1

Grc Risk Analyst Jobs in Baltimore, MD (NOW HIRING)

Cloud SCA-R, Mid

Fort George G Meade, MD ยท On-site

$72.75 - $96.50/hr

... Risk and Compliance (GRC) tools * Demonstrated ability to interpret and apply NIST SP 800-53 security controls in cloud environments * Strong analytical and technical writing skills with the ability ...

Experience with governance, risk, and compliance (GRC) tooling. * AI Governance certifications and ... business analyst, governance analyst, or risk/compliance analyst in a regulated industry.

Experience with governance, risk, and compliance (GRC) tooling. * AI Governance certifications and ... business analyst, governance analyst, or risk/compliance analyst in a regulated industry.

Experience with governance, risk, and compliance (GRC) tooling. * AI Governance certifications and ... business analyst, governance analyst, or risk/compliance analyst in a regulated industry.

ServiceNow Platform Engineer

Baltimore, MD ยท On-site

$180 - $240/hr

... analytics * Enable operational resilience through risk-informed Change Management, blackout ... Equip Cyber and GRC teams with automation pipelines, policy attestation workflows, and operational ...

Security Lead

Linthicum, MD ยท On-site

$184K/yr

Mentor and develop security analysts to enhance their understanding of cybersecurity challenges and GRC automation. What you need: * Compliance Risk Management * Cybersecurity * Cybersecurity Risk ...

Showing results 41-60

Grc Risk Analyst information

See Baltimore, MD salary details

$15

$40

$65

How much do grc risk analyst jobs pay per hour?

As of Sep 5, 2026, the average hourly pay for grc risk analyst in Baltimore, MD is $40.23, according to ZipRecruiter salary data. Most workers in this role earn between $29.62 and $48.94 per hour, depending on experience, location, and employer.

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What job categories do people searching Grc Risk Analyst jobs in Baltimore, MD look for?

The top searched job categories for Grc Risk Analyst jobs in Baltimore, MD are:

What cities near Baltimore, MD are hiring for Grc Risk Analyst jobs?

Cities near Baltimore, MD with the most Grc Risk Analyst job openings:

Infographic showing various Grc Risk Analyst job openings in Baltimore, MD as of August 2026, with employment types broken down into 1% As Needed, 87% Full Time, 9% Part Time, and 3% Contract. Highlights an 88% Physical, 4% Hybrid, and 8% Remote job distribution, with an average salary of $83,674 per year, or $40.2 per hour.

Cloud SCA-R, Mid

AGE solutions

Fort George G Meade, MD โ€ข On-site

$72.75 - $96.50/hr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 20 hours ago


Job description

About Us
AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and intelligence sectors. Prioritizing innovation and client-focused solutions, we assist major agencies in addressing intricate issues and ensuring a more secure future.

AGE Solutions is looking for a Cloud SCA-R, Mid, to join our team in support of a cybersecurity risk management and assessment program with our DoD customer. In this role, you will be part of a team responsible for performing analysis, conducting independent validations of assessments, and Continuous Monitoring (ConMon) for authorized CSPs and CSOs.

Individuals in this role must be available to work full-time on-site at Ft. Meade, MD.

Essential Duties and Responsibilities Include:

