GRC Analyst: Cyber Defense Risk & Compliance

Chaos Industries

Washington

On-site

USD 130,000 - 170,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Health benefits
401k match
FSA/HSA
Life insurance
Free daily lunch

Job summary

CHAOS Industries is recruiting a senior GRC professional to own and mature our cybersecurity risk management program across multiple departments. You will establish governance, policy, and control frameworks aligned to NIST, ISO, and DoD requirements, and coordinate audits with Legal, Compliance, and IT teams.

You will design risk processes, maintain the risk register, and drive security maturity beyond compliance while translating broad requirements into practical controls.

Qualifications

  • Bachelor’s degree or equivalent in CS/IS or related field, or equivalent practical experience.
  • Deep knowledge of NIST CSF, NIST RMF, ISO/IEC 27000 series, UK Cyber Essentials, CMMC/NIST 800-171, NIST 800-53.
  • Experience selecting, implementing, or administering GRC tooling and workflows.
  • Exposure to governance, risk, and compliance frameworks across security, privacy, and quality management domains.
  • Familiarity with OT/ICS security concepts.
  • Minimum of 5 years hands-on GRC/compliance experience in a DoD environment or military service.
  • Supported third-party or certification audits from evidence collection to closure.
  • Ability to design real, working controls tailored to an organization.

Responsibilities

  • Own risk assessments across departments and maintain the centralized risk register.
  • Design and maintain a unified control framework tailored to CHAOS Industries’ environment, including MTD, RPO, and RTO for critical systems.
  • Write and maintain policy that goes beyond minimum compliance, building security maturity.
  • Manage GRC tooling and workflows to support risk assessments, control monitoring, and reporting.
  • Coordinate audits, evidence requests, customer reviews, and remediation tracking with Legal, Compliance, and IT teams.
  • Act as a bridge between departments to develop security and compliance requirements.
  • Report to the Program Director and executives on risk posture and program maturity.
  • Onsite presence required 4 days per week.
  • Travel up to 25% to support Manufacturing and Physical Security control validation.
  • Support cybersecurity risk management with customers, vendors, and subcontractors.

Skills

GRC
NIST RMF
NIST CSF
ISO 27000 series
CMMC/NIST 800-171
Audit coordination

Education

Bachelor’s degree in CS/IS or related field

Tools

GRC tooling

Job description

CHAOS Industries is recruiting a senior GRC professional to own and mature our cybersecurity risk management program across multiple departments. You will establish governance, policy, and control frameworks aligned to NIST, ISO, and DoD requirements, and coordinate audits with Legal, Compliance, and IT teams.

You will design risk processes, maintain the risk register, and drive security maturity beyond compliance while translating broad requirements into practical controls.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC Analyst: Cyber Risk, Compliance & Audit Leadership
GRC Analyst: Cyber Risk, Compliance & Audit Leadership

Chaos, Inc. • Washington, Northern (KY)

Hybrid
USD 120,000 - 150,000
Health benefits 100% paid by company
401k with company match
Free daily lunch
+2
GRC & Security Risk Lead (Hybrid) — Build Mature Program
GRC & Security Risk Lead (Hybrid) — Build Mature Program

CHAOS Industries • Washington

On-site
USD 110,000 - 150,000
Health benefits
401k match
Free daily lunch
+3
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
GRC Analyst: Cyber Risk & Compliance Expert
GRC Analyst: Cyber Risk & Compliance Expert

Cone Health • Greensboro (NC)

On-site
USD 110,000 - 140,000
GRC Consultant: Cybersecurity Compliance & Risk Strategy
GRC Consultant: Cybersecurity Compliance & Risk Strategy

Cybershield Risk Management Ltd • Indiana (PA)

On-site
USD 70,000 - 110,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Senior GRC Analyst
Senior GRC Analyst

Averity • New York (NY)

On-site
USD 90,000 - 140,000
GRC Specialist (Governance, Risk & Compliance)
GRC Specialist (Governance, Risk & Compliance)

360CyberX • United States

On-site
USD 70,000 - 90,000
Senior Cybersecurity Risk & GRC Leader
Senior Cybersecurity Risk & GRC Leader

mTrade, LLC. • Oxford (MS)

On-site
USD 110,000 - 160,000
Cybersecurity GRC Professional
Cybersecurity GRC Professional

duvari group • United States

On-site
USD 120,000 - 190,000