2

Remote Grc Jobs in Silver Spring, MD (NOW HIRING)

Senior Information Security Engineer

Reston, VA · Remote

$110K - $150K/yr

Remote Key Responsibilities * Serve as the primary cybersecurity and privacy advisor to System ... GRC) tools. * Strong knowledge of NIST SP 800-37, NIST SP 800-53, FISMA, FIPS 199, and federal ...

Cybersecurity Program Manager

Reston, VA · Remote

$115K - $156K/yr

Remote Key Responsibilities * Serve as the primary cybersecurity and privacy advisor to System ... GRC) tools. * Strong knowledge of NIST SP 800-37, NIST SP 800-53, FISMA, FIPS 199, and federal ...

Cybersecurity Program Manager

Reston, VA · Remote

$115K - $156K/yr

Remote Key Responsibilities * Serve as the primary cybersecurity and privacy advisor to System ... GRC) tools. * Strong knowledge of NIST SP 800-37, NIST SP 800-53, FISMA, FIPS 199, and federal ...

Senior Information Security Engineer

Reston, VA · Remote

$110K - $150K/yr

Remote Key Responsibilities * Serve as the primary cybersecurity and privacy advisor to System ... GRC) tools. * Strong knowledge of NIST SP 800-37, NIST SP 800-53, FISMA, FIPS 199, and federal ...

Contract Compensation: $44/HR Work Model: 100% Remote Role Overview We're seeking a detail-driven ... Experience with GRC tools or AI governance platforms * Background supporting audits or regulatory ...

Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation ... Experience with eMASS or similar GRC platforms * Familiarity with FedRAMP , cloud security concepts ...

Contract Compensation: $44/HR Work Model: 100% Remote Role Overview We're seeking a detail-driven ... Experience with GRC tools or AI governance platforms * Background supporting audits or regulatory ...

Contract Compensation: $44/HR Work Model: 100% Remote Role Overview We're seeking a detail-driven ... Experience with GRC tools or AI governance platforms * Background supporting audits or regulatory ...

Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation ... Experience with eMASS or similar GRC platforms * Familiarity with FedRAMP , cloud security concepts ...

Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation ... Experience with eMASS or similar GRC platforms * Familiarity with FedRAMP , cloud security concepts ...

Contract Compensation: $44/HR Work Model: 100% Remote Role Overview We're seeking a detail-driven ... Experience with GRC tools or AI governance platforms * Background supporting audits or regulatory ...

Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation ... Experience with eMASS or similar GRC platforms * Familiarity with FedRAMP , cloud security concepts ...

Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation ... Experience with eMASS or similar GRC platforms * Familiarity with FedRAMP , cloud security concepts ...

Showing results 41-60

Remote Grc information

See Silver Spring, MD salary details

$20

$26

$34

How much do remote grc jobs pay per hour?

As of Sep 5, 2026, the average hourly pay for remote grc in Silver Spring, MD is $26.02, according to ZipRecruiter salary data. Most workers in this role earn between $23.61 and $26.11 per hour, depending on experience, location, and employer.

What is a Remote GRC?

A Remote GRC (Governance, Risk, and Compliance) job involves managing an organization's regulatory compliance, risk assessment, and policy enforcement from a remote location. Professionals in this role ensure that the company adheres to industry standards, identifies potential risks, and implements security controls. Responsibilities may include conducting audits, developing compliance programs, and advising on best practices. Remote GRC roles are common in industries such as finance, healthcare, and technology, where data security and regulatory adherence are critical. Strong analytical skills, knowledge of compliance frameworks (such as ISO 27001, NIST, or SOC 2), and experience with risk management tools are typically required.

What does a Remote GRC do?

A Remote GRC professional is responsible for developing and maintaining risk management policies, conducting audits, and ensuring regulatory compliance across the organization. They may also evaluate internal controls, coordinate with IT and legal teams, and facilitate responses to compliance assessments or incidents. Regular tasks often include preparing detailed reports, monitoring changes in regulations, and providing training or guidance to staff. Collaboration is done via virtual meetings and digital tools, making strong communication skills essential for effective teamwork in a remote environment.

What are the key skills and qualifications needed to thrive in the Remote GRC position, and why are they important?

To thrive as a Remote GRC professional, you need strong knowledge of governance, risk, and compliance frameworks (such as ISO 27001, NIST, or SOX) plus experience in risk assessments and policy development. Familiarity with GRC platforms (like RSA Archer, ServiceNow, or LogicGate) and certification such as CISA, CISM, or CRISC is often required. Excellent communication, self-motivation, and time-management skills help remote GRC specialists succeed in a distributed environment. These abilities are critical for maintaining security posture, ensuring regulatory compliance, and effectively supporting business goals from a remote setting.

