Назад
Company hidden
15 часов назад

GRC Analyst (Cybersecurity)

62 000 - 141 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
GRC Analyst (Cybersecurity): Supporting Risk Management Framework activities and Assessment and Authorization packages through Authorization to Operate decisions with an accent on NIST controls, security documentation, and compliance evidence. Focus on assessing risk, translating technical findings into remediation plans, coordinating authorizing officials, and maintaining continuous monitoring for secure and compliant systems.

Location: Remote role associated with Bethesda, Maryland, USA; occasional work at a Booz Allen or customer facility may be required.

Salary: $62,000–$141,000 annualized USD

Company

hirify.global supports government and mission teams with cybersecurity risk management, compliance, and authorization activities.

What you will do

  • Support Risk Management Framework activities across categorization, control selection and implementation, assessment, authorization, and continuous monitoring.
  • Drive Assessment and Authorization packages through Authorization to Operate decisions with authorizing officials.
  • Perform security control assessments and produce Security Assessment Reports and Plans of Action and Milestones.
  • Develop and maintain System Security Plans, control implementation statements, and other security documentation.
  • Translate technical findings into risk statements and remediation recommendations aligned with mission and business priorities.
  • Track residual risk, plan continuous monitoring, and drive closure of remediation items.

Requirements

  • 3+ years of experience in cyber risk management or security compliance, or 5+ years of information security experience in lieu of a bachelor's degree.
  • Experience applying NIST RMF and supporting Assessment and Authorization activities and Authorization to Operate decisions.
  • Knowledge of NIST SP 800-53 Rev. 5 control families, control tailoring, and FISMA processes.
  • Ability to assess controls, maintain security artifacts, and communicate risk and remediation recommendations clearly.
  • Public Trust determination and eligibility for a U.S. government client investigation are required.
  • Bachelor's degree in information security or a related area, unless the experience alternative applies.

Nice to have

  • Assessment and Authorization experience with health or research-focused government entities.
  • Experience communicating complex security concepts to non-technical stakeholders and senior leaders.
  • Experience producing executive-ready summaries and concise technical documentation.
  • Knowledge of stakeholder analysis, change management, structured writing, and plain-language techniques.
  • Master's degree and experience facilitating working sessions or presenting recommendations.

Culture & Benefits

  • Remote work model with cameras generally expected during virtual meetings.
  • Potential in-person work at a Booz Allen or customer facility when required by the role.
  • Health, life, disability, financial, and retirement benefits.
  • Paid leave, professional development, tuition assistance, work-life programs, and dependent care.
  • Recognition awards and support for employee well-being.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →