Cyber GRC Specialist

Brown Advisory

Washington (District of Columbia)

On-site

USD 105,000 - 127,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical
Dental
Vision
Wellness program participation

Job summary

Brown Advisory is seeking a Cyber GRC Specialist to mature governance routines, manage policy ownership, risk tracking, and audit readiness within a lean security team. The role emphasizes translating security requirements into practical programs, coordinating evidence, and reporting on controls.

The ideal candidate has 3–6 years of cyber GRC experience, knowledge of ISO 27001/NIST, and experience with multiple GRC platforms. DC-based, full-time with strong collaboration across departments.

Qualifications

  • Bachelor's degree in cyber security, information systems, risk management, business preferred or equivalent experience.
  • 3–6 years of experience in cyber GRC, information security, technology risk, IT audit, compliance, or related control-management work.
  • Knowledge of ISO 27001, SOC 2, NIST CSF, CIS Controls, SEC/FINRA expectations, privacy requirements or similar.
  • Experience supporting audits, evidence collection, control testing, policy updates, issue tracking or risk-register maintenance in regulated environments.
  • Professional designations (CISA, CRISC, CISM, Security+, ISO 27001) preferred but not required.

Responsibilities

  • Support and mature cyber governance routines: policy management, control ownership, risk acceptance, exceptions and governance reporting.
  • Maintain cyber risk register and document risk decisions, remediation plans, due dates and dependencies.
  • Administer ISO and security-risk platforms (Vanta, Archer, ServiceNow GRC, OneTrust, Drata).
  • Coordinate evidence collection, control testing, audit requests and regulatory responses.
  • Translate security expectations into practical controls and operating procedures.
  • Facilitate cross-functional communications for security changes and policy enforcement.
  • Coordinate vulnerability governance: scan intake, prioritization, remediation tracking and reporting.
  • Collaborate with security engineers, IT, Compliance, Legal, Operations and Client Service to close control gaps.
  • Develop metrics for control effectiveness and audit readiness.
  • Identify process improvements for governance repeatability and transparency.

Skills

Cyber risk management
Stakeholder management
Policy communication
Writing and facilitation
Continuous improvement

Education

Bachelor's degree in cyber security, information systems, risk management, business

Tools

Vanta
Archer
ServiceNow GRC
OneTrust
Drata

Job description

Company Overview

Every firm has a culture – the values, beliefs, methodology, attitudes and standards that reflect an organization’s DNA. But the truly inspiring firms – the game‑changers, the industry leaders and the disruptors – have cultures that propel them to innovate and stand out. At Brown Advisory, we aim to be one of those inspired firms. Over the years, we have purposefully built and nurtured our client‑first culture.

Company Overview

Every firm has a culture – the values, beliefs, methodology, attitudes and standards that reflect an organization’s DNA. But the truly inspiring firms – the game‑changers, the industry leaders and the disruptors – have cultures that propel them to innovate and stand out. At Brown Advisory, we aim to be one of those inspired firms. Over the years, we have purposefully built and nurtured our client‑first culture.

Brown Advisory is an independent investment management and strategic advisory firm committed to delivering a combination of first‑class performance, strategic advice and the highest level of client service. The firm’s clients—including individuals, families, family offices, endowments, foundations, charities, institutions, consultants, and financial intermediaries—are served by over 1,000 colleagues worldwide, all of whom are equity owners of the firm.

Brown Advisory is currently seeking a Cyber GRC Specialist to support and mature the firm's governance, risk, compliance, and control‑management routines. This blended role is designed for someone who can translate security requirements into practical business processes, drive evidence and accountability, and communicate clearly with technical and non‑technical stakeholders.

As part of a lean Information Security team within a mid‑sized financial services organization, this individual will serve as a central coordinator for cyber risk, policy management, control testing, audit readiness, client and regulatory response support, and vulnerability remediation governance. The role is not intended to be a hands‑on vulnerability engineering role; rather, it ensures the process, ownership, exceptions, reporting, and governance routines are working.

Blended Role Coverage

Primary emphasis: Cyber GRC support for policies, controls, cyber risk tracking, audit coordination, exceptions, and governance routines.

Blended coverage: Cyber Risk / Compliance Analyst work, ISO and risk‑platform support, evidence coordination, client/regulatory response support, communications, and vulnerability governance.

