1

Senior Grc Analyst Jobs in Reston, VA (NOW HIRING)

GRC Lead

Fairfax, VA · On-site

$95 - $120/hr

You lead a GRC Analyst and report to the CTO & EVP. This is a working leadership role: you set the program, and you also do the senior, judgment-heavy work yourself. Salary Range: $95,000-$120,000 ...

New

Senior Business Analyst

Washington, DC · On-site

$130K - $147K/yr

... GRC) application, and that are governed by federal laws and Department of State policies and ... analyses, and strategic recommendations to senior leadership and key stakeholders. * Act as a ...

The GRC Engineer III serves as the enterprise architect and senior technical leader for governance ... Experience with RMF automation, FAIR analysis, or continuous monitoring. Familiarity with AI ...

Security GRC Senior Analyst

Mclean, VA

$97K - $126K/yr

In this role, you're expected to own the area of responsibility with minimal guidance from senior ... Excellent analytical and process development skills * Detail oriented with an eye for quality

Security GRC Senior Analyst

Herndon, VA · On-site

$98K - $129K/yr

In this role, you're expected to own the area of responsibility with minimal guidance from senior ... Excellent analytical and process development skills * Detail oriented with an eye for quality

Security GRC Senior Analyst

Washington, DC · On-site

$108K - $142K/yr

In this role, you're expected to own the area of responsibility with minimal guidance from senior ... Excellent analytical and process development skills * Detail oriented with an eye for quality

Oversee program delivery across multiple workstreams (e.g., GRC, Zero Trust, CIO FISMA Metrics ... Proficiency with reporting tools, data analytics, and performance metric tracking. * Strong ...

New

next page

Showing results 1-20

Senior Grc Analyst information

See Reston, VA salary details

$55.8K

$114.5K

$148.5K

How much do senior grc analyst jobs pay per year?

As of Sep 3, 2026, the average yearly pay for senior grc analyst in Reston, VA is $114,490.00, according to ZipRecruiter salary data. Most workers in this role earn between $94,300.00 and $142,800.00 per year, depending on experience, location, and employer.

What is a senior GRC analyst?

Senior GRC Analysts are experienced professionals who oversee an organization's Governance, Risk, and Compliance (GRC) programs. They are responsible for identifying and managing risks, ensuring compliance with laws and regulations, and developing policies and controls to protect the organization. Senior GRC Analysts often lead risk assessments, design compliance frameworks, and collaborate with different departments to implement best practices. Their expertise helps organizations navigate complex regulatory environments and maintain a strong security posture.

What are the key skills and qualifications needed to thrive as a senior GRC analyst?

To thrive as a Senior GRC Analyst, you need expertise in risk management, compliance frameworks (such as SOX, GDPR, or ISO 27001), and a solid understanding of business processes, usually supported by a relevant degree or certification (e.g., CISA, CRISC). Familiarity with GRC platforms like RSA Archer or ServiceNow, as well as audit and risk assessment tools, is typically required. Strong analytical thinking, communication, and stakeholder management skills help you influence decision-making and foster organizational buy-in. These skills and qualities are crucial for effectively identifying risks, ensuring regulatory compliance, and supporting the organization's overall risk posture.

What are some common challenges faced by senior GRC analysts, and how can applicants prepare to address them?

Senior GRC Analysts often encounter challenges such as navigating evolving regulatory requirements, managing cross-departmental collaboration, and ensuring that risk management processes align with business objectives. To succeed, applicants should be prepared to communicate effectively with stakeholders at all levels, stay updated on relevant compliance frameworks, and be proactive in identifying and mitigating potential risks. Gaining experience with industry-standard tools and frameworks, as well as honing project management skills, can help candidates excel in this dynamic and impactful role.

What are the most commonly searched types of Grc Analyst jobs in Reston, VA?

The most popular types of Grc Analyst jobs in Reston, VA are:

What are popular job titles related to Senior Grc Analyst jobs in Reston, VA?

For Senior Grc Analyst jobs in Reston, VA, the most frequently searched job titles are:

What job categories do people searching Senior Grc Analyst jobs in Reston, VA look for?