Can a remote GRC analyst work remotely?

Yes, a remote GRC (Governance, Risk, and Compliance) analyst can work remotely, as many organizations offer remote positions in this field. These roles typically require strong knowledge of compliance frameworks, risk management tools, and communication skills, and often involve using collaboration software and security protocols to perform duties effectively from a remote location.

Is remote GRC still in demand?

Remote GRC (Governance, Risk, and Compliance) roles remain in demand as organizations prioritize cybersecurity, regulatory compliance, and risk management. These positions often require knowledge of frameworks like ISO, NIST, or GDPR, and can be performed effectively with skills in policy development, audits, and compliance tools. The shift to remote work has increased opportunities for GRC professionals across various industries.

What are the most commonly searched types of Grc jobs in Silver Spring, MD?

The most popular types of Grc jobs in Silver Spring, MD are:

What cities near Silver Spring, MD are hiring for Remote Grc jobs?

Cities near Silver Spring, MD with the most Remote Grc job openings:

Infographic showing various Remote Grc job openings in Silver Spring, MD as of August 2026, with employment types broken down into 92% Full Time, 3% Part Time, and 5% Contract. Highlights an 77% Physical, 8% Hybrid, and 15% Remote job distribution, with an average salary of $54,129 per year, or $26 per hour.

Senior Information Security Engineer

asrcfh

Reston, VA • Remote

$110K - $150K/yr

Full-time

Posted 12 days ago


ASRC Federal rating

7.8

Company rating: 7.8 out of 10

Based on 28 frontline employees who took The Breakroom Quiz

243rd of 453 rated engineering


Job description

ASRC Federal Data Networx is seeking a Senior Information System Security Officer (ISSO) to support federal cybersecurity and Risk Management Framework (RMF) activities for enterprise information systems. The ISSO serves as the primary cybersecurity and privacy advisor to System Owners (SOs), ensuring security and privacy requirements are integrated throughout the system lifecycle while maintaining compliance with federal regulations and Authorization to Operate (ATO) requirements.

Work Location: Remote

Key Responsibilities

  • Serve as the primary cybersecurity and privacy advisor to System Owners for assigned systems.
  • Lead RMF activities, including development and maintenance of System Security and Privacy Plans (SSPPs), authorization packages, risk documentation, and supporting artifacts.
  • Ensure systems maintain Authorization to Operate (ATO) through assessment support, continuous monitoring, and compliance with NIST RMF, FISMA, and federal security requirements.
  • Assess security risks, validate security controls, and coordinate remediation of vulnerabilities and Plans of Action and Milestones (POA&Ms).
  • Maintain system inventories, security documentation, contingency plans, configuration management plans, and privacy documentation.
  • Collaborate with ISSMs, System Owners, Security Control Assessors, and technical teams to integrate security throughout the system lifecycle.
  • Monitor system security posture, review vulnerability and compliance scan results, and support continuous authorization initiatives.
  • Provide cybersecurity guidance, develop security policies and procedures, and deliver security awareness training.
  • Support security engineering, certification and accreditation activities, and implementation of security controls across systems.
  • Recommend process improvements and automation opportunities to enhance RMF and cybersecurity operations.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, or a related field.
  • Minimum 5–7 years of experience supporting information assurance, cybersecurity, RMF, or information system security, or an equivalent combination of education and experience.
  • Experience supporting federal cybersecurity programs and the NIST Risk Management Framework (RMF).
  • Experience developing and maintaining RMF documentation, authorization packages, and Governance, Risk, and Compliance (GRC) tools.
  • Strong knowledge of NIST SP 800-37, NIST SP 800-53, FISMA, FIPS 199, and federal privacy requirements.
  • Experience supporting Authorization to Operate (ATO), Continuous ATO (cATO), or Continuous Authorization efforts.
  • Strong analytical, communication, documentation, and stakeholder engagement skills.

Required Certifications

  • Certified Information Systems Security Professional (CISSP)
  • Certified in Governance, Risk and Compliance (CGRC) or Certified Cloud Security Professional (CCSP)

Preferred Qualifications

  • Experience supporting U.S. federal civilian agencies, preferably the USPTO.
  • Experience with continuous monitoring, vulnerability management, and security automation.
  • Familiarity with cloud security, DevSecOps, and continuous authorization initiatives.
  • Knowledge of privacy compliance activities, including Privacy Threshold Assessments (PTAs), Privacy Impact Assessments (PIAs), and System of Records Notices (SORNs).

What ASRC Federal employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom