SIPR Governance, Risk, and Compliance (GRC) & Security Analyst Intrepid, an SPA Company, brings more than 20 years of experience supporting the Department of Defense and U.S. Government, consistently ...
SIPR Governance, Risk, and Compliance (GRC) & Security Analyst Intrepid, an SPA Company, brings more than 20 years of experience supporting the Department of Defense and U.S. Government, consistently ...
The Risk and Resilience Manager is responsible for assessing, mitigating, and managing operational ... compliance with federal security and resiliency standards. The ideal candidate brings deep ...
The Risk and Resilience Manager is responsible for assessing, mitigating, and managing operational ... compliance with federal security and resiliency standards. The ideal candidate brings deep ...
Senior Manager, Vendor Risk & Procurement Governance - Mobility
Centreville, VA · On-site
$94K - $127K/yr
This role serves as the operational bridge between Procurement, Legal, Risk & Compliance, and Information Security. Responsibility and Impact : Vendor Risk Process Operationalization * Translate the ...
Senior Manager, Vendor Risk & Procurement Governance - Mobility
Centreville, VA · On-site
$94K - $127K/yr
This role serves as the operational bridge between Procurement, Legal, Risk & Compliance, and Information Security. Responsibility and Impact : Vendor Risk Process Operationalization * Translate the ...
CMMC Champion and Head of IT Security and GRC, Unique Virginia HW-SW C
Reston, VA · On-site
$200K - $275K/yr
CMMC Champion and Head of IT Security, Data Governance and IT Risk Audit and Controls Unique Newly ... IT Risk-Compliance and related audits; experience working as the corporate driver/catalyst for ...
Quick apply
CMMC Champion and Head of IT Security and GRC, Unique Virginia HW-SW C
Reston, VA · On-site
$200K - $275K/yr
CMMC Champion and Head of IT Security, Data Governance and IT Risk Audit and Controls Unique Newly ... IT Risk-Compliance and related audits; experience working as the corporate driver/catalyst for ...
SPA has an immediate need for SIPR Governance, Risk, and Compliance (GRC) & Security Analyst within the U.S. Army's General Fund Enterprise Business System - Sensitive Activities (GFEBS-SA). This ...
SPA has an immediate need for SIPR Governance, Risk, and Compliance (GRC) & Security Analyst within the U.S. Army's General Fund Enterprise Business System - Sensitive Activities (GFEBS-SA). This ...
Oracle ERP Fusion Risk and Compliance Systems Analyst
Vienna, VA · On-site
$48 - $60/hr
This position is a Finance Technology Security & Controls Analyst/Business Systems Analyst role focused on Oracle ERP Fusion security, risk monitoring, and compliance operations within a Finance ...
Quick apply
Oracle ERP Fusion Risk and Compliance Systems Analyst
Vienna, VA · On-site
$48 - $60/hr
This position is a Finance Technology Security & Controls Analyst/Business Systems Analyst role focused on Oracle ERP Fusion security, risk monitoring, and compliance operations within a Finance ...
The IT Risk Assessor is responsible for assisting with meeting security and compliance requirements per state and federal standards. The risk assessor will review information system security controls ...
The IT Risk Assessor is responsible for assisting with meeting security and compliance requirements per state and federal standards. The risk assessor will review information system security controls ...
SIPR Governance, Risk, and Compliance (GRC) & Security Specialis with Security Clearance
Arlington, VA · On-site
SPA has an immediate need for SIPR Governance, Risk, and Compliance (GRC) & Security Analyst within the U.S. Army's General Fund Enterprise Business System - Sensitive Activities (GFEBS-SA). This ...
SIPR Governance, Risk, and Compliance (GRC) & Security Specialis with Security Clearance
Arlington, VA · On-site
SPA has an immediate need for SIPR Governance, Risk, and Compliance (GRC) & Security Analyst within the U.S. Army's General Fund Enterprise Business System - Sensitive Activities (GFEBS-SA). This ...
Demonstrated professional consulting (internal or external) experience with enterprise IT-security, information security and Governance Risk Compliance services gained in previous delivery capacity.