The top searched job categories for Senior Grc Analyst jobs in Reston, VA are:

What cities near Reston, VA are hiring for Senior Grc Analyst jobs?

Cities near Reston, VA with the most Senior Grc Analyst job openings:

Infographic showing various Senior Grc Analyst job openings in Reston, VA as of August 2026, with employment types broken down into 84% Full Time, 10% Part Time, 1% Temporary, and 5% Contract. Highlights an 81% Physical, 8% Hybrid, and 11% Remote job distribution, with an average salary of $114,490 per year, or $55 per hour.

$95 - $120/hr

Other

Posted 2 days ago

New


Job description

Location: Onsite – Fairfax, VA · U.S. Citizen Required (FedRAMP / Federal Customer)

Type: Full Time

NextgenID is hiring a GRC Lead to own our governance, risk, and compliance program end-to-end. We verify and credential identity at the highest assurance level (IAL3) for federal agencies and enterprises, which means our authorizations — FedRAMP, Kantara, UK digital identity (DIATF/DVS), and the security assurances our customers depend on — are core to the business. You own the compliance calendar, the risk register, the audit and assessment relationships, and the evidence that proves our posture. You lead a GRC Analyst and report to the CTO & EVP. This is a working leadership role: you set the program, and you also do the senior, judgment-heavy work yourself.

Salary Range: $95,000–$120,000

Role Fit & Non-Negotiables
  • Onsite at our Fairfax, VA headquarters. This is a hands-on leadership role, not remote.
  • U.S. citizen, required for FedRAMP and federal-customer obligations.
  • Five or more years in governance, risk, and compliance, including ownership of a formal authorization or audit program.
  • Direct experience with FedRAMP, FISMA, or an equivalent federal framework, and with third-party (3PAO) assessments.
  • Able to make and defend risk decisions and to sign off on evidence that goes to assessors and customers.
What You Will Own (90 to 180 Day Outcomes)
  • A single, authoritative compliance calendar and program plan across FedRAMP, Kantara, UK DVS, SOC 2, and customer questionnaires.
  • The FedRAMP 20x authorization effort carried toward submission, including the 3PAO relationship, Trust Center publication, and machine-readable (OSCAL) control package.
  • A current, governed risk register and monthly POA&M process, with documented risk decisions and compensating controls.
  • Kantara 800-63A (IAL3) certification maintained, with a planned path from Rev 3 to Rev 4.
  • A functioning GRC tooling and evidence pipeline (Vanta) that keeps documentation and submissions current with less manual effort.
  • A GRC Analyst onboarded, directed, and delivering, with the departing analyst’s and intern’s workstreams fully absorbed.
Core Responsibilities

Compliance Program Leadership — own the program, the calendar, and the standard.

  • Own the compliance calendar and program plan across FedRAMP, FISMA, Kantara/NIST 800-63, UK DIATF/DVS, SOC 2, and ADA.
  • Set GRC policy, standards, and process, and keep them current and version-controlled.
  • Report compliance status, risk posture, and audit readiness to the CTO and leadership.

Authorizations & External Assessments — lead audits, 3PAOs, and certification bodies.

  • Lead FedRAMP 20x authorization: 3PAO selection and relationship, ATO timeline, Trust Center publication, and the OSCAL submission strategy.
  • Own the Kantara certification program (800-63A, IAL3) and the Rev 3 to Rev 4 transition strategy.
  • Own the UK DVS / DIATF certification, including scoping and gap-assessment leadership.

Risk Management — own the risk register and the decisions that carry risk.

  • Maintain the enterprise and vendor risk register and govern the monthly POA&M process.
  • Make and document risk decisions, risk adjustments, and compensating controls, including vendor vulnerabilities.
  • Set vulnerability remediation priorities and pentest readiness with the engineering and DevSecOps leads.

Vendor & Customer Assurance — prove our posture to third parties without slowing the business.

  • Own third-party and vendor risk assessments across our tooling and supply chain.
  • Own the security-questionnaire program (final review and sign-off) and represent our posture to customers and prospects.
  • Partner with Growth and Legal on assurance commitments and trust-center content.

