2

Remote Grc Analyst Jobs in Reston, VA (NOW HIRING)

Sr. Analyst - SCRM

VA · On-site +1

$88K - $116K/yr

General information Job Posting Title Sr. Analyst - SCRM Date Thursday, May 28, 2026 City Remote ... using GRC/TPRM tooling to manage supplier inventories, risk assessments, evidence collection ...

Research, draft, and analyze policies to ensure alignment with stakeholder needs, subject matter ... Familiarity with security governance, risk management, and compliance (GRC) processes. * Must be ...

Research, draft, and analyze policies to ensure alignment with stakeholder needs, subject matter ... Familiarity with security governance, risk management, and compliance (GRC) processes. * Must be ...

Research, draft, and analyze policies to ensure alignment with stakeholder needs, subject matter ... Familiarity with security governance, risk management, and compliance (GRC) processes. * Must be ...

SOC Analyst

Washington, DC · Remote

$50 - $55/hr

Hybrid 2 Days Onsite/3 Days Remote in Washington, DC Our client seeks a SOC Analyst to support ... Exposure to AWS, hybrid architectures, GRC tools such as Xacta, and enterprise platforms such as ...

FedRAMP Analyst

Washington, DC · On-site +1

$80K - $100K/yr

Remote USA Compensation: $80,000 - $100,000 / year Description The FedRAMP Analyst is responsible ... Skills, Knowledge and Expertise * 3+ years of experience in cybersecurity compliance, GRC, or ...

IT & Cyber Security Consultant

Washington, DC · On-site +1

$156K - $234K/yr

Location: Remote - This position may be performed remotely in states where the company is ... You will enable the SOC by improving detection and orchestration capabilities and enable GRC by ...

IT & Cyber Security Consultant

Washington, DC · On-site +1

$156K - $234K/yr

Location: Remote - This position may be performed remotely in states where the company is ... You will enable the SOC by improving detection and orchestration capabilities and enable GRC by ...

IT & Cyber Security Consultant

Washington, DC · On-site +1

$156K - $234K/yr

Location: Remote - This position may be performed remotely in states where the company is ... You will enable the SOC by improving detection and orchestration capabilities and enable GRC by ...

IT & Cyber Security Consultant

Washington, DC · On-site +1

$156K - $234K/yr

Location: Remote - This position may be performed remotely in states where the company is ... You will enable the SOC by improving detection and orchestration capabilities and enable GRC by ...

IT & Cyber Security Consultant

Washington, DC · On-site +1

$156K - $234K/yr

Location: Remote - This position may be performed remotely in states where the company is ... You will enable the SOC by improving detection and orchestration capabilities and enable GRC by ...

IT & Cyber Security Consultant

Washington, DC · On-site +1

$156K - $234K/yr

Location: Remote - This position may be performed remotely in states where the company is ... You will enable the SOC by improving detection and orchestration capabilities and enable GRC by ...

next page

Showing results 1-20

Remote Grc Analyst information

See Reston, VA salary details

$38K

$101.6K

$237.7K

How much do remote grc analyst jobs pay per year?

As of Jun 27, 2026, the average yearly pay for remote grc analyst in Reston, VA is $101,601.00, according to ZipRecruiter salary data. Most workers in this role earn between $57,200.00 and $115,500.00 per year, depending on experience, location, and employer.

What are some typical challenges faced by a Remote GRC Analyst, and how are they addressed?

A common challenge for Remote GRC Analysts is maintaining efficient communication and collaboration with cross-functional teams while working offsite. To address this, organizations generally provide access to collaboration tools like Slack, Microsoft Teams, and secure document management systems, enabling seamless coordination. Additionally, you may need to proactively manage your workflow and stay updated on changes in regulations and company policies, often requiring strong time management and self-motivation. Success in this role often comes from building solid virtual relationships and actively participating in remote meetings, ensuring you remain an integral part of the compliance and risk management processes.

What are the key skills and qualifications needed to thrive in the Remote Grc Analyst position, and why are they important?

To thrive as a Remote GRC Analyst, you need strong analytical abilities, a solid understanding of risk management and compliance frameworks (such as ISO 27001, NIST, or SOX), and a relevant degree in information security, business, or a related field. Familiarity with GRC platforms (like RSA Archer or ServiceNow), along with certifications such as CISA, CISM, or CRISC, is highly valued. Excellent communication, organization, and problem-solving skills are essential for effectively managing compliance documentation and collaborating remotely across teams. These attributes ensure you can proactively identify risks, implement controls, and support ongoing governance requirements in a dynamic, decentralized work environment.

What is a Remote GRC Analyst job?

