

  • Bachelor's degree (IT-related field preferred)
  • Eight (8) years of overall experience in cybersecurity or network security position
  • Have an active DoD Top Secret clearance with SCI eligibility
  • DoD 8570 IAM/IA Technical (IAT) Level III certification
  • Familiarity with security controls for Azure, AWS, and assorted cloud platforms
  • Solid understanding of DoD Risk Management Framework (RMF), DoDI 8510.01, and DoD Cloud Computing Security Requirements Guide (SRG)
  • Familiarity with security controls for Azure, AWS, and assorted cloud platforms
  • Hands-on experience with eMASS or other government-provided GRC tools
  • Familiarity with cloud security documentation, including SSPs, SARs, RARs, and POA&Ms
  • Ability to analyze complex cloud architectures and provide accurate risk assessments
  • Strong technical writing and communication skills to produce security assessment reports and formal recommendations
  • Applicants must reside within a commutable distance of Ft. Meade, MD in order to work onsite full time.

The projected salary range for this position is $115,000+ annually. Final compensation will be determined based on factors including years of relevant experience, active security clearance level, certifications, technical skillset, contract requirements, and overall qualifications.