GRC Lead

NextgenID

Fairfax, Northern (VA, KY)

Hybrid

USD 95,000 - 120,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

NextgenID is seeking a GRC Lead to own governance, risk, and compliance end-to-end at its Fairfax, VA headquarters. This hands-on leadership role combines program ownership with senior, judgment-heavy work in FedRAMP, 3PAO coordination, and risk management.

The role requires US citizenship and onsite presence; a 5+ year track record in GRC and federal frameworks, plus direct FedRAMP/FISMA experience, is expected. You will guide a GRC Analyst and collaborate with the CTO & EVP.

Qualifications

  • Five or more years in governance, risk, and compliance with program ownership.
  • Experience owning a federal authorization or audit program through a 3PAO or independent assessment.
  • Built and maintained a risk register and a POA&M process and defended risk decisions.
  • Interpreted NIST 800-53 and NIST 800-63 (identity assurance) and translated to policy/evidence.
  • Experience with GRC tooling (Vanta) and vulnerability tools (Qualys/Nessus).

Responsibilities

  • Lead compliance program across FedRAMP, FISMA, Kantara/NIST 800-63, UK DIATF/DVS, SOC 2, and ADA.
  • Own external assessments and manage 3PAO relationships and certification bodies.
  • Maintain risk register and POA&M with documented risk decisions.
  • Provide evidence to assessors and customers and coordinate with engineering/Legal.

Skills

GRC leadership
FedRAMP knowledge
Risk management
Audit coordination
Third-party assessments

Tools

Vanta
Qualys
OSCAL

Job description

Location: Onsite – Fairfax, VA · U.S. Citizen Required (FedRAMP / Federal Customer)

Type: Full Time

NextgenID is hiring a GRC Lead to own our governance, risk, and compliance program end-to-end. We verify and credential identity at the highest assurance level (IAL3) for federal agencies and enterprises, which means our authorizations — FedRAMP, Kantara, UK digital identity (DIATF/DVS), and the security assurances our customers depend on — are core to the business. You own the compliance calendar, the risk register, the audit and assessment relationships, and the evidence that proves our posture. You lead a GRC Analyst and report to the CTO & EVP. This is a working leadership role: you set the program, and you also do the senior, judgment-heavy work yourself.

Salary Range: $95,000–$120,000

Role Fit & Non-Negotiables
  • Onsite at our Fairfax, VA headquarters. This is a hands-on leadership role, not remote.
  • U.S. citizen, required for FedRAMP and federal-customer obligations.
  • Five or more years in governance, risk, and compliance, including ownership of a formal authorization or audit program.
  • Direct experience with FedRAMP, FISMA, or an equivalent federal framework, and with third-party (3PAO) assessments.
  • Able to make and defend risk decisions and to sign off on evidence that goes to assessors and customers.
What You Will Own (90 to 180 Day Outcomes)
  • A single, authoritative compliance calendar and program plan across FedRAMP, Kantara, UK DVS, SOC 2, and customer questionnaires.
  • The FedRAMP 20x authorization effort carried toward submission, including the 3PAO relationship, Trust Center publication, and machine-readable (OSCAL) control package.
  • A current, governed risk register and monthly POA&M process, with documented risk decisions and compensating controls.
  • Kantara 800-63A (IAL3) certification maintained, with a planned path from Rev 3 to Rev 4.
  • A functioning GRC tooling and evidence pipeline (Vanta) that keeps documentation and submissions current with less manual effort.
  • A GRC Analyst onboarded, directed, and delivering, with the departing analyst’s and intern’s workstreams fully absorbed.
Core Responsibilities

Compliance Program Leadership — own the program, the calendar, and the standard.

  • Own the compliance calendar and program plan across FedRAMP, FISMA, Kantara/NIST 800-63, UK DIATF/DVS, SOC 2, and ADA.
  • Set GRC policy, standards, and process, and keep them current and version-controlled.
  • Report compliance status, risk posture, and audit readiness to the CTO and leadership.

Authorizations & External Assessments — lead audits, 3PAOs, and certification bodies.

  • Lead FedRAMP 20x authorization: 3PAO selection and relationship, ATO timeline, Trust Center publication, and the OSCAL submission strategy.
  • Own the Kantara certification program (800-63A, IAL3) and the Rev 3 to Rev 4 transition strategy.
  • Own the UK DVS / DIATF certification, including scoping and gap-assessment leadership.

Risk Management — own the risk register and the decisions that carry risk.

  • Maintain the enterprise and vendor risk register and govern the monthly POA&M process.
  • Make and document risk decisions, risk adjustments, and compensating controls, including vendor vulnerabilities.
  • Set vulnerability remediation priorities and pentest readiness with the engineering and DevSecOps leads.

Vendor & Customer Assurance — prove our posture to third parties without slowing the business.

  • Own third-party and vendor risk assessments across our tooling and supply chain.
  • Own the security-questionnaire program (final review and sign-off) and represent our posture to customers and prospects.
  • Partner with Growth and Legal on assurance commitments and trust-center content.

Team & Tooling — deliver the program through the analyst and the toolchain.

