Cyber GRC & Policy Governance Lead

Brown Advisory Incorporated

Baltimore (MD)

On-site

USD 95,000 - 127,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical
Dental
Vision
Wellness program participation incent
Financial wellness program
Gym membership discounts
401(k)

Job summary

Brown Advisory in Baltimore, MD seeks a Cyber GRC professional to support policies, controls, cyber risk tracking, audit coordination, exceptions, and governance routines. You will maintain the cyber risk register, coordinate evidence collection, control testing, and regulatory responses, and partner with security engineers, Legal, Compliance, and Operations to close gaps.

A background in ISO27001, SOC2, NIST CSF, or related frameworks, plus 3–6 years of cyber GRC experience in financial

Qualifications

  • Bachelor's degree in cyber security, information systems, risk management, business, or a relevant field preferred; equivalent professional experience will be considered.
  • 3-6 years of experience in cyber GRC, information security, technology risk, IT audit, compliance, or related control-management work preferred.
  • Working knowledge of ISO27001, SOC2, NIST CSF, CIS Controls, SEC/FINRA expectations, privacy requirements, or comparable control frameworks.
  • CISA, CRISC, CISM, Security+, ISO27001 Foundation/Lead Implementer, or similar professional designation preferred but not required.

Responsibilities

  • Support and mature core cyber governance routines, including policy management, control ownership, risk acceptance, exception handling, standards maintenance, and periodic leadership reporting.
  • Maintain the cyber risk register and partner with technology and business owners to document risk decisions, remediation plans, due dates, dependencies, and residual risk.
  • Serve as a key administrator and process contributor for ISO and security-risk management platforms such as Vanta or similar tools.
  • Coordinate evidence collection, control testing, audit requests, client due diligence responses, regulatory requests, and recurring compliance deliverables.
  • Translate ISO27001, regulatory, client, and internal security expectations into practical controls and operating procedures appropriate for Brown Advisory's size and risk profile.
  • Facilitate cross-functional communications for security change, SaaS inventory, policy enforcement, control adoption, and risk remediation.
  • Coordinate vulnerability management governance, including scan-result intake, prioritization routines, remediation tracking, exception handling, and reporting.
  • Partner with security engineers, infrastructure teams, application owners, Compliance, Legal, Operations, and Client Service to close control gaps in a business-aligned manner.
  • Develop clear metrics for control effectiveness, audit readiness, exceptions, overdue remediation, and recurring governance activities.
  • Identify process improvements that make security governance more repeatable, transparent, and useful without creating unnecessary bureaucracy.

Skills

Cyber risk governance
Policy management
Audit coordination
Risk tracking
Stakeholder management

Education

Bachelor's degree in cyber security or related field
3–6 years of cyber GRC experience

Tools

Vanta
Archer
ServiceNowGRC
OneTrust
Drata

Job description

Brown Advisory in Baltimore, MD seeks a Cyber GRC professional to support policies, controls, cyber risk tracking, audit coordination, exceptions, and governance routines. You will maintain the cyber risk register, coordinate evidence collection, control testing, and regulatory responses, and partner with security engineers, Legal, Compliance, and Operations to close gaps.

A background in ISO27001, SOC2, NIST CSF, or related frameworks, plus 3–6 years of cyber GRC experience in financial

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber GRC Specialist: Policy, Risk & Audit
Cyber GRC Specialist: Policy, Risk & Audit

Brown Advisory • Washington

On-site
USD 105,000 - 127,000
Medical
Dental
Vision
+1
Cyber GRC Specialist: Policy, Risk & Audit Lead
Cyber GRC Specialist: Policy, Risk & Audit Lead

Brown Advisory • Baltimore (MD)

On-site
USD 95,000 - 125,000
Medical
Dental
Vision
+11
Cyber GRC Specialist
Cyber GRC Specialist

Brown Advisory • Baltimore (MD)

On-site
USD 95,000 - 125,000
Medical
Dental
Vision
+11
Cyber GRC Specialist
Cyber GRC Specialist

Brown Advisory • Washington

On-site
USD 105,000 - 127,000
Medical
Dental
Vision
+1
Cyber GRC Specialist
Cyber GRC Specialist

Brown Advisory Incorporated • Baltimore (MD)

On-site
USD 95,000 - 127,000
Medical
Dental
Vision
+4
Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

duvari group • Fenton (MO)

On-site
USD 83,000 - 131,000
Cybersecurity Governance & Compliance Specialist
Cybersecurity Governance & Compliance Specialist

ROHDE & SCHWARZ GmbH & Co. KG • Frederick (MD)

On-site
USD 120,000 - 160,000
Cybersecurity GRC Specialist
Cybersecurity GRC Specialist

The TemPositions Group of Companies • New York (FL)

On-site
USD 140,000 - 190,000
Hybrid GRC Cybersecurity Analyst: Lead Risk & Compliance
Hybrid GRC Cybersecurity Analyst: Lead Risk & Compliance

Request Technology, LLC • Chicago (IL)

Hybrid
USD 110,000 - 180,000
Defense GRC & Cyber Risk Analyst
Defense GRC & Cyber Risk Analyst

CHAOS Industries • Los Angeles (CA)

On-site
USD 120,000 - 150,000
Health benefits
401k match
FSA/HSA
+5