1

Security Risk Compliance Jobs in Virginia (NOW HIRING)

Be Seen First

CMMC Champion and Head of IT Security, Data Governance and IT Risk Audit and Controls Unique Newly ... IT Risk-Compliance and related audits; experience working as the corporate driver/catalyst for ...

The IT Risk Assessor is responsible for assisting with meeting security and compliance requirements per state and federal standards. The risk assessor will review information system security controls ...

Demonstrated professional consulting (internal or external) experience with enterprise IT-security, information security and Governance Risk Compliance services gained in previous delivery capacity.

The IT Risk Assessor is responsible for assisting with meeting security and compliance requirements per state and federal standards. The risk assessor will review information system security controls ...

Learn more about Delek at Position Responsibilities Information security risk management and compliance are critical parts of Deltek's business and product strategy. The Principal Governance, Risk ...

Risk Management Framework SME

Hampton, VA · On-site

$135K - $145K/yr

... compliance with DOD, NIST and agency-specific security policies * Develop, maintain, and validate ... Conduct vulnerability analysis, risk assessment and remediation planning * Guide continuous ...

next page

Showing results 1-20

Security Risk Compliance information

See Virginia salary details

$32.2K

$80.4K

$122.4K

How much do security risk compliance jobs pay per year?

As of Jun 12, 2026, the average yearly pay for security risk compliance in Virginia is $80,447.00, according to ZipRecruiter salary data. Most workers in this role earn between $60,000.00 and $99,100.00 per year, depending on experience, location, and employer.

What is the difference between Security Risk Compliance vs Security Analyst?

AspectSecurity Risk ComplianceSecurity Analyst
CertificationsISO 27001 Lead Implementer, CISSP, CISACISSP, CompTIA Security+, GIAC Security Certifications
Work EnvironmentPolicy development, compliance audits, risk assessmentsMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government sectors focusing on regulatory adherenceIT departments across various industries focusing on security operations

Security Risk Compliance professionals focus on ensuring organizations meet regulatory standards and manage security risks through policies and audits. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within similar environments, their core responsibilities differ: compliance versus active security monitoring.

What are some common challenges faced by Security Risk Compliance professionals when balancing regulatory requirements with business objectives?

Security Risk Compliance professionals often need to navigate the delicate balance between adhering to complex regulatory standards and supporting the organization's operational goals. A major challenge is ensuring compliance without hindering business innovation or efficiency. This involves working closely with various departments to interpret regulations, communicate risks, and implement pragmatic controls that satisfy both legal requirements and business needs. Effective collaboration and ongoing education are key to overcoming these challenges and maintaining a strong security posture.

What are the key skills and qualifications needed to thrive as a Security Risk Compliance professional, and why are they important?

To thrive as a Security Risk Compliance professional, you need a solid understanding of information security frameworks, risk assessment methodologies, and relevant regulations, often supported by a degree in cybersecurity or a related field. Familiarity with tools such as GRC (Governance, Risk, and Compliance) platforms, vulnerability scanners, and certifications like CISSP, CISA, or CRISC is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and collaborate with stakeholders. These skills are vital to ensure organizations meet compliance requirements, mitigate risks, and maintain trust with clients and regulators.

What is Security Risk Compliance?

Security Risk Compliance refers to the process of identifying, assessing, and managing risks to an organization's information systems while ensuring adherence to relevant laws, regulations, and industry standards. Professionals in this field develop policies, conduct risk assessments, and implement controls to protect sensitive data from threats. Their work helps organizations minimize security vulnerabilities and avoid legal or financial consequences related to non-compliance.
What job categories do people searching Security Risk Compliance jobs in Virginia look for? The top searched job categories for Security Risk Compliance jobs in Virginia are:
What cities in Virginia are hiring for Security Risk Compliance jobs? Cities in Virginia with the most Security Risk Compliance job openings:
Infographic showing various Security Risk Compliance job openings in Virginia as of June 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $80,447 per year, or $38.7 per hour.

SIPR Governance, Risk, and Compliance (GRC) & Security Specialist

Systems Planning and Analysis, Inc

Arlington, VA

Other

Retirement

Posted 9 days ago


Job description

SIPR Governance, Risk, and Compliance (GRC) & Security Analyst

Intrepid, an SPA Company, brings more than 20 years of experience supporting the Department of Defense and U.S. Government, consistently setting the standard for excellence in the federal marketplace. Committed to advancing the mission of the U.S. Warfighter, Intrepid leverages technological superiority to deliver innovative solutions across air, space, land, and sea domains. We are proud to foster a collaborative, dynamic work environment, offering competitive compensation and an industry-leading 401k contribution. Our team is built through merit and achievement, and we're always looking for the best and brightest to join us in our growth. We treat our people like family, we are mission-focused, and we give back! Join us today.

Our Financial Management & Business Analysis Portfolio supports the U.S. Army Financial Management Command (USAFMCOM), Systems Support Operations (SSO) Division. We provide effective functional systems support, user technical support, training support, and governance support of the Army's modernized and deployed FM domain ERP systems (GFEBS / GFEBS-SA / GCSS-A (Finance)), ensuring technological capabilities maturation and evolution aligns with Army and FM domain goals and objectives.

