GRC & Security Risk Lead (Hybrid) — Build Mature Program

CHAOS Industries

Washington (District of Columbia)

On-site

USD 110,000 - 150,000

Full time

10 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health benefits
401k match
Free daily lunch
No meeting Fridays
Unlimited PTO
Relocation assistance

Job summary

CHAOS Industries is seeking a Governance, Risk & Compliance Analyst to mature the GRC program across the organization. You will establish governance, policies, standards, and accountability, and translate broad requirements into practical controls.

You will work with IT, Cybersecurity, Physical Security, and Manufacