Compliance Analyst (GRC/RMF Focused)

CL 1e6d8f31 073f 48cd b324 b581c00084bf

Washington (District of Columbia)

Hybrid

USD 80,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CL 1e6d8f31 073f 48cd b324 b581c00084bf is seeking a Compliance Analyst focused on GRC and RMF initiatives. You will support governance and compliance by developing security documentation in accordance with federal standards. The ideal candidate will have experience in cybersecurity compliance and strong communication skills.

This is a hybrid position based in Washington, DC, requiring a detail-oriented individual to manage multiple compliance workstreams while engaging with various stakeholders.

Qualifications

  • 3–6+ years of experience in GRC, RMF, or cybersecurity compliance roles.
  • Strong knowledge of FISMA and NIST guidelines.
  • Ability to produce audit-ready documentation.

Responsibilities

  • Support GRC initiatives by managing compliance documentation.
  • Lead discussions and communicate requirements with stakeholders.
  • Manage multiple compliance workstreams effectively.

Skills

Authoring security documentation
Knowledge of NIST SP 800-53
Developing documentation based on compliance requirements
Experience supporting FedRAMP and/or CMMC
Understanding of SOC 2 principles
Proficiency with GRC tools
Translating technical configurations
Managing POA&Ms
Engagement with customers
Written and verbal communication
Organizational skills
Experience with business tools
Technical proficiency in cloud and on-prem environments
Basic understanding of AI tools

Education

Bachelor’s degree in Cybersecurity or related field

Tools

Microsoft Word
Microsoft Excel
SharePoint
Microsoft Teams

Job description

Job Title: Compliance Analyst (GRC/RMF Focused)

Pay Type: SALARIED EXEMPT

Location: Hybrid, Washington, DC (DMV Area)

Summary of Position Role/Responsibilities

The Compliance Analyst (GRC/RMF Focused) supports governance, risk, and compliance (GRC) initiatives by developing, maintaining, and managing security documentation and compliance artifacts aligned with federal standards. This role plays a key part in supporting Risk Management Framework (RMF) activities, continuous monitoring, and authorization efforts across federal and regulated environments. This role requires strong expertise in NIST SP 800-53, FISMA, and related guidance, with the ability to translate technical system configurations into clear, audit‑ready documentation. The ideal candidate is detail‑oriented, organized, and capable of managing multiple compliance workstreams while engaging effectively with both technical and non‑technical stakeholders.

Essential Functions of the Job
  • Experience authoring and maintaining security documentation, including System Security Plans (SSPs), control implementation statements, policies, and procedures
  • Strong knowledge of NIST SP 800-53 Moderate and High baselines and FISMA requirements
  • Ability to develop documentation in accordance with Agency‑specific security and compliance requirements
  • Experience supporting FedRAMP and/or CMMC compliance efforts
  • Working understanding of SOC 2 principles and control structures
  • Hands‑on experience with GRC tools
  • Ability to translate technical system configurations into clear, audit‑ready documentation
  • Experience developing and managing POA&Ms and supporting continuous monitoring activities
  • Strong understanding of NIST standards and supporting guidance (e.g., 800-60, 800-37, 800-171, 800-137)
  • Ability to engage directly with customers, lead discussions, and clearly communicate requirements to both technical and non‑technical stakeholders
  • Strong written and verbal communication skills with a focus on clarity and professionalism
  • Proven ability to manage multiple priorities and meet strict deadlines in a fast‑paced environment
  • High attention to detail with strong organizational and documentation management skills
  • Proficiency with standard business tools (e.g., Microsoft Word, Excel, SharePoint, Teams)
  • Technical proficiency with On Prem environments, Cloud environments, and associated security concepts
  • Basic understanding of AI tools and ability to leverage them for documentation development (including effective prompting techniques)
  • Ability to work independently while coordinating effectively across internal teams and stakeholders.
Marginal Functions of the Job
  • Other duties as assigned
Normal Work Schedule

This is a full‑time position. Standard business hours are Monday through Friday 8:30 AM to 5:30 PM. Additional time outside of these hours may be needed to complete the essential functions of the job.

Education, Training, and Experience
  • Bachelor’s degree in Cybersecurity, Information Technology, Information Systems, or a related field.
  • 3–6+ years of experience in GRC, RMF, or cybersecurity compliance roles within federal or regulated environments.
  • Strong knowledge of NIST SP 800-53, FISMA, and supporting NIST guidance (e.g., 800-37, 800-60, 800-171, 800-137).
  • Experience supporting FedRAMP, CMMC, and/or SOC 2 compliance efforts.
  • Hands‑on experience with GRC platforms and compliance tracking tools.
  • Technical understanding of on‑premise and cloud environments and associated security concepts.
  • Proven ability to produce audit‑ready documentation and manage compliance artifacts.
  • Strong written and verbal communication skills with the ability to clearly convey complex information.
  • Demonstrated ability to manage multiple projects and deadlines with strong organizational skills.
  • Experience working independently while coordinating across cross‑functional teams.
  • Must be a U.S. Citizen and eligible to support federal contracting environments.
Preferred Certifications
  • CISA (Certified Information Systems Auditor)
  • Security+, CISSP, or similar cybersecurity certification
  • FedRAMP or RMF‑related training or certifications are a plus
EEO Statement

The Company is an Equal Employment Opportunity (EEO) employer and does not discriminate based on race, color, religion, sex, sexual orientation, national origin, age, marital status, disability, veteran's status, or any other basis protected by applicable discrimination laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Assessor (RMF / GRC)
Security Assessor (RMF / GRC)

Digital Global Connectors • McLean (VA)

Hybrid
USD 110,000 - 160,000
Security Assessor (RMF / GRC)
Security Assessor (RMF / GRC)

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 120,000 - 155,000
GRC Analyst II
GRC Analyst II

Frontgrade Technologies • Colorado Springs (CO)

On-site
USD 70,000 - 90,000
Immediate Medical, Dental, and Vision
401K Match with 100% immediate vesting
Tuition Reimbursement/Student Loan Repayment
+2
Principal Security GRC Analyst
Principal Security GRC Analyst

Jobgether • United States

On-site
USD 150,000 - 210,000
High autonomy
Multi-framework exposure
Cloud environment experience
Hybrid RMF & GRC Compliance Analyst
Hybrid RMF & GRC Compliance Analyst

CL 1e6d8f31 073f 48cd b324 b581c00084bf • Washington

Hybrid
USD 80,000 - 110,000
Cybersecurity Audit Analyst
Cybersecurity Audit Analyst

Applied Aerospace • Huntsville (AL)

On-site
USD 70,000 - 90,000
Security Control Assessor
Security Control Assessor

Guidehouse • McLean (VA)

On-site
USD 130,000 - 170,000
Medical Insurance
401(k) Retirement Plan
Parental Leave and Adoption Assistance
+2
Manager of Information Security and Compliance
Manager of Information Security and Compliance

iboss • United States

On-site
USD 100,000 - 130,000
Health, Vision, Dental
401(k) with company match
Unlimited Paid Time Off
+1
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000
FISMA Support Analyst
FISMA Support Analyst

Edgewater Federal Solutions • Washington

On-site
USD 133,000 - 136,000
Paid Time Off
Medical Insurance
Dental Insurance
+5