Duties And Responsibilities
  • Support and mature core cyber governance routines, including policy management, control ownership, risk acceptance, exception handling, standards maintenance, and periodic leadership reporting.
  • Maintain the cyber risk register and partner with technology and business owners to document risk decisions, remediation plans, due dates, dependencies, and residual risk.
  • Serve as a key administrator and process contributor for ISO and security‑risk management platforms such as Vanta or similar tools.
  • Coordinate evidence collection, control testing, audit requests, client due diligence responses, regulatory requests, and recurring compliance deliverables.
  • Translate ISO 27001, regulatory, client, and internal security expectations into practical controls and operating procedures appropriate for Brown Advisory's size and risk profile.
  • Facilitate cross‑functional communications for security change, SaaS inventory, policy enforcement, control adoption, and risk remediation.
  • Coordinate vulnerability management governance, including scan‑result intake, prioritization routines, remediation tracking, exception handling, and reporting.
  • Partner with security engineers, infrastructure teams, application owners, Compliance, Legal, Operations, and Client Service to close control gaps in a business‑aligned manner.
  • Develop clear metrics for control effectiveness, audit readiness, exceptions, overdue remediation, and recurring governance activities.
  • Identify process improvements that make security governance more repeatable, transparent, and useful without creating unnecessary bureaucracy.
Preferred Qualifications
  • Bachelor's degree in cyber security, information systems, risk management, business, or a relevant field preferred; equivalent professional experience will be considered.
  • 3-6 years of experience in cyber GRC, information security, technology risk, IT audit, compliance, or related control‑management work preferred.
  • Working knowledge of ISO 27001, SOC 2, NIST CSF, CIS Controls, SEC/FINRA expectations, privacy requirements, or comparable control frameworks.
  • Experience supporting audits, evidence collection, control testing, policy updates, issue tracking, or risk‑register maintenance in a regulated environment; financial services experience preferred.
  • CISA, CRISC, CISM, Security+, ISO 27001 Foundation/Lead Implementer, or similar professional designation preferred but not required.
Technical Skills
  • Cyber risk registers, exception management, control testing, evidence management, policy lifecycle management, and audit coordination.
  • GRC or trust‑management platforms such as Vanta, Archer, ServiceNow GRC, OneTrust, Drata, or similar tools.
  • Vulnerability management governance, including prioritization, remediation tracking, aging analysis, exception workflows, and executive reporting.
  • Strong knowledge of cyber security controls across identity, endpoint, cloud, network, data protection, application security, and third‑party risk.
  • Excellent writing, facilitation, and stakeholder‑management skills, including the ability to turn technical risk into clear business language.
  • Practical judgment about when to enforce, when to escape, and when to help the business find a workable control path.
  • Demonstrates curiosity and a continuous improvement mindset by identifying opportunities to enhance processes, improve efficiency, and thoughtfully leverage new technologies and tools, including AI‑enabled productivity solutions.
Personal Attributes
  • Take ownership and move initiatives forward without constant oversight.
  • Balance technical depth, process discipline, and sound business judgment.
  • Approach risk management pragmatically rather than theoretically.
  • Thrive in collaborative, high‑accountability environments.
  • Communicate clearly with technical and non‑technical colleagues.
  • Bring an entrepreneurial mindset to building and improving security capabilities.

Applicants must be authorized to work in the United States without the need for current or future employer‑sponsored work authorization (e.g., H‑1B , O‑1, F‑1 (OPT), TN, or any other non‑immigrant visa classifications that require employer support or sponsorship).

MD Salary: $95-$115k. Commensurate with experience and location. Does not include bonus or long term incentive eligibility (if applicable).

DC Salary: $104.5K–$126.5K. Commensurate with experience and location. Does not include bonus or long‑term incentive eligibility (if applicable).

Benefits

At Brown Advisory we offer a competitive compensation package, including full benefits.

  • Medical
  • Dental
  • Vision
  • Wellness program participation incentive
  • Financial wellness program
  • Fitness event fee reimbursement
  • Gym membership discounts
  • Colleague Assistance Program
  • Telemedicine Program (for those enrolled in Medical)
  • Adoption Benefits
  • Daycare late pick‑up fee reimbursement
  • Basic Life & Accidental Death & Dismemberment Insurance
  • Voluntary Life & Accidental Death & Dismemberment Insurance
  • Short Term Disability
  • Paid parental leave
  • Group Long Term Disability
  • Pet Insurance
  • 401(k) (50% employer match up to IRS limit, 4 year vesting)

Brown Advisory is an Equal Employment Opportunity Employer.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber GRC Specialist
Cyber GRC Specialist

Brown Advisory • Baltimore (MD)

On-site
USD 95,000 - 125,000
Medical
Dental
Vision
+11
Identity and Access Security Engineer
Identity and Access Security Engineer

Brown Advisory • Baltimore (MD)

On-site
USD 110,000 - 135,000
Medical
Dental
Vision
+1
Cyber GRC Specialist: Policy, Risk & Audit
Cyber GRC Specialist: Policy, Risk & Audit

Brown Advisory • Washington

On-site
USD 105,000 - 127,000
Medical
Dental
Vision
+1
Cloud Security Engineer
Cloud Security Engineer

Brown Advisory • Washington

On-site
USD 154,000 - 165,000
Medical
Dental
Vision
+3
Cloud Security Engineer
Cloud Security Engineer

Brown Advisory • Baltimore (MD)

On-site
USD 140,000 - 150,000
Medical
Dental
Vision
+14
Cyber GRC Specialist: Policy, Risk & Audit Lead
Cyber GRC Specialist: Policy, Risk & Audit Lead

Brown Advisory • Baltimore (MD)

On-site
USD 95,000 - 125,000
Medical
Dental
Vision
+11
Sr Cybersecurity GRC Associate
Sr Cybersecurity GRC Associate

ManpowerGroup Global, Inc. • Town of Norway (WI), Chicago (IL)

Hybrid
USD 130,000
Medical and Prescription Drug Plans
Dental Plan
Vision Plan
+3
Assistant Director, Cyber GRC
Assistant Director, Cyber GRC

Principal Financial Group • Des Moines (IA)

Hybrid
USD 141,000 - 180,000
Flexible Time Off
Pension eligibility
Option for hybrid or remote work
Identity and Access Security Engineer
Identity and Access Security Engineer

Brown Advisory Incorporated • Baltimore (MD)

On-site
USD 110,000 - 135,000
Medical
Dental
Vision
+1
Senior Governance, Risk, & Compliance Analyst
Senior Governance, Risk, & Compliance Analyst

Jobgether • United States

On-site
USD 58,000 - 222,000
Medical, dental, vision insurance
Flexible work environment
Paid time off
+1