SPA has an immediate need for a SIPR Governance, Risk, and Compliance (GRC) & Security Analyst within the U.S. Army's General Fund Enterprise Business System – Sensitive Activities (GFEBS-SA). This role requires onsite work 5 days a week in customer's SIPR location.

Responsibilities

Managing GRC system and its related processes:

  • Manage the full lifecycle of GRC tickets to support user access provisioning.
  • Conduct Segregation of Duties (SOD) Analysis simulations to identify and mitigate potential conflicts before assigning roles. This includes creating mock requests to troubleshoot user-reported issues.
  • Deliver User Support & GRC training to groups of end-users, such as Supervisors and Role Approvers.
  • Guide users in completing 4th Tier Hierarchy worksheets to facilitate security role updates, Developing job aids and process documentation.

Working on SAP ECC/BI Security concepts and administration:

  • Execute SAP Transactions.
  • Conducting SAP Role Design & Objects.
  • Gathering functional requirements from business users and translating them into clear, actionable specifications for the SAP Security team.

Navigating Audit & Compliance:

  • Participating in multiple cycles of internal and external audits.
  • Facilitating SOC-1 and SOC-2 audits.
  • Conducting Control Examination related to security, availability, processing integrity, and privacy.

Responsible for User Access Reviews & Systems:

  • Conducting Critical Access Monitoring (CAM) and engaging directly with end-users.
  • Executing User Reaffirmation cycles, guiding users on removing unnecessary roles and resolving identified SOD conflicts.
  • Managing and resolving incidents in ServiceNow.

As a part of FSO duties, conducting Physical Security in SCIF:

  • Either opening SIPR office space at 0700EST daily or close SIPR 1700EST M-F.
  • Creating Visitor Access Requests (VARS) and verifying background clearances.
  • Maintaining sign-in and sign-out roster for visitors; Monitor and assist during on-site classified meetings.
Qualifications

Required Qualifications:

  • Active TS clearance
  • 10+ years of position related experience in GRC systems, SAP ECC/BI Security, Audit & Compliance, Critical Access Monitoring.
  • MA/MS degree

The candidate must demonstrate mastery of the GRC system and its related processes:

  • Ticket & Workflow Management: Experience managing the full lifecycle of GRC tickets to support user access provisioning. Must be able to articulate the purpose of each stage in the GRC workflow.
  • Segregation of Duties (SOD) Analysis: Experience conducting SOD simulations to identify and mitigate potential conflicts before assigning roles.
  • User Support & Training: Experience delivering GRC training to groups of end-users.
  • Process Documentation: Experience guide users in completing 4th Tier Hierarchy worksheets to facilitate security role updates. Ability to develop job aids and process documentation (e.g., how to request a FireFighter ID).
  • Issue Resolution: Understand the utilization of GRC "escape paths" to resolve complex access issues.

The candidate must have a strong technical foundation in SAP ECC/BI Security concepts and administration.

  • SAP Transactions: Proficiency in executing and understanding the purpose of key SAP transactions, including: SE16n, SU01D, SUIM, SU53, WE02, FMZ3, and SM37.
  • Role Design & Objects: Experience & knowledge of SAP role design (single vs. composite) and a thorough understanding of core authorization objects (e.g., S_TABU_DIS, S_PROGRAM,  S_USR_* tables).
  • Requirements Translation: Proven ability to gather functional requirements from business users and translate them into clear, actionable specifications for the SAP Security team.

The candidate must be experienced in Audit & Compliance, navigating the demands of both internal and external audits.

  • Audit Participation: Direct experience participating in multiple cycles of internal and external audits, including responding to Provided by Client (PBC) requests.
  • SOC Audits: Direct experience facilitating SOC-1 and SOC-2 audits in a federal environment. Must be able to articulate their specific role, contributions, and challenges faced.
  • Auditor Communication: Adept at discussing Segregation of Duties (SOD) controls and policies with internal and external auditors.
  • Control Examination: Ability to examine controls related to security, availability, processing integrity, and privacy, and provide concrete examples of evidence supplied for audit reviews such as responding to NFRs (notice of findings and recommendations), describing significance of a POAM (plan of action & milestones), and responding to PBCs (provided by client).

Must be experienced in User Access Reviews & System Proficiency, in cyclical user access reviews and must be proficient in using a help desk system.

  • Critical Access Monitoring (CAM): Experience with the CAM process, including its purpose, risks, and benefits, as well as engaging directly with end-users.
  • User Reaffirmation: Proven ability to execute User Reaffirmation cycles, guiding users on removing unnecessary roles and resolving identified SOD conflicts.
  • ServiceNow: Proficiency in using ServiceNow as a help desk ticketing system to manage and resolve incidents.

Experience in Physical Security is a plus:

  • Role requires availability to either open SIPR office space at 0700EST daily or close SIPR 1700EST M-F.
  • Experience using DISS: creating Visitor Access Requests (VARS) and verifying background clearances.