×
Register Here to Apply for Jobs or Post Jobs. X

Security Governance Risk & Compliance (GRC) Analyst

Job in Washington, District of Columbia, 20022, USA
Listing for: Virtru
Full Time position
Listed on 2026-08-22
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant
Salary/Wage Range or Industry Benchmark: 130000 - 170000 USD Yearly USD 130000.00 170000.00 YEAR
Job Description & How to Apply Below

Security Governance Risk & Compliance (GRC) Analyst

Washington, DC - Remote

About Virtru:

While the rest of the security industry obsesses over locking data down to prevent it from being lost or stolen, we’re doing something fundamentally different ’re setting data free so that you can intentionally share it with others, but without sacrificing security, privacy, or control.

We’ve created both a suite of powerful data protection applications and an open platform that’s sparking an ecosystem of innovation. Through the Trusted Data Format (TDF) open standard, we’re not just protecting data; we’re creating a new paradigm where security enables sharing rather than preventing it.

Think of us as the Android of data protection: a robust platform with an open core that developers and partners can build upon, coupled with our own best‑in‑class applications that showcase what’s possible when you reimagine security from the ground up.

Backed by Iconiq Capital, Bessemer Venture Partners, Foundry Capital, and Tiger Global, we’re helping Fortune 500 companies and government agencies discover that true data security means having the freedom to share, collaborate, and innovate—without compromise.

Compensation: $130,000-$170,000/year

Here at Virtru you’ll help build a cutting‑edge security compliance program aligned with FedRAMP, SOC 2, PCI, HIPAA, GDPR, and any other security/privacy framework you can think of, while getting your hands on some of today’s most important tools and tech like Kubernetes, GCP, AWS, Terraform. We put a high value on input from everyone on our team. Your voice will have a significant impact.

With a constantly growing customer base, there is no shortage of challenging and exciting scaling/optimization work to ensure that we can provide the most secure and performant service.

As a GRC Analyst at Virtru, you will be the primary point of contact for compliance‑related inquiries. You will lead and manage the organization’s efforts to achieve and maintain CMMC compliance by conducting gap analyses and developing a roadmap to address compliance requirements. You will also play a vital role in supporting our existing FedRAMP, SOC 2, and PCI DSS compliance.

Responsibilities
  • Manage and implement complex controls frameworks for large systems, including cloud infrastructure and SaaS services (GCP, AWS, Git Hub, Okta, etc.).
  • Design and develop automation solutions for evidence collection across cloud infrastructure, endpoints, and SaaS services.
  • Conduct risk assessments across business units and processes, identify risk findings, and recommend remediation and risk‑mitigation strategies.
  • Participate in incident response activities, providing risk analysis and remediation support as needed.
  • Assist or implement automated controls to support risk mitigation efforts across various business units with stakeholders.
  • Incorporate CMMC certification into Virtru’s slate of compliance assessments and ongoing monitoring activities (FedRAMP, SOC 2, PCI).
  • Facilitate the third‑party vendor on‑boarding and annual review process by evaluating the security of current and prospective partners.
  • Enhance the team with your individualism, spirit, and love of learning.
Skills that Will Help You Thrive
  • Minimum of 5+ years of information security, IT audit and/or IT risk management, or GRC analyst/engineer experience.
  • Deep understanding of at least a few of the following: CMMC, NIST 800‑53 & 800‑171, FedRAMP, SOC 2, PCI, and/or other global privacy compliance frameworks.
  • Technical acumen: strong understanding of modern cloud technologies (AWS, GCP, Azure, etc.) and familiarity with GRC tools (Hyperproof, Vanta, Drata, etc.) and SIEM tools (Datadog, Splunk).
  • You’re a relationship builder and have worked with both business and technical risk and understand how to translate risk to various levels of the organization.
  • Experience training and coaching teams to become better security and privacy practitioners.
  • Like working on an autonomous agile team. At Virtru, you will have ownership of security, but you’ll collaborate with everyone to ensure we produce and implement the right solutions.
  • Ability to resolve conflicts and drive issues to…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary