1

Grc Risk Analyst Jobs in Fort Washington, MD (NOW HIRING)

US Citizen Applicants Only SafePaaS is seeking a Business Analyst with a compliance and IT risk background to bridge business stakeholders, client teams, and technical delivery on GRC implementations.

... and enterprise GRC programs. * Proficiency in Third-Party Risk Management (TPRM) and vendor ... Conduct third-party vendor security reviews and analyze contract clauses for risk exposure.

New

GRC Lead

Fairfax, VA ยท On-site

$95 - $120/hr

You own the compliance calendar, the risk register, the audit and assessment relationships, and the evidence that proves our posture. You lead a GRC Analyst and report to the CTO & EVP. This is a ...

Cyber Risk / Compliance Analyst work, ISO and risk-platform support, evidence coordination, client ... GRC or trust-management platforms such as Vanta, Archer, ServiceNow GRC, OneTrust, Drata, or ...

Showing results 21-40

Grc Risk Analyst information

See Fort Washington, MD salary details

$15

$41

$67

How much do grc risk analyst jobs pay per hour?

As of Sep 5, 2026, the average hourly pay for grc risk analyst in Fort Washington, MD is $41.70, according to ZipRecruiter salary data. Most workers in this role earn between $30.72 and $50.77 per hour, depending on experience, location, and employer.

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What are popular job titles related to Grc Risk Analyst jobs in Fort Washington, MD?

For Grc Risk Analyst jobs in Fort Washington, MD, the most frequently searched job titles are:

What job categories do people searching Grc Risk Analyst jobs in Fort Washington, MD look for?

The top searched job categories for Grc Risk Analyst jobs in Fort Washington, MD are:

What cities near Fort Washington, MD are hiring for Grc Risk Analyst jobs?

Cities near Fort Washington, MD with the most Grc Risk Analyst job openings:

Business Analyst - GRC - US Citizen

SafePaaS

Washington, DC โ€ข On-site

Full-time

Posted 3 days ago

New


Job description

US Citizen Applicants Only


SafePaaS is seeking a
Business Analyst with a compliance and IT risk background
to bridge business stakeholders, client teams, and technical delivery on GRC implementations. This role focuses on requirements gathering, data analysis, and dashboard/reporting delivery for clients using SafePaaS to manage SoD violations, access risk, and regulatory controls - rather than deep ERP security configuration itself. It's ideal for someone who understands financial risk, fraud patterns, and regulatory frameworks, and can translate those into system requirements, controls logic, and stakeholder-facing reporting.


Key Responsibilities

  • Elicit and document business requirements from client stakeholders (compliance, audit, risk, and IT teams) for SoD rules, access controls, and risk libraries within the SafePaaS platform.
  • Translate regulatory requirements into functional specifications and user stories for the SafePaaS product/config team.
  • Build dashboards and reports visualizing SoD violations, remediation status, control effectiveness, and audit-readiness metrics for client stakeholders and internal leadership.
  • Support client onboarding by mapping business processes and risk taxonomies to SafePaaS rule sets, working alongside technical configuration teams.
  • Facilitate Agile ceremonies for platform enhancement and client implementation projects, managing requirements in JIRA/Confluence.
  • Prepare audit-ready documentation: functional specs, SOPs, control narratives, and remediation reports.
  • Serve as a liaison between clients' compliance/audit teams and SafePaaS's technical delivery team, ensuring requirements are accurately captured and delivered.
  • Stay current on emerging risk areas - including AI/non-human identity (NHI) governance and evolving regulatory frameworks - and help incorporate them into requirements.

Required Qualifications

  • Bachelor's degree in Business, Systems Engineering, Finance, or related field.
  • 4+ years of Business Analyst experience, ideally within financial compliance, fraud/risk, or regulatory environments.
  • Strong SQL skills and experience validating/reconciling data across multiple systems.
  • Experience with Agile/Scrum delivery (JIRA, Confluence) and writing user stories/functional specs.
  • Strong dashboard/reporting skills (Power BI or equivalent BI tools).
  • Understanding of internal controls frameworks (SOX, COSO, ITGC) and segregation of duties concepts.
  • Excellent stakeholder communication skills, with experience working across compliance, audit, and technical teams.

Preferred Qualifications

  • Familiarity with ERP security/access governance concepts (Oracle GRC/AACG/CCG/PCG, SAP GRC, or similar platforms) - hands-on config experience not required but a plus.
  • Experience supporting regulatory/government clients (SEC, FHFA, financial institutions).
  • US Federal Agency Security Clearance