Demonstrated professional consulting (internal or external) experience with enterprise IT-security, information security and Governance Risk Compliance services gained in previous delivery capacity.
Risk Assessor
Richmond, VA · On-site
The IT Risk Assessor is responsible for assisting with meeting security and compliance requirements per state and federal standards. The risk assessor will review information system security controls ...
Risk Assessor
Richmond, VA · On-site
The IT Risk Assessor is responsible for assisting with meeting security and compliance requirements per state and federal standards. The risk assessor will review information system security controls ...
Share this job: Share: Share Security Specialist, Risk and Compliance Services (Chantilly) with Facebook Share Security Specialist, Risk and Compliance Services (Chantilly) with LinkedIn Share ...
Share this job: Share: Share Security Specialist, Risk and Compliance Services (Chantilly) with Facebook Share Security Specialist, Risk and Compliance Services (Chantilly) with LinkedIn Share ...
Demonstrated professional consulting (internal or external) experience with enterprise IT-security, information security, and Governance Risk Compliance services gained in a previous delivery ...
Demonstrated professional consulting (internal or external) experience with enterprise IT-security, information security, and Governance Risk Compliance services gained in a previous delivery ...
The NSG Governance, Risk, Compliance (GRC) Team enables business agility while maintaining a strong security posture via intelligent risk-taking, optimized controls management, and iterative security ...
The NSG Governance, Risk, Compliance (GRC) Team enables business agility while maintaining a strong security posture via intelligent risk-taking, optimized controls management, and iterative security ...
Provide ISSM-level oversight and guidance to ensure compliance with DOD, NIST and agency-specific ... risk acceptance recommendations. Provide training, mentoring and support to security analysts and ...
Provide ISSM-level oversight and guidance to ensure compliance with DOD, NIST and agency-specific ... risk acceptance recommendations. Provide training, mentoring and support to security analysts and ...
... SCI security clearance to support TGS and our government customer at Fort Belvoir, VA. This ... Advise system owners, engineers, and leadership on risk posture, compliance requirements, and ...
... SCI security clearance to support TGS and our government customer at Fort Belvoir, VA. This ... Advise system owners, engineers, and leadership on risk posture, compliance requirements, and ...
Additionally, RTA works to identify, analyze, and mitigate security risk identified through various compliance activities, pentesting, and other sources. We are seeking an experienced, self-motivated ...
Additionally, RTA works to identify, analyze, and mitigate security risk identified through various compliance activities, pentesting, and other sources. We are seeking an experienced, self-motivated ...
Additionally, RTA works to identify, analyze, and mitigate security risk identified through various compliance activities, pentesting, and other sources. We are seeking an experienced, self-motivated ...
Additionally, RTA works to identify, analyze, and mitigate security risk identified through various compliance activities, pentesting, and other sources. We are seeking an experienced, self-motivated ...
Pncpl GRC Analyst
Herndon, VA · Remote
Learn more about Delek at Position Responsibilities Information security risk management and compliance are critical parts of Deltek's business and product strategy. The Principal Governance, Risk ...
Pncpl GRC Analyst
Herndon, VA · Remote
Learn more about Delek at Position Responsibilities Information security risk management and compliance are critical parts of Deltek's business and product strategy. The Principal Governance, Risk ...
Risk Management Framework SME
Hampton, VA · On-site
$135K - $145K/yr
... compliance with DOD, NIST and agency-specific security policies * Develop, maintain, and validate ... Conduct vulnerability analysis, risk assessment and remediation planning * Guide continuous ...
Risk Management Framework SME
Hampton, VA · On-site
$135K - $145K/yr
... compliance with DOD, NIST and agency-specific security policies * Develop, maintain, and validate ... Conduct vulnerability analysis, risk assessment and remediation planning * Guide continuous ...
Review complex sponsor and industrial partners system designs for security risk and compliance with sponsor policy and regulations; propose resolution and preventive strategies. * Communicate complex ...
Review complex sponsor and industrial partners system designs for security risk and compliance with sponsor policy and regulations; propose resolution and preventive strategies. * Communicate complex ...