  • Lead, mentor, and prioritize the work of the GRC Analyst and absorb the departing intern’s workstreams.
  • Own GRC tooling strategy and the evidence pipeline (Vanta, Qualys, OSCAL).
  • Coordinate engineering, DevSecOps, operations, and legal contributors to compliance deliverables.
What You Must Have Already Done
  • Owned a federal authorization or audit program (FedRAMP, FISMA, StateRAMP, or equivalent) through a 3PAO or independent assessment.
  • Built and maintained a risk register and a POA&M process, and defended risk decisions to an assessor or customer.
  • Interpreted a control framework (NIST 800-53, 800-63, or ISO 27001) and translated it into policy, procedure, and evidence.
  • Managed an external assessor or certification-body relationship end to end.
  • Led or mentored analysts and coordinated cross-functional contributors to a compliance deadline.
Required Qualifications
  • Five or more years in governance, risk, and compliance, security compliance, or audit, with program ownership.
  • Direct experience with FedRAMP and/or FISMA, including continuous monitoring (ConMon) and 3PAO assessment.
  • Working command of NIST SP 800-53 and NIST SP 800-63 (identity assurance), and of risk-assessment methodology.
  • Experience owning a risk register, a POA&M process, and a vendor-risk program.
  • Experience managing external assessors, auditors, or certification bodies.
  • Experience with GRC or compliance-automation tooling (Vanta or similar) and vulnerability tools (Qualys or Nessus).
  • Ability to make, document, and defend risk decisions.
  • Excellent written and verbal communication for assessors, customers, and executives.
  • Must be able to work onsite in Fairfax, VA; U.S. citizen (FedRAMP / federal customer).
Preferred Qualifications
  • CISA, CRISC, CISSP, or CISM certification.
  • Experience with Kantara / NIST 800-63 identity assurance (IAL2 / IAL3) certification.
  • Experience with international identity frameworks (UK DIATF / DVS) or ISO 27001 certification.
  • Experience with OSCAL or machine-readable control packages for FedRAMP 20x.
  • Background in a federal-contractor or IDaaS / identity-security environment.
  • Familiarity with SOC 2 and ADA / Section 508 accessibility assessments.
  • You own the calendar in your head: you know what is due, to whom, and what evidence proves it.
  • You make risk calls and defend them with documented reasoning, not hand-waving.
  • You turn a framework into a short list of what has to be done, and get it done.
  • You keep assessors and customers confident because your evidence is clean and current.
  • You lead through other teams, coordinating engineering and operations without owning their headcount.
What Success Looks Like
  • FedRAMP 20x reaches submission on schedule, with a published Trust Center and a machine-readable control package.
  • Kantara IAL3 certification stays current, with a credible Rev 4 transition plan.
  • A single risk register and monthly POA&M process run on cadence, with documented risk decisions.
  • Customer questionnaires and external assessments are answered accurately and on time, with no material findings from poor evidence.
  • The GRC Analyst is productive and the departing analyst’s and intern’s workstreams continue without gaps.
Why NextgenID

NextgenID builds the compliance-grade identity infrastructure that federal agencies and enterprises rely on to verify and credential identity at IAL3. Compliance is not overhead here — it is the product’s license to operate. As GRC Lead, you own the authorizations and the evidence that let us sell and deliver, and you will see your work directly in every certification we hold and every customer we win. For the right person, this is the path to a GRC Manager or Director role as the program grows.

NextgenID focuses on improving the efficiency and speed of mission critical, high assurance identity enrollment and credentialing operations that are essential to hundreds of millions of users worldwide.

Our technologies are engineered to dramatically reduce the time and cost of capturing accurate data when creating a digital identity. Our industry-neutral solutions revolve around "Supervised Remote-Identity Proofing" to automatically, securely and "remotely" perform all proofing, enrollment and credentialing processes and workflows for our customers. The industry is taking notice as we are now working with some of the largest agencies in the US Defense, intelligence, Civil, State and Local government markets, as well as other national governments and commercial organizations throughout the world.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst
GRC Analyst

NextgenID • Fairfax (VA), Northern (KY)

Hybrid
USD 75,000 - 95,000
QA Manager
QA Manager

NextgenID • Fairfax (VA), Northern (KY)

Hybrid
USD 115,000 - 165,000
DevSecOps Manager (Gov / FedRAMP Focus)
DevSecOps Manager (Gov / FedRAMP Focus)

NextgenID • Fairfax (VA)

On-site
USD 120,000 - 160,000
Onsite GRC Analyst: FedRAMP & Federal Compliance
Onsite GRC Analyst: FedRAMP & Federal Compliance

NextgenID • Fairfax (VA), Northern (KY)

Hybrid
USD 75,000 - 95,000
GRC Lead: Federal Compliance & Risk (Onsite)
GRC Lead: Federal Compliance & Risk (Onsite)

NextgenID • Fairfax (VA), Northern (KY)

Hybrid
USD 95,000 - 120,000
GRC Analyst - Public Sector
GRC Analyst - Public Sector

Apply • Washington, Northern (KY)

Hybrid
USD 110,000 - 140,000
GRC Analyst – Public Sector
GRC Analyst – Public Sector

Jobtailor • California (MO)

On-site
USD 120,000 - 180,000
GRC Program Manager (FedRAMP & Compliance)
GRC Program Manager (FedRAMP & Compliance)

Port.io • Boston (MA)

On-site
USD 120,000 - 150,000
Compliance Operations Lead
Compliance Operations Lead

GovSignals • New York (NY)

On-site
USD 140,000 - 190,000
100% employer-paid medical, vision, and dental
Unlimited PTO
Equity in a fast-growing startup
GRC Engineer (NIST)
GRC Engineer (NIST)

Jobless • Northern (KY)

Hybrid
USD 90,000 - 130,000
Career Development
Role-Related Training
Competitive Compensation
+2