Team & Tooling — deliver the program through the analyst and the toolchain.

  • Lead, mentor, and prioritize the work of the GRC Analyst and absorb the departing intern’s workstreams.
  • Own GRC tooling strategy and the evidence pipeline (Vanta, Qualys, OSCAL).
  • Coordinate engineering, DevSecOps, operations, and legal contributors to compliance deliverables.
What You Must Have Already Done
  • Owned a federal authorization or audit program (FedRAMP, FISMA, StateRAMP, or equivalent) through a 3PAO or independent assessment.
  • Built and maintained a risk register and a POA&M process, and defended risk decisions to an assessor or customer.
  • Interpreted a control framework (NIST 800-53, 800-63, or ISO 27001) and translated it into policy, procedure, and evidence.
  • Managed an external assessor or certification-body relationship end to end.
  • Led or mentored analysts and coordinated cross-functional contributors to a compliance deadline.
Required Qualifications
  • Five or more years in governance, risk, and compliance, security compliance, or audit, with program ownership.
  • Direct experience with FedRAMP and/or FISMA, including continuous monitoring (ConMon) and 3PAO assessment.
  • Working command of NIST SP 800-53 and NIST SP 800-63 (identity assurance), and of risk-assessment methodology.
  • Experience owning a risk register, a POA&M process, and a vendor-risk program.
  • Experience managing external assessors, auditors, or certification bodies.
  • Experience with GRC or compliance-automation tooling (Vanta or similar) and vulnerability tools (Qualys or Nessus).
  • Ability to make, document, and defend risk decisions.
  • Excellent written and verbal communication for assessors, customers, and executives.
  • Must be able to work onsite in Fairfax, VA; U.S. citizen (FedRAMP / federal customer).
Preferred Qualifications
  • CISA, CRISC, CISSP, or CISM certification.
  • Experience with Kantara / NIST 800-63 identity assurance (IAL2 / IAL3) certification.
  • Experience with international identity frameworks (UK DIATF / DVS) or ISO 27001 certification.
  • Experience with OSCAL or machine-readable control packages for FedRAMP 20x.
  • Background in a federal-contractor or IDaaS / identity-security environment.
  • Familiarity with SOC 2 and ADA / Section 508 accessibility assessments.
  • You own the calendar in your head: you know what is due, to whom, and what evidence proves it.
  • You make risk calls and defend them with documented reasoning, not hand-waving.
  • You turn a framework into a short list of what has to be done, and get it done.
  • You keep assessors and customers confident because your evidence is clean and current.
  • You lead through other teams, coordinating engineering and operations without owning their headcount.
What Success Looks Like
  • FedRAMP 20x reaches submission on schedule, with a published Trust Center and a machine-readable control package.
  • Kantara IAL3 certification stays current, with a credible Rev 4 transition plan.
  • A single risk register and monthly POA&M process run on cadence, with documented risk decisions.
  • Customer questionnaires and external assessments are answered accurately and on time, with no material findings from poor evidence.
  • The GRC Analyst is productive and the departing analyst’s and intern’s workstreams continue without gaps.
Why NextgenID

NextgenID builds the compliance-grade identity infrastructure that federal agencies and enterprises rely on to verify and credential identity at IAL3. Compliance is not overhead here — it is the product’s license to operate. As GRC Lead, you own the authorizations and the evidence that let us sell and deliver, and you will see your work directly in every certification we hold and every customer we win. For the right person, this is the path to a GRC Manager or Director role as the program grows.

NextgenID focuses on improving the efficiency and speed of mission critical, high assurance identity enrollment and credentialing operations that are essential to hundreds of millions of users worldwide.

Our technologies are engineered to dramatically reduce the time and cost of capturing accurate data when creating a digital identity. Our industry-neutral solutions revolve around "Supervised Remote-Identity Proofing" to automatically, securely and "remotely" perform all proofing, enrollment and credentialing processes and workflows for our customers. The industry is taking notice as we are now working with some of the largest agencies in the US Defense, intelligence, Civil, State and Local government markets, as well as other national governments and commercial organizations throughout the world.

#J-18808-Ljbffr