Cyber GRC Specialist: Policy, Risk & Audit Lead

Brown Advisory

Baltimore (MD)

On-site

USD 95,000 - 125,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical
Dental
Vision
Wellness program
Financial wellness program
Gym membership discounts
Colleague Assistance Program
Telemedicine Program
Adoption Benefits
Daycare late pick-up fee reimbursement
Short Term Disability
Paid parental leave
Group Long Term Disability
401(k)

Job summary

Brown Advisory is seeking a Cyber GRC Specialist to support and mature governance, risk, compliance, and control-management routines within a lean information security team. The role focuses on translating security requirements into practical business processes, driving evidence collection, and coordinating with stakeholders across technology and business units.

In this blended role, you will manage ISO and risk platforms, coordinate audits, and develop metrics for control effectiveness and

Qualifications

  • Bachelor's degree preferred; equivalent professional experience considered.
  • 3–6 years of experience in cyber GRC, information security, technology risk, IT audit, compliance, or related control-management work.
  • Working knowledge of ISO 27001, SOC 2, NIST CSF, CIS Controls, SEC/FINRA expectations, privacy requirements, or comparable frameworks.
  • Experience supporting audits, evidence collection, control testing, policy updates, issue tracking, or risk-register maintenance in a regulated environment; financial services experience preferred.
  • CISA, CRISC, CISM, Security+, ISO 27001 Foundation/Lead Implementer, or similar designation preferred but not required.

Responsibilities

  • Support and mature core cyber governance routines, including policy management, control ownership, risk acceptance, exception handling, standards maintenance, and leadership reporting.
  • Maintain the cyber risk register and document risk decisions, remediation plans, due dates, dependencies, and residual risk.
  • Serve as administrator for ISO and security-risk platforms such as Vanta, Archer, or similar tools.
  • Coordinate evidence collection, control testing, audit requests, client due diligence responses, regulatory requests, and recurring compliance deliverables.
  • Translate ISO 27001, regulatory, client, and internal security expectations into practical controls and procedures.

Skills

Cyber risk registers
Policy lifecycle management
Audit coordination
Evidence management
Stakeholder management
Vulnerability governance
ISO 27001 knowledge
Excellent writing

Education

Bachelor's degree in cyber security, information systems, risk management, or related field

Tools

Vanta
Archer
ServiceNow GRC
OneTrust
Drata

Job description

Brown Advisory is seeking a Cyber GRC Specialist to support and mature governance, risk, compliance, and control-management routines within a lean information security team. The role focuses on translating security requirements into practical business processes, driving evidence collection, and coordinating with stakeholders across technology and business units.

In this blended role, you will manage ISO and risk platforms, coordinate audits, and develop metrics for control effectiveness and

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber GRC Specialist: Policy, Risk & Audit
Cyber GRC Specialist: Policy, Risk & Audit

Brown Advisory • Washington

On-site
USD 105,000 - 127,000
Medical
Dental
Vision
+1
Cyber GRC & Policy Governance Lead
Cyber GRC & Policy Governance Lead

Brown Advisory Incorporated • Baltimore (MD)

On-site
USD 95,000 - 127,000
Medical
Dental
Vision
+4
Cyber GRC Specialist
Cyber GRC Specialist

Brown Advisory • Washington

On-site
USD 105,000 - 127,000
Medical
Dental
Vision
+1
Cyber GRC Specialist
Cyber GRC Specialist

Brown Advisory • Baltimore (MD)

On-site
USD 95,000 - 125,000
Medical
Dental
Vision
+11
Cyber GRC Specialist
Cyber GRC Specialist

Brown Advisory Incorporated • Baltimore (MD)

On-site
USD 95,000 - 127,000
Medical
Dental
Vision
+4
GRC Cybersecurity Policy & Risk Analyst
GRC Cybersecurity Policy & Risk Analyst

Vanguard • Dallas (TX)

On-site
USD 90,000 - 125,000
GRC Specialist (Governance, Risk & Compliance)
GRC Specialist (Governance, Risk & Compliance)

360CyberX • United States

On-site
USD 70,000 - 90,000
Global Cyber GRC & Awareness Analyst
Global Cyber GRC & Awareness Analyst

UL Solutions • Chicago (IL)

On-site
USD 65,000 - 85,000
Cyber Risk & Governance Specialist
Cyber Risk & Governance Specialist

Preferred Materials, Inc. in • Lutz (FL)

Hybrid
USD 110,000 - 160,000
Competitive pay
Medical benefits
Retirement plan
+2
Senior GRC & Information Security Lead
Senior GRC & Information Security Lead

Dorsey & Whitney LLP • Phoenix (AZ)

On-site
USD 140,000 - 180,000
Health benefits
Paid time off
Parental leave