×
Register Here to Apply for Jobs or Post Jobs. X

Mid-Level GRC Analyst

Job in Silver Spring, Montgomery County, Maryland, 20900, USA
Listing for: H & R Computer Consulting Services
Full Time position
Listed on 2026-05-21
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security, Data Security
Salary/Wage Range or Industry Benchmark: 70000 - 80000 USD Yearly USD 70000.00 80000.00 YEAR
Job Description & How to Apply Below

Job Title: Mid-Level GRC Analyst
Location: 1-day on-site at HQ - Silver Spring, MD
Clearance Required: Public Trust Eligible
Salary: $70K-$80K

Final date to receive applications:
To apply, please follow these steps:

  • Visit .
  • Select the position you are interested in.
  • Review the job details, then click Apply Now.
  • Complete and submit your application.

Description
The Mid-Level GRC Analyst will support cybersecurity governance, risk management, and compliance (GRC) initiatives across commercial and federal client environments. This role requires hands-on experience supporting cybersecurity compliance activities with minimal supervision from senior GRC personnel.

The ideal candidate must be capable of independently developing and maintaining System Security Plans (SSPs), identifying documentation and evidence deficiencies, and coordinating directly with stakeholders to request corrected or additional artifacts as needed. The candidate must possess strong written communication skills and the ability to translate technical implementations into defensible compliance documentation.

Key Responsibilities:
Governance & Policy Support

  • Develop, maintain, and update cybersecurity policies, standards, procedures, and supporting documentation.
  • Support policy-to-control mapping and traceability activities across multiple frameworks.
  • Coordinate annual policy reviews and assist with compliance reporting activities.
  • Research cybersecurity laws, regulations, standards, and guidelines relevant to client environments.

Risk Management

  • Conduct system-level and scoped enterprise risk assessments aligned with NIST SP 800-30 methodologies.
  • Identify threats, vulnerabilities, likelihood, impact, and overall risk ratings.
  • Develop risk assessment reports and remediation recommendations.
  • Maintain and track risks within centralized risk registers.
  • Support vendor risk management activities, including third-party security questionnaire and SOC report reviews.

Compliance & Audit Readiness

  • Independently develop and maintain System Security Plans (SSPs) for frameworks such as NIST SP 800-53 and NIST SP 800-171.
  • Document control implementation statements and validate supporting evidence.
  • Identify incomplete, inaccurate, or insufficient artifacts and coordinate directly with technical stakeholders to obtain corrected evidence.
  • Support readiness efforts for frameworks such as CMMC, HIPAA, ISO 27001, SOC 2, and FedRAMP.
  • Participate in internal and external audit engagements, evidence collection activities, stakeholder interviews, and remediation tracking efforts.
  • Maintain POA&Ms and compliance remediation trackers.

Methodology & Team Support

  • Contribute improvements to internal GRC methodologies, templates, checklists, and delivery processes.
  • Provide mentorship and informal guidance to junior team members, apprentices, and interns.
  • Escalate complex issues and risks to senior leadership as appropriate.
  • Participate in monthly volunteer efforts supporting environmental and humanitarian initiatives.

Required Qualifications:

  • Bachelor''''s degree in Cybersecurity, Information Technology, Information Systems, Computer Science, or related field; OR equivalent cybersecurity coursework and practical experience.
  • 2 to 4 years of hands-on cybersecurity GRC experience.
  • Experience supporting or documenting compliance activities aligned with:
    • NIST SP 800-53
    • NIST SP 800-171
    • CMMC
  • Experience developing or maintaining System Security Plans (SSPs).
  • Ability to independently identify evidence gaps and request corrected artifacts from stakeholders.
  • Strong written and verbal communication skills.
  • Ability to work independently and within a team environment.

Preferred Qualifications:

  • Familiarity with FedRAMP environments and federal compliance requirements.
  • Security+, CAP, CISA, CCP, or similar cybersecurity certification preferred but not required.
  • Experience supporting federal clients or regulated environments preferred.
  • Public Trust eligibility required;
    Secret clearance eligibility preferred.

Work Environment:
This position supports both commercial and federal cybersecurity compliance initiatives within a collaborative and fast-paced environment. Candidates should be comfortable working directly with technical teams, leadership, and client stakeholders while managing multiple concurrent compliance activities.

About IBSS Corp.
Since 1992, IBSS, a woman-owned small business, has provided transformational consulting services to the Federal defense, civilian, and commercial sectors. Our services include cybersecurity and enterprise information technology, environmental science and engineering (including oceans, coasts, climate, and weather), and professional management services.

Our approach is to serve our employees by investing in their growth and development. As a result, our employees bring greater capabilities and provide exceptional service to our clients. In addition to creating career development opportunities for our employees, IBSS is passionate about giving back to the community and serving the environment. We strive to…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary