GRC Lead
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Location: Onsite – Fairfax, VA
· U.S. Citizen Required (FedRAMP / Federal Customer)
Type: Full Time
NextgenID is hiring a GRC Lead to own our governance, risk, and compliance program end-to-end. We verify and credential identity at the highest assurance level (IAL3) for federal agencies and enterprises, which means our authorizations — FedRAMP, Kantara, UK digital identity (DIATF/DVS), and the security assurances our customers depend on — are core to the business. You own the compliance calendar, the risk register, the audit and assessment relationships, and the evidence that proves our posture.
You lead a GRC Analyst and report to the CTO & EVP. This is a working leadership role: you set the program, and you also do the senior, judgment-heavy work yourself.
Salary Range: $95,000–$120,000
Role Fit & Non-Negotiables- Onsite at our Fairfax, VA headquarters. This is a hands-on leadership role, not remote.
- U.S. citizen, required for FedRAMP and federal-customer obligations.
- Five or more years in governance, risk, and compliance, including ownership of a formal authorization or audit program.
- Direct experience with FedRAMP, FISMA, or an equivalent federal framework, and with third-party (3
PAO) assessments. - Able to make and defend risk decisions and to sign off on evidence that goes to assessors and customers.
- A single, authoritative compliance calendar and program plan across FedRAMP, Kantara, UK DVS, SOC 2, and customer questionnaires.
- The FedRAMP 20x authorization effort carried toward submission, including the 3
PAO relationship, Trust Center publication, and machine-readable (OSCAL) control package. - A current, governed risk register and monthly POA&M process, with documented risk decisions and compensating controls.
- Kantara 800-63A (IAL3) certification maintained, with a planned path from Rev 3 to Rev 4.
- A functioning GRC tooling and evidence pipeline (Vanta) that keeps documentation and submissions current with less manual effort.
- A GRC Analyst onboarded, directed, and delivering, with the departing analyst’s and intern’s work streams fully absorbed.
Compliance Program Leadership — own the program, the calendar, and the standard.
- Own the compliance calendar and program plan across FedRAMP, FISMA, Kantara/NIST 800-63, UK DIATF/DVS, SOC 2, and ADA.
- Set GRC policy, standards, and process, and keep them current and version-controlled.
- Report compliance status, risk posture, and audit readiness to the CTO and leadership.
Authorizations & External Assessments — lead audits, 3
PAOs, and certification bodies.
- Lead FedRAMP 20x authorization: 3
PAO selection and relationship, ATO timeline, Trust Center publication, and the OSCAL submission strategy. - Own the Kantara certification program (800-63A, IAL3) and the Rev 3 to Rev 4 transition strategy.
- Own the UK DVS / DIATF certification, including scoping and gap-assessment leadership.
Risk Management — own the risk register and the decisions that carry risk.
- Maintain the enterprise and vendor risk register and govern the monthly POA&M process.
- Make and document risk decisions, risk adjustments, and compensating controls, including vendor vulnerabilities.
- Set vulnerability remediation priorities and pentest readiness with the engineering and Dev Sec Ops leads.
Vendor & Customer Assurance — prove our posture to third parties without slowing the business.
- Own third-party and vendor risk assessments across our tooling and supply chain.
- Own the security-questionnaire program (final review and sign-off) and represent our posture to customers and prospects.
- Partner with Growth and Legal on assurance commitments and trust-center content.
Team & Tooling — deliver the program through the analyst and the toolchain.
- Lead, mentor,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).