Cyber GRC Specialist
Job in
Washington, District of Columbia, 20022, USA
Listed on 2026-09-16
Listing for:
Jobtailor
Full Time
position Listed on 2026-09-16
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
- Support and mature cyber governance routines, including policy management, control ownership, risk acceptance, exception handling, standards maintenance, and leadership reporting
- Maintain the cyber risk register and document risk decisions, remediation plans, due dates, dependencies, and residual risk
- Administer and contribute process support to ISO and security-risk management platforms such as Vanta or similar tools
- Coordinate evidence collection, control testing, audits, client due diligence responses, regulatory requests, and compliance deliverables
- Translate ISO 27001, regulatory, client, and internal security expectations into practical controls and operating procedures
- Facilitate cross-functional communications for security change, SaaS inventory, policy enforcement, control adoption, and risk remediation
- Coordinate vulnerability management governance, including scan-result intake, prioritization, remediation tracking, exception handling, and reporting
- Partner with security engineers, infrastructure teams, application owners, Compliance, Legal, Operations, and Client Service to close control gaps
- Develop metrics for control effectiveness, audit readiness, exceptions, overdue remediation, and governance activities
- Identify process improvements to make security governance repeatable, transparent, and useful
- Bachelor's degree in cyber security, information systems, risk management, business, or a relevant field preferred; equivalent professional experience will be considered
- 3-6 years of experience in cyber GRC, information security, technology risk, IT audit, compliance, or related control-management work preferred
- Working knowledge of ISO 27001, SOC 2, NIST CSF, CIS Controls, SEC/FINRA expectations, privacy requirements, or comparable control frameworks
- Experience supporting audits, evidence collection, control testing, policy updates, issue tracking, or risk-register maintenance in a regulated environment; financial services experience preferred
- CISA, CRISC, CISM, Security+, ISO 27001 Foundation/Lead Implementer, or similar professional designation preferred but not required
- Knowledge of cyber risk registers, exception management, control testing, evidence management, policy lifecycle management, and audit coordination
- Experience with GRC or trust-management platforms such as Vanta, Archer, Service Now GRC, One Trust, Drata, or similar tools
- Knowledge of vulnerability management governance, prioritization, remediation tracking, aging analysis, exception workflows, and executive reporting
- Strong knowledge of cyber security controls across identity, endpoint, cloud, network, data protection, application security, and third-party risk
- Excellent writing, facilitation, and stakeholder-management skills
- Ability to translate technical risk into clear business language
- Practical judgment in enforcing, escalating, and developing workable control paths
- Ability to take ownership and move initiatives forward without constant oversight
- Ability to balance technical depth, process discipline, and business judgment
- Ability to communicate clearly with technical and non-technical colleagues
- Must be authorized to work in the United States without current or future employer-sponsored work authorization
Demonstrates expertise in cyber governance, risk management, and compliance, with a strong focus on ISO 27001 and related frameworks. Capable of translating complex security requirements into actionable controls while facilitating cross-functional collaboration and effective communication.
Highest-signal resume keywords- Cyber Governance
- ISO 27001 Knowledge
- Risk Management
- GRC Platforms Experience
- Control Testing
- Cyber Risk Management
- Policy Management
- Control Ownership
- Audit Coordination
- Evidence Collection
- Vulnerability Management
- Risk Register Maintenance
- Technical Risk Translation
- Control Effectiveness Metrics
- Compliance Deliverables
- Excellent Writing
- Facilitation Skills
- Stakeholder Management
- Practical Judgment
- Clear Communication
- CISA
- CRISC
- CISM
- Security+
- ISO 27001 Foundation/Lead Implementer
- Cyber Security
- Information Security
- Technology Risk
- IT Audit
- Compliance
- Financial Services
- SOC 2
- NIST CSF
- CIS Controls
- SEC/FINRA Expectations
- Vanta
- Archer
- Service Now GRC
- One Trust
- Drata
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×