A Remote GRC (Governance, Risk, and Compliance) Analyst is responsible for assessing and managing an organization's compliance with industry regulations, internal policies, and risk management frameworks—all while working remotely. They conduct risk assessments, monitor security controls, prepare audit documentation, and ensure regulatory compliance across various business functions. This role often involves collaborating with teams across different locations to implement best practices for security and compliance. Strong analytical skills, knowledge of industry standards (such as ISO 27001, NIST, or SOX), and familiarity with compliance tools are essential for success in this position.

What are the most commonly searched types of Grc Analyst jobs in Reston, VA? The most popular types of Grc Analyst jobs in Reston, VA are:
What are popular job titles related to Remote Grc Analyst jobs in Reston, VA? For Remote Grc Analyst jobs in Reston, VA, the most frequently searched job titles are:
What job categories do people searching Remote Grc Analyst jobs in Reston, VA look for? The top searched job categories for Remote Grc Analyst jobs in Reston, VA are:
What cities near Reston, VA are hiring for Remote Grc Analyst jobs? Cities near Reston, VA with the most Remote Grc Analyst job openings:
Sr. Analyst - SCRM

Sr. Analyst - SCRM

Maximus

VA • On-site, Remote

$88K - $116K/yr

Full-time

Medical, Life, Retirement, PTO

Posted 15 hours ago


Maximus rating

6.9

Company rating: 6.9 out of 10

Based on 291 frontline employees who took The Breakroom Quiz

236th of 430 rated business services


Job description

General information
Job Posting Title
Sr. Analyst - SCRM
Date
Thursday, May 28, 2026
City
Remote
Country
United States
Working time
Full-time
Description & Requirements
The Sr. Analyst - Supply Chain Risk Management (SCRM) Analyst supports enterprise and program stakeholders in ensuring Maximus, Maximus Federal, and third-party relationships meet U.S. federal and DoD contractual and regulatory obligations. This role helps translate requirements into actionable SCRM governance, due diligence, and monitoring activities aligned to applicable FAR/DFARS clauses (including Section 889 considerations), customer security requirements (e.g., NIST-based controls and RMF/ATO expectations where applicable), and other federal directives affecting supplier and technology risk. The position partners with procurement, legal, security, IT, and business teams to conduct supplier risk assessments, maintain risk registers and supporting evidence, track remediation and exceptions, and produce compliance-ready reporting that enables informed leadership decisions and supports audits, assessments, and ongoing federal/DoD growth.
Essential Duties and Responsibilities:
- Perform complex risk analyses and risk assessment.
- Establish and satisfy Information Assurance (IA) and security requirements based upon the analysis of user, policy, regulatory, and resource demands.
- Support customers in the development and implementation of doctrine and policies.
- Advise information system owners on client/project security policies and requirements for systems.
- Keep abreast of emerging security technologies and make appropriate recommendations regarding the enhancement of the security posture of systems and their implementation.
- Interpret and operationalize federal and DoD supply chain requirements by mapping applicable FAR/DFARS clauses (including Section 889 considerations) and customer SCRM expectations into enterprise policies, procedures, and control guidance for shared services and third-party providers.
- Conduct and document supplier/third-party SCRM due diligence (pre-award and periodic) for federal and DoD pursuits and programs, including risk questionnaires, evidence reviews, and validation of flow-downs to subcontractors and cloud/service providers.
- Assess, track, and report SCRM control effectiveness using NIST guidance (e.g., NIST SP 800-161 concepts and NIST SP 800-53 control families as applicable), maintaining risk registers, corrective action plans, POA&Ms, and supporting evidence to enable audit- and assessment-ready compliance.
- Support contract lifecycle governance by advising procurement and program teams on SCRM-related contract language, required representations, and evidence packages; manage exceptions/waivers and coordinate legal/security reviews to ensure consistent FAR/DFARS compliance decisions.
- Perform ongoing SCRM monitoring for high-risk suppliers (e.g., performance, financial, cybersecurity, and geopolitical indicators), coordinate issue escalation and remediation with internal stakeholders and vendors, and deliver recurring leadership reporting for federal/DoD readiness and program assurance.
Minimum Requirements
- Please refer to the additional information section of the job requisition for this opening to determine clearance eligibility required.
- Bachelor's Degree in related field.
- 5-7 years of relevant professional experience required.
- Equivalent combination of education and experience considered in lieu of degree.
Education/Requirements
- Bachelor's degree in supply chain, business, information systems, cybersecurity, risk management, or a related field (or equivalent combination of education, training, and experience).
- 7+ years of experience in supply chain risk management, third-party/vendor risk management (TPRM), federal compliance, or related risk/governance functions within a regulated environment.
- U.S Citizen with ability to obtain a US government security clearance.
- Experience supporting federal and/or DoD contract compliance activities (e.g., proposal support, contract onboarding, evidence collection, internal/external audits, and customer assessments).
- Strong knowledge of federal acquisition and cybersecurity supply chain requirements, including applicable FAR/DFARS clauses, subcontractor flow-down concepts, and prohibited/covered telecommunications considerations (e.g., Section 889).
- Experience using GRC/TPRM tooling to manage supplier inventories, risk assessments, evidence collection, issues/remediation, and reporting (tool experience may include platforms such as Archer, ServiceNow GRC, Coupa Risk, or equivalents).
- Demonstrated experience performing supplier due diligence (pre-award and periodic), maintaining SCRM risk registers, and driving remediation and exception workflows with procurement, legal, IT/security, and business stakeholders.
- Working knowledge of NIST supply chain risk guidance (e.g., NIST SP 800-161 concepts) and ability to align SCRM practices to NIST SP 800-53 control expectations where required by customer contracts.
- Preferred: relevant certifications (e.g., CTPRP/CTPR, CISM, CRISC, CISSP, PMP) and/or eligibility to obtain a U.S. government security clearance, if required by program/customer needs.
- Applies risk-based analysis to complex supplier, technology, and sourcing scenarios; independently evaluates tradeoffs across compliance, operational impact, and mission needs.
- Proven ability to influence and coordinate across procurement, legal, security, IT, finance, and program teams to drive consistent SCRM governance and timely decisions.
- Experienced in building compliance-ready evidence packages and responding to federal/DoD customer questions, audits, and assessments related to third-party and supply chain risk.
- Skilled in developing SCRM metrics and executive reporting (risk trends, supplier segmentation, remediation aging, compliance status) to support leadership visibility and continuous improvement.
- Strong documentation discipline and attention to detail; able to track contractual requirements, subcontractor flow-downs, and exceptions through closure.
- Ability to translate FAR/DFARS and NIST-aligned requirements into practical supplier due diligence, contracting, and operational control expectations.
- Strong verbal and written communication skills, including drafting SCRM policies, procedures, assessment narratives, and leadership briefings.
- Demonstrated ability to support fast-paced capture/proposal and program delivery timelines with responsive, customer-focused risk guidance.
- Analytical skills to support supplier segmentation, risk scoring, and trend analysis using Excel and/or reporting tools.
- Proficient in Microsoft Office (Excel, Word, PowerPoint; Visio preferred) to develop procedures, process maps, risk analyses, and executive-ready briefings.
- Ability to manage multiple supplier assessments, remediation actions, and stakeholder requests simultaneously, prioritizing work based on risk and contractual deadlines.
- Understanding of insider threat, counterintelligence, and supply chain threat concepts, including recognizing/reporting indicators (e.g., suspicious vendor behavior, anomalous access requests, counterfeit/compromised components, foreign influence concerns) in coordination with security leadership.
- Knowledge of the 32 CFR Part 117 (National Industrial Security Program Operating Manual (NISPOM) Rule) and the Defense Counterintelligence and Security Agency (DCSA) oversight environment, including understanding of supplier/outsourcing considerations that may impact safeguarding of classified information.
#maxcorp #c0rejobs #CoreTech #HotJobs0623LI #HotJobs0623FB #HotJobs0623X #HotJobs0623TH #TrendingJobs
EEO Statement
Maximus is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, age, national origin, disability, veteran status, genetic information and other legally protected characteristics.
Pay Transparency
Maximus compensation is based on various factors including but not limited to job location, a candidate's education, training, experience, expected quality and quantity of work, required travel (if any), external market and internal value analysis including seniority and merit systems, as well as internal pay alignment. Annual salary is just one component of Maximus's total compensation package. Other rewards may include short- and long-term incentives as well as program-specific awards. Additionally, Maximus provides a variety of benefits to employees, including health insurance coverage, life and disability insurance, a retirement savings plan, paid holidays and paid time off. Compensation ranges may differ based on contract value but will be commensurate with job duties and relevant work experience. An applicant's salary history will not be used in determining compensation. Maximus will comply with regulatory minimum wage rates and exempt salary thresholds in all instances.
Accommodations
Maximus provides reasonable accommodations to individuals requiring assistance during any phase of the employment process due to a disability, medical condition, or physical or mental impairment. If you require assistance at any stage of the employment process-including accessing job postings, completing assessments, or participating in interviews,-please contact People Operations at applicantaccom@maximus.com.
Minimum Salary
$
90,780.00
Maximum Salary
$
122,820.00

What Maximus employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom