Cyber Risk / Compliance Analyst work, ISO and risk-platform support, evidence coordination, client ... GRC or trust-management platforms such as Vanta, Archer, ServiceNow GRC, OneTrust, Drata, or ...
Cyber Risk / Compliance Analyst work, ISO and risk-platform support, evidence coordination, client ... GRC or trust-management platforms such as Vanta, Archer, ServiceNow GRC, OneTrust, Drata, or ...
The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an experienced Information System Security Officer (ISSO) to bridge the gap between high-level policy and ...
The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an experienced Information System Security Officer (ISSO) to bridge the gap between high-level policy and ...
Enterprise Cybersecurity GRC Governance Analyst
Mclean, VA · On-site
$99 - $225/hr
Enterprise Cybersecurity GRC Governance Analyst The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an experienced Information System Security Officer (ISSO) to ...
Enterprise Cybersecurity GRC Governance Analyst
Mclean, VA · On-site
$99 - $225/hr
Enterprise Cybersecurity GRC Governance Analyst The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an experienced Information System Security Officer (ISSO) to ...
The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an experienced Information System Security Officer (ISSO) to bridge the gap between high-level policy and ...
The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an experienced Information System Security Officer (ISSO) to bridge the gap between high-level policy and ...
The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an experienced Information System Security Officer (ISSO) to bridge the gap between high-level policy and ...
The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an experienced Information System Security Officer (ISSO) to bridge the gap between high-level policy and ...
GRC Engineer III
Washington, DC · On-site
GRC Engineer III Category: Cyber Security Main location: United States, District of Columbia ... Support risk aggregation, reporting accuracy, and enterprise level compliance functions. Lead ...
GRC Engineer III
Washington, DC · On-site
GRC Engineer III Category: Cyber Security Main location: United States, District of Columbia ... Support risk aggregation, reporting accuracy, and enterprise level compliance functions. Lead ...
... GRC, risk, compliance, audit, regulatory operations, government technology, public-sector solutions, government acquisition, or adjacent domains. * Domain Expertise: Demonstrated fluency in one or ...
... GRC, risk, compliance, audit, regulatory operations, government technology, public-sector solutions, government acquisition, or adjacent domains. * Domain Expertise: Demonstrated fluency in one or ...
KYM is seeking a Archer Governance, Risk, and Compliance (GRC) Consultant to execute and support the implementation of a successful DHS program. Responsibilities: * Develop, administer, and configure ...
Quick apply
KYM is seeking a Archer Governance, Risk, and Compliance (GRC) Consultant to execute and support the implementation of a successful DHS program. Responsibilities: * Develop, administer, and configure ...
... and risk mitigation. • Oversee security aspects of system builds, upgrades, patching, client ... GRC, SAP BTP, and other security tools. • Strong organizational skills to manage multiple ...
... and risk mitigation. • Oversee security aspects of system builds, upgrades, patching, client ... GRC, SAP BTP, and other security tools. • Strong organizational skills to manage multiple ...
... risk standards, procedures, appetite, registry, and business strategy. Expertise in compliance management, internal or external audit, and GRC platforms is strongly desired. The successful candidate ...
... risk standards, procedures, appetite, registry, and business strategy. Expertise in compliance management, internal or external audit, and GRC platforms is strongly desired. The successful candidate ...
... GRC efforts. This position is 100% Onsite and not open for Remote. Senior Analyst, Cybersecurity Governance, Risk and Compliance Responsibilities: - Review and understand current IT Risk Management ...
... GRC efforts. This position is 100% Onsite and not open for Remote. Senior Analyst, Cybersecurity Governance, Risk and Compliance Responsibilities: - Review and understand current IT Risk Management ...
Work within the Logic Manager (GRC) platform * Support metrics and reporting focused on issues and ... risk experience a plus * Desired knowledge of NCUA, FFIEC, BSA/AML, NIST (including the ...
Work within the Logic Manager (GRC) platform * Support metrics and reporting focused on issues and ... risk experience a plus * Desired knowledge of NCUA, FFIEC, BSA/AML, NIST (including the ...
Lead the Federal GRC pillar strategy, roadmap, operating model, governance rhythm, reporting ... Own the federal risk register governance model, including risk identification, severity assessment ...
Lead the Federal GRC pillar strategy, roadmap, operating model, governance rhythm, reporting ... Own the federal risk register governance model, including risk identification, severity assessment ...
Hands-on experience with ServiceNow Integrated Risk Management (IRM), Governance Risk and Compliance (GRC), or Strategic Portfolio Management (SPM) modules. * In-depth knowledge of FOCI concepts ...
Quick apply
Hands-on experience with ServiceNow Integrated Risk Management (IRM), Governance Risk and Compliance (GRC), or Strategic Portfolio Management (SPM) modules. * In-depth knowledge of FOCI concepts ...
Risk Mitigation Specialist
Washington, DC · On-site
$111K/yr
Hands-on experience with ServiceNow Integrated Risk Management (IRM), Governance Risk and Compliance (GRC), or Strategic Portfolio Management (SPM) modules. * In-depth knowledge of FOCI concepts ...
Risk Mitigation Specialist
Washington, DC · On-site
$111K/yr
Hands-on experience with ServiceNow Integrated Risk Management (IRM), Governance Risk and Compliance (GRC), or Strategic Portfolio Management (SPM) modules. * In-depth knowledge of FOCI concepts ...
Risk Mitigation Specialist
Washington, DC · On-site
$111K/yr
Hands-on experience with ServiceNow Integrated Risk Management (IRM), Governance Risk and Compliance (GRC), or Strategic Portfolio Management (SPM) modules. * In-depth knowledge of FOCI concepts ...
Risk Mitigation Specialist
Washington, DC · On-site
$111K/yr
Hands-on experience with ServiceNow Integrated Risk Management (IRM), Governance Risk and Compliance (GRC), or Strategic Portfolio Management (SPM) modules. * In-depth knowledge of FOCI concepts ...
ServiceNow GRC Application Developer
Mclean, VA · On-site
$110 - $150/hr
Certified Implementation Specialist - Risk and Compliance (GRC). * Experience with ServiceNow Integration Hub and REST integrations. * 4+ years of Agile/Scrum experience. * Strong communication and ...
New
ServiceNow GRC Application Developer
Mclean, VA · On-site
$110 - $150/hr
Certified Implementation Specialist - Risk and Compliance (GRC). * Experience with ServiceNow Integration Hub and REST integrations. * 4+ years of Agile/Scrum experience. * Strong communication and ...
New
Program Manager, Cybersecurity Risk
Reston, VA · On-site
$110.10 - $176.90/hr
Familiarity with GRC / TPRM platforms and security‑ratings services (e.g., OneTrust, Archer ... Understanding of qualitative risk analysis and the ability to translate risk into clear business ...
New
Program Manager, Cybersecurity Risk
Reston, VA · On-site
$110.10 - $176.90/hr
Familiarity with GRC / TPRM platforms and security‑ratings services (e.g., OneTrust, Archer ... Understanding of qualitative risk analysis and the ability to translate risk into clear business ...
New
We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to own and scale our security and AI governance compliance posture as SpaceXAI grows. You will set the standards the ...
Quick apply
We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to own and scale our security and AI governance compliance posture as SpaceXAI grows. You will set the standards the ...
Securities Compliance Content Specialist
Washington, DC · On-site
$120K - $140K/yr
CFM Partners GRC, Inc. helps organizations strengthen governance, manage risk, and build a lasting culture of compliance. Based in Washington, D.C., we've been delivering trusted Governance, Risk ...
Quick apply
Securities Compliance Content Specialist
Washington, DC · On-site
$120K - $140K/yr
CFM Partners GRC, Inc. helps organizations strengthen governance, manage risk, and build a lasting culture of compliance. Based in Washington, D.C., we've been delivering trusted Governance, Risk ...
Grc Risk information
See Ashburn, VA salary details
$23K - $40.4K
2% of jobs
$40.4K - $57.9K
2% of jobs
$57.9K - $75.3K
12% of jobs
$85.9K is the 25th percentile. Wages below this are outliers.
