GRC Analyst
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Location: Onsite - Fairfax, VA
· U.S. Citizen Required (FedRAMP / Federal Customer)
Type: Full Time
NextgenID is hiring a GRC Analyst to do the hands‑on work that keeps our compliance program running. We verify and credential identity at the highest assurance level (IAL3) for federal agencies and enterprises, so evidence, documentation, and audit support are constant, real work. You maintain our control documentation and evidence, run the operational side of our FedRAMP, Kantara, and UK digital‑identity efforts, keep the POA&M and vulnerability tracking current, and complete the security questionnaires our customers send.
You report to the GRC Lead.
Salary Range: $75,000-$95,000
- Onsite at our Fairfax, VA headquarters. This role is hands‑on and evidence‑heavy.
- U.S. citizen, required for FedRAMP and federal‑customer obligations.
- Two or more years in GRC, security compliance, audit support, or a closely related role.
- Comfortable owning documentation, evidence, and trackers to a deadline.
- Detail‑oriented and discreet with sensitive security information.
- Current, well‑organized control documentation and evidence repositories, moving from SharePoint into Vanta.
- The operational FedRAMP evidence effort: control documentation, gap‑finding tracking, and Trust Center content drafts.
- A monthly POA&M produced from Qualys findings using the FedRAMP template, with remediation tracked to closure.
- Completed, consistent security questionnaires delivered on time for GRC Lead review.
- The UK DVS documentation package and Kantara assessment materials kept current and submission‑ready.
Compliance Documentation & Evidence — keep the record current and audit‑ready.
- Maintain control documentation, policies, and procedures, and migrate evidence into Vanta.
- Gather and organize evidence from engineering, Dev Sec Ops , and operations leads.
- Convert implemented controls into machine‑readable (OSCAL / JSON) format for FedRAMP submission.
Authorization & Assessment Support — run the operational side of our certifications.
- Refine and maintain the UK DVS / DIATF documentation package and scoping forms.
- Prepare Kantara assessment materials (SoCA, S3A, KAR) and the Rev 4 gap working draft.
- Coordinate assessment and pentest logistics, scheduling, and evidence with assessors and leads.
Vulnerability & POA&M Tracking — keep the remediation record honest.
- Produce the monthly POA&M from Qualys findings using the FedRAMP template.
- Track vulnerability remediation and compensating controls with the Red Team / Dev Sec Ops leads.
- Maintain vulnerability and vendor‑risk evidence logs (for example, the Beyond Trust remediation log).
Customer & Vendor Assurance Support — answer the questionnaires and support vendor risk.
- Complete security questionnaires (for example, CCRA and customer Info Sec assessments) consistent with prior responses.
- Support third‑party and vendor risk assessments and evidence requests.
- Route completed responses to the GRC Lead and management for review before submission.
Research & Program Support — support the wider compliance effort.
- Provide compliance and privacy research to the document and product teams.
- Support ADA / Section 508 assessments and international import certification documentation (BIS, WPC, ATA Carnet).
- Help configure and maintain GRC tooling (Vanta) and keep the compliance calendar updated.
- Gathered and organized audit evidence and maintained compliance documentation to a deadline.
- Worked with a control framework (NIST 800-53, 800-63, ISO 27001, or SOC
2) on real evidence or gap work. - Tracked vulnerabilities or POA&M items and coordinated remediation with technical teams.
- Completed a customer or vendor…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).