1

Grc Risk Jobs in Baltimore, MD (NOW HIRING)

Cloud SCA-R, Senior

Fort George G Meade, MD · On-site

$115K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Validate CSO controls within eMASS or other government-provided Governance, Risk, and Compliance (GRC) tools; ensure accurate tracking in the Mission Status Report (MSR). * Review and verify the ...

Cloud SCA-R, Mid

Fort George G Meade, MD · On-site

$72.75 - $96.50/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Proficiency with eMASS or equivalent Government Risk and Compliance (GRC) tools * Demonstrated ability to interpret and apply NIST SP 800-53 security controls in cloud environments * Strong ...

Cloud SCA-R, Mid

Fort George G Meade, MD · On-site

$72.75 - $96.50/hr

Proficiency with eMASS or equivalent Government Risk and Compliance (GRC) tools * Demonstrated ability to interpret and apply NIST SP 800-53 security controls in cloud environments * Strong ...

Showing results 41-60

Grc Risk information

See Baltimore, MD salary details

$22.4K

$117.5K

$208.7K

How much do grc risk jobs pay per year?

As of Aug 18, 2026, the average yearly pay for grc risk in Baltimore, MD is $117,506.00, according to ZipRecruiter salary data. Most workers in this role earn between $84,000.00 and $144,100.00 per year, depending on experience, location, and employer.

What is the difference between Grc Risk vs Grc Analyst?

AspectGrc RiskGrc Analyst
CertificationsISO 31000, CRISC, COSOCISA, CRISC, CISSP
Work EnvironmentRisk management teams, compliance departmentsIT, audit, compliance teams
Industry UsageFinancial, healthcare, corporate sectorsIT, finance, consulting firms
Primary FocusIdentifying and managing enterprise risksAnalyzing controls, assessing risks in systems

Grc Risk professionals focus on enterprise-wide risk management strategies, while Grc Analysts typically analyze specific controls and systems to identify vulnerabilities. Both roles require similar certifications and often work within the same industries, but Grc Risk has a broader scope in risk oversight, whereas Grc Analysts concentrate on detailed control assessments.

What cities near Baltimore, MD are hiring for Grc Risk jobs?

Cities near Baltimore, MD with the most Grc Risk job openings:

Cloud SCA-R, Senior

AGE Solutions

Fort George G Meade, MD

$115K/yr

Full-time

Re-posted yesterday


Job description

AGE Solutions is looking for a Cloud SCA-R, Senior to join our team in support of an upcoming cybersecurity risk management and assessment program with our DoD customer. As a Team Lead, you will be responsible for performing analysis, conducting independent validations of assessments, and Continuous Monitoring (ConMon) for authorized CSPs and CSOs.

Individuals in this role must be available to work full-time on-site at Ft. Meade, MD.

Duties and Responsibilities Include:

  • Conduct cybersecurity assessments and validations of Cloud Service Offerings (CSOs) in support of the Department of Defense (DoD) Provisional Authorization (PA) process.
  • Evaluate Cloud Service Provider (CSP) documentation packages following government guidance and procedures, including key artifacts such as the Cloud Architecture Diagram, System Security Plan (SSP), SSP Addendum, Readiness Assessment Report (RAR), System Architecture, Security Assessment Plan (SAP), Security Assessment Report (SAR), and associated Plans of Action & Milestones (POA&Ms).
  • Review, analyze, and process additional documents including Change Requests, Extension Requests, Deviation Requests, Whitelist Requests, Corrective Action Plans, templates, process guide approvals, and continuous monitoring (ConMon) artifacts for existing Provisional Authorizations.
  • Prepare and deliver up to 30 Cloud Security Assessment Packages annually, each including validated cybersecurity controls, certifier recommendations, and a statement of residual risk.
  • Participate in technical kickoff meetings and review preliminary documentation to assess a CSP's readiness posture.
  • Analyze and provide detailed feedback on CSP submissions such as the RAR, SAP, SSP, and architectural diagrams.
  • Assess and document the operational impact of authorizations, changes, and vulnerabilities on the CSP environment.
  • Develop Cloud Security Assessment Packages in accordance with established guidelines, including the SAR, POA&M, and any Deviation Requests.
  • Draft Authorization Recommendation Memoranda outlining CSO compliance with DoD cybersecurity controls, residual risks, and technical findings.
  • Prepare formal DoD Provisional Authorization memoranda, detailing authorization length, CSO boundary, services provided, operating conditions, DoD usage considerations, and follow-on activities.
  • Validate CSO controls within eMASS or other government-provided Governance, Risk, and Compliance (GRC) tools; ensure accurate tracking in the Mission Status Report (MSR).
  • Review and verify the Customer Responsibility Matrix (CRM), ensuring proper control inheritance is reflected in eMASS/GRC systems.
  • Upload authorization conditions as system-level POA&Ms in eMASS and monitor their resolution.
  • Organize and associate all received documentation with applicable security controls within eMASS.
  • Maintain and update the DoD Cloud Process Guide, including all checklists, templates, forms, and guidance documents.
  • Assist in developing internal requirements and how-to guides for assessors conducting CSP validations.
  • Document and refine assessment procedures and validation best practices to align with DoDI 8510.01 and the DoD Cloud Computing Security Requirements Guide (SRG).
  • Contribute to the ongoing development and annual updates of the DoD Cloud Assessment Process Guides as requested by the Government.

Requirements:

  • Bachelor's degree (IT-related field preferred)
  • Eight (8) years of overall experience in cybersecurity or network security position
  • Have an active DoD Top Secret clearance with SCI eligibility
  • DoD 8570 IAM/IA Technical (IAT) Level III certification
  • Familiarity with security controls for Azure, AWS, and assorted cloud platforms
  • Solid understanding of DoD Risk Management Framework (RMF), DoDI 8510.01, and DoD Cloud Computing Security Requirements Guide (SRG)
  • Familiarity with security controls for Azure, AWS, and assorted cloud platforms
  • Hands-on experience with eMASS or other government-provided GRC tools
  • Familiarity with cloud security documentation, including SSPs, SARs, RARs, and POA&Ms
  • Ability to analyze complex cloud architectures and provide accurate risk assessments
  • Strong technical writing and communication skills to produce security assessment reports and formal recommendations
  • Applicants must reside within a commutable distance of Ft. Meade, MD in order to work onsite full time.

The projected salary range for this position is $115,000+ annually. Final compensation will be determined based on factors including years of relevant experience, active security clearance level, certifications, technical skillset, contract requirements, and overall qualifications.