$75.3K - $92.7K
15% of jobs
$92.7K - $110.2K
16% of jobs
The median wage is $113.6K / yr.
$110.2K - $127.6K
16% of jobs
$143K is the 75th percentile. Wages above this are outliers.
$127.6K - $145K
14% of jobs
$145K - $162.5K
9% of jobs
$162.5K - $179.9K
10% of jobs
$179.9K - $197.3K
3% of jobs
$197.3K - $214.7K
2% of jobs
$23K
$120.9K
$214.7K
How much do grc risk jobs pay per year?
What is the difference between Grc Risk vs Grc Analyst?
| Aspect | Grc Risk | Grc Analyst |
|---|---|---|
| Certifications | ISO 31000, CRISC, COSO | CISA, CRISC, CISSP |
| Work Environment | Risk management teams, compliance departments | IT, audit, compliance teams |
| Industry Usage | Financial, healthcare, corporate sectors | IT, finance, consulting firms |
| Primary Focus | Identifying and managing enterprise risks | Analyzing controls, assessing risks in systems |
Grc Risk professionals focus on enterprise-wide risk management strategies, while Grc Analysts typically analyze specific controls and systems to identify vulnerabilities. Both roles require similar certifications and often work within the same industries, but Grc Risk has a broader scope in risk oversight, whereas Grc Analysts concentrate on detailed control assessments.
What are popular job titles related to Grc Risk jobs in Ashburn, VA?
For Grc Risk jobs in Ashburn, VA, the most frequently searched job titles are:
What job categories do people searching Grc Risk jobs in Ashburn, VA look for?
The top searched job categories for Grc Risk jobs in Ashburn, VA are:
What cities near Ashburn, VA are hiring for Grc Risk jobs?
Cities near Ashburn, VA with the most Grc Risk job openings:
Full-time
Medical, Dental, Vision, Life, Retirement
Posted 8 days ago
Job description
Company Overview
Every firm has a culture - the values, beliefs, methodology, attitudes and standards that reflect an organization's DNA. But the truly inspiring firms - the game-changers, the industry leaders and the disruptors - have cultures that propel them to innovate and stand out. At Brown Advisory, we aim to be one of those inspired firms. Over the years, we have purposefully built and nurtured our client-first culture.
Brown Advisory is an independent investment management and strategic advisory firm committed to delivering a combination of first-class performance, strategic advice and the highest level of client service. The firm's clients-including individuals, families, family offices, endowments, foundations, charities, institutions, consultants, and financial intermediaries-are served by over 1,000 colleagues worldwide, all of whom are equity owners of the firm.
Brown Advisory is currently seeking a Cyber GRC Specialist to support and mature the firm's governance, risk, compliance, and control-management routines. This blended role is designed for someone who can translate security requirements into practical business processes, drive evidence and accountability, and communicate clearly with technical and non-technical stakeholders.
As part of a lean Information Security team within a mid-sized financial services organization, this individual will serve as a central coordinator for cyber risk, policy management, control testing, audit readiness, client and regulatory response support, and vulnerability remediation governance. The role is not intended to be a hands-on vulnerability engineering role; rather, it ensures the process, ownership, exceptions, reporting, and governance routines are working.
Blended Role CoveragePrimary emphasis: Cyber GRC support for policies, controls, cyber risk tracking, audit coordination, exceptions, and governance routines.
Blended coverage: Cyber Risk / Compliance Analyst work, ISO and risk-platform support, evidence coordination, client/regulatory response support, communications, and vulnerability governance.
Duties and Responsibilities
Support and mature core cyber governance routines, including policy management, control ownership, risk acceptance, exception handling, standards maintenance, and periodic leadership reporting.
Maintain the cyber risk register and partner with technology and business owners to document risk decisions, remediation plans, due dates, dependencies, and residual risk.
Serve as a key administrator and process contributor for ISO and security-risk management platforms such as Vanta or similar tools.