  • Conduct cybersecurity assessments and validations of Cloud Service Offerings (CSOs) in support of the DoD Provisional Authorization (PA) process
  • Prepare 30 Cloud Security Assessment Packages per year, including validated cybersecurity controls, certifier's recommendations, and residual risk statements
  • Review Cloud Service Provider (CSP) documentation packages, including architectural diagrams, System Security Plans (SSP) with Addendums, Readiness Assessment Reports (RAR), Security Assessment Plans (SAP), and Security Assessment Reports (SAR)
  • Evaluate supporting materials such as POA&Ms, Change Requests, Extension and Deviation Requests, Whitelist Requests, Corrective Action Plans, and applicable templates, checklists, and Continuous Monitoring (ConMon) artifacts
  • Attend technical kickoff meetings to evaluate and document the CSP's security posture and readiness for assessment
  • Analyze and provide feedback on assessment documentation, including the RAR, SAP, SSP, and system architecture diagrams
  • Identify and document the operational impact of security authorizations, changes, or identified vulnerabilities within the CSP's environment
  • Develop complete Cloud Security Assessment Packages in accordance with DoD standards, ensuring inclusion of SARs, POA&Ms, and Deviation Requests
  • Create authorization recommendation memorandums summarizing compliance with DoD cybersecurity controls, technical evaluation results, and residual risk considerations
  • Draft DoD PA memorandums outlining CSO boundary definitions, service offerings, authorization duration, terms and conditions, DoD usage considerations, and follow-on actions
  • Validate implementation of CSO controls within eMASS or a government-provided GRC platform, and log assessment completion in the Mission Security Review (MSR)
  • Review the Customer Responsibility Matrix (CRM) and ensure correct inheritance mapping within eMASS or the designated GRC tool
  • Enter all authorization conditions into eMASS as system-level POA&Ms and monitor for timely resolution
  • Upload and associate all CSP documentation with applicable security controls in eMASS or the appropriate system of record
  • Track and manage all CSO-related data using the Team Lead Resource (TLR) Assessment Database
  • Maintain and update the DoD Cloud Process Guide and associated templates, forms, checklists, and documentation
  • Contribute to the development of internal instructions, how-to guides, and reference material to support consistent assessor workflows
  • Ensure assessment activities are conducted in compliance with DoDI 8510.01 and the DoD Cloud Computing Security Requirements Guide (SRG)
  • Document assessment methodologies and validation best practices to continuously improve assessment accuracy, consistency, and process efficiency
  • Support the ongoing development and annual updates of the DoD Cloud Assessment Process Guides in alignment with evolving policy and government directives

Required Qualifications:

  • Education:
    • Bachelor's degree (IT-related field preferred)
  • Experience:
    • Five (5) years of overall experience in cybersecurity or network security position
  • Security Clearance:
    • Must have an active DoD Top Secret clearance with SCI eligibility
  • Certifications:
    • DoD 8570 IAM/IA Technical (IAT) Level II certification
  • Skills and Knowledge:
    • Working knowledge of DoD Risk Management Framework (RMF) and DoDI 8510.01
    • Familiarity with the DoD Cloud Computing Security Requirements Guide (SRG) and associated cloud security policies
    • Familiarity with security controls for Azure, AWS, and assorted cloud platforms
    • Experience conducting security assessments and developing security documentation (e.g., SSP, SAR, POA&M, SAP)
    • Proficiency with eMASS or equivalent Government Risk and Compliance (GRC) tools
    • Demonstrated ability to interpret and apply NIST SP 800-53 security controls in cloud environments
    • Strong analytical and technical writing skills with the ability to communicate complex topics clearly
  • Location:
    • Applicants must reside within a commutable distance of Ft. Meade, MD in order to work onsite full time.

The projected salary range for this position is $100,000+ annually. Final compensation will be determined based on factors including years of relevant experience, active security clearance level, certifications, technical skillset, contract requirements, and overall qualifications.

At AGE Solutions, we reward performance, invest in growth, and share success. Our benefits support the whole person, professionally, financially, and personally.

  • 26 Days Paid Leave: Includes vacation, sick, personal time, and holidays. You choose how to use it.
  • Performance Bonuses: Performance bonuses are awarded based on individual contributions and company-wide results, aligning recognition with impact.
  • 401(k) with Match: We match 3% of your contributions with immediate vesting.
  • Financial Protection: Company-paid life insurance up to $300K and options for additional coverage for you and your dependents.
  • Health Benefits: Multiple medical plans, dental, vision, FSA and HSA options to fit your needs.
  • Parental Leave: 15 days of fully paid leave for new parents, because family matters.
  • Military Differential Pay: We bridge the gap for employees on active duty, so they don't take a financial hit while serving.
  • Professional Growth: Paid training and certifications, tuition reimbursement, and the tools and tech to get the job done right.
  • Shared Success: In the event of a company sale, our CEO has committed to returning 80% of net proceeds to employees. This ensures our team shares in the long term value they help create.

At AGE, you'll do work that matters, supported by a company that delivers for its people.