Security Risk Compliance information
See Virginia salary details
$32.2K - $40.4K
6% of jobs
$40.4K - $48.6K
0% of jobs
$48.6K - $56.8K
6% of jobs
$62.7K is the 25th percentile. Wages below this are outliers.
$56.8K - $65K
17% of jobs
The median wage is $72.8K / yr.
$65K - $73.2K
21% of jobs
$73.2K - $81.4K
7% of jobs
$81.4K - $89.6K
9% of jobs
$89.6K - $97.8K
7% of jobs
$98.2K is the 75th percentile. Wages above this are outliers.
$97.8K - $106K
12% of jobs
$106K - $114.2K
6% of jobs
$114.2K - $122.4K
7% of jobs
$32.2K
$80.4K
$122.4K
How much do security risk compliance jobs pay per year?
What is the difference between Security Risk Compliance vs Security Analyst?
| Aspect | Security Risk Compliance | Security Analyst |
|---|---|---|
| Certifications | ISO 27001 Lead Implementer, CISSP, CISA | CISSP, CompTIA Security+, GIAC Security Certifications |
| Work Environment | Policy development, compliance audits, risk assessments | Monitoring security systems, incident response, vulnerability analysis |
| Employer & Industry Usage | Financial, healthcare, government sectors focusing on regulatory adherence | IT departments across various industries focusing on security operations |
Security Risk Compliance professionals focus on ensuring organizations meet regulatory standards and manage security risks through policies and audits. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within similar environments, their core responsibilities differ: compliance versus active security monitoring.
What are some common challenges faced by Security Risk Compliance professionals when balancing regulatory requirements with business objectives?
What are the key skills and qualifications needed to thrive as a Security Risk Compliance professional, and why are they important?
What is Security Risk Compliance?

SIPR Governance, Risk, and Compliance (GRC) & Security Specialist
Systems Planning and Analysis, IncArlington, VA
Other
Retirement
Posted 9 days ago
Job description
Intrepid, an SPA Company, brings more than 20 years of experience supporting the Department of Defense and U.S. Government, consistently setting the standard for excellence in the federal marketplace. Committed to advancing the mission of the U.S. Warfighter, Intrepid leverages technological superiority to deliver innovative solutions across air, space, land, and sea domains. We are proud to foster a collaborative, dynamic work environment, offering competitive compensation and an industry-leading 401k contribution. Our team is built through merit and achievement, and we're always looking for the best and brightest to join us in our growth. We treat our people like family, we are mission-focused, and we give back! Join us today.
Our Financial Management & Business Analysis Portfolio supports the U.S. Army Financial Management Command (USAFMCOM), Systems Support Operations (SSO) Division. We provide effective functional systems support, user technical support, training support, and governance support of the Army's modernized and deployed FM domain ERP systems (GFEBS / GFEBS-SA / GCSS-A (Finance)), ensuring technological capabilities maturation and evolution aligns with Army and FM domain goals and objectives.
SPA has an immediate need for a SIPR Governance, Risk, and Compliance (GRC) & Security Analyst within the U.S. Army's General Fund Enterprise Business System – Sensitive Activities (GFEBS-SA). This role requires onsite work 5 days a week in customer's SIPR location.
ResponsibilitiesManaging GRC system and its related processes:
- Manage the full lifecycle of GRC tickets to support user access provisioning.
- Conduct Segregation of Duties (SOD) Analysis simulations to identify and mitigate potential conflicts before assigning roles. This includes creating mock requests to troubleshoot user-reported issues.
- Deliver User Support & GRC training to groups of end-users, such as Supervisors and Role Approvers.
- Guide users in completing 4th Tier Hierarchy worksheets to facilitate security role updates, Developing job aids and process documentation.
Working on SAP ECC/BI Security concepts and administration:
- Execute SAP Transactions.
- Conducting SAP Role Design & Objects.
- Gathering functional requirements from business users and translating them into clear, actionable specifications for the SAP Security team.
Navigating Audit & Compliance:
- Participating in multiple cycles of internal and external audits.
- Facilitating SOC-1 and SOC-2 audits.
- Conducting Control Examination related to security, availability, processing integrity, and privacy.
Responsible for User Access Reviews & Systems:
- Conducting Critical Access Monitoring (CAM) and engaging directly with end-users.
- Executing User Reaffirmation cycles, guiding users on removing unnecessary roles and resolving identified SOD conflicts.
- Managing and resolving incidents in ServiceNow.
As a part of FSO duties, conducting Physical Security in SCIF:
- Either opening SIPR office space at 0700EST daily or close SIPR 1700EST M-F.
- Creating Visitor Access Requests (VARS) and verifying background clearances.
- Maintaining sign-in and sign-out roster for visitors; Monitor and assist during on-site classified meetings.
Required Qualifications:
- Active TS clearance
- 10+ years of position related experience in GRC systems, SAP ECC/BI Security, Audit & Compliance, Critical Access Monitoring.
- MA/MS degree
The candidate must demonstrate mastery of the GRC system and its related processes:
- Ticket & Workflow Management: Experience managing the full lifecycle of GRC tickets to support user access provisioning. Must be able to articulate the purpose of each stage in the GRC workflow.
- Segregation of Duties (SOD) Analysis: Experience conducting SOD simulations to identify and mitigate potential conflicts before assigning roles.
- User Support & Training: Experience delivering GRC training to groups of end-users.
- Process Documentation: Experience guide users in completing 4th Tier Hierarchy worksheets to facilitate security role updates. Ability to develop job aids and process documentation (e.g., how to request a FireFighter ID).
- Issue Resolution: Understand the utilization of GRC "escape paths" to resolve complex access issues.
The candidate must have a strong technical foundation in SAP ECC/BI Security concepts and administration.
- SAP Transactions: Proficiency in executing and understanding the purpose of key SAP transactions, including: SE16n, SU01D, SUIM, SU53, WE02, FMZ3, and SM37.
- Role Design & Objects: Experience & knowledge of SAP role design (single vs. composite) and a thorough understanding of core authorization objects (e.g., S_TABU_DIS, S_PROGRAM,  S_USR_* tables).
- Requirements Translation: Proven ability to gather functional requirements from business users and translate them into clear, actionable specifications for the SAP Security team.
The candidate must be experienced in Audit & Compliance, navigating the demands of both internal and external audits.
- Audit Participation: Direct experience participating in multiple cycles of internal and external audits, including responding to Provided by Client (PBC) requests.
- SOC Audits: Direct experience facilitating SOC-1 and SOC-2 audits in a federal environment. Must be able to articulate their specific role, contributions, and challenges faced.
- Auditor Communication: Adept at discussing Segregation of Duties (SOD) controls and policies with internal and external auditors.
- Control Examination: Ability to examine controls related to security, availability, processing integrity, and privacy, and provide concrete examples of evidence supplied for audit reviews such as responding to NFRs (notice of findings and recommendations), describing significance of a POAM (plan of action & milestones), and responding to PBCs (provided by client).
Must be experienced in User Access Reviews & System Proficiency, in cyclical user access reviews and must be proficient in using a help desk system.
- Critical Access Monitoring (CAM): Experience with the CAM process, including its purpose, risks, and benefits, as well as engaging directly with end-users.
- User Reaffirmation: Proven ability to execute User Reaffirmation cycles, guiding users on removing unnecessary roles and resolving identified SOD conflicts.
- ServiceNow: Proficiency in using ServiceNow as a help desk ticketing system to manage and resolve incidents.
Experience in Physical Security is a plus:
- Role requires availability to either open SIPR office space at 0700EST daily or close SIPR 1700EST M-F.
- Experience using DISS: creating Visitor Access Requests (VARS) and verifying background clearances.
About Systems Planning & Analysis
Sourced by ZipRecruiter
Industry
Guided missile and space vehicle manufacturing
Company size
1,001 - 5,000 Employees
Headquarters location
Alexandria, VA, US
Year founded
1972