Coordinate evidence collection, control testing, audit requests, client due diligence responses, regulatory requests, and recurring compliance deliverables.
Translate ISO 27001, regulatory, client, and internal security expectations into practical controls and operating procedures appropriate for Brown Advisory's size and risk profile.
Facilitate cross-functional communications for security change, SaaS inventory, policy enforcement, control adoption, and risk remediation.
Coordinate vulnerability management governance, including scan-result intake, prioritization routines, remediation tracking, exception handling, and reporting.
Partner with security engineers, infrastructure teams, application owners, Compliance, Legal, Operations, and Client Service to close control gaps in a business-aligned manner.
Develop clear metrics for control effectiveness, audit readiness, exceptions, overdue remediation, and recurring governance activities.
Identify process improvements that make security governance more repeatable, transparent, and useful without creating unnecessary bureaucracy.
Preferred Qualifications
Bachelor's degree in cyber security, information systems, risk management, business, or a relevant field preferred; equivalent professional experience will be considered.
3-6 years of experience in cyber GRC, information security, technology risk, IT audit, compliance, or related control-management work preferred.
Working knowledge of ISO 27001, SOC 2, NIST CSF, CIS Controls, SEC/FINRA expectations, privacy requirements, or comparable control frameworks.
Experience supporting audits, evidence collection, control testing, policy updates, issue tracking, or risk-register maintenance in a regulated environment; financial services experience preferred.
CISA, CRISC, CISM, Security+, ISO 27001 Foundation/Lead Implementer, or similar professional designation preferred but not required.
Technical Skills
Cyber risk registers, exception management, control testing, evidence management, policy lifecycle management, and audit coordination.
GRC or trust-management platforms such as Vanta, Archer, ServiceNow GRC, OneTrust, Drata, or similar tools.
Vulnerability management governance, including prioritization, remediation tracking, aging analysis, exception workflows, and executive reporting.
Strong knowledge of cyber security controls across identity, endpoint, cloud, network, data protection, application security, and third-party risk.
Excellent writing, facilitation, and stakeholder-management skills, including the ability to turn technical risk into clear business language.
Practical judgment about when to enforce, when to escalate, and when to help the business find a workable control path.
Demonstrates curiosity and a continuous improvement mindset by identifying opportunities to enhance processes, improve efficiency, and thoughtfully leverage new technologies and tools, including AI-enabled productivity solutions
Personal Attributes
Take ownership and move initiatives forward without constant oversight.
Balance technical depth, process discipline, and sound business judgment.
Approach risk management pragmatically rather than theoretically.
Thrive in collaborative, high-accountability environments.
Communicate clearly with technical and non-technical colleagues.
Bring an entrepreneurial mindset to building and improving security capabilities.
Applicants must be authorized to work in the United States without the need for current or future employer-sponsored work authorization (e.g., H-1B , O-1, F-1 (OPT), TN, or any other non-immigrant visa classifications that require employer support or sponsorship).
MD Salary: $95-$115k. Commensurate with experience and location. Does not include bonus or long term incentive eligibility (if applicable).
DC Salary: $104.5K-$126.5K. Commensurate with experience and location. Does not include bonus or long-term incentive eligibility (if applicable).
Benefits
At Brown Advisory we offer a competitive compensation package, including full benefits.
Medical
Dental
Vision
Wellness program participation incentive
Financial wellness program
Fitness event fee reimbursement
Gym membership discounts
Colleague Assistance Program
Telemedicine Program (for those enrolled in Medical)
Adoption Benefits
Daycare late pick-up fee reimbursement
Basic Life & Accidental Death & Dismemberment Insurance
Voluntary Life & Accidental Death & Dismemberment Insurance
Short Term Disability
Paid parental leave
Group Long Term Disability
Pet Insurance
401(k) (50% employer match up to IRS limit, 4 year vesting)
Brown Advisory is an Equal Employment Opportunity Employer.
About Brown Advisory
Sourced by ZipRecruiter
Industry
Finance and insurance
Company size
201 - 500 Employees
Headquarters location
Baltimore, MD, US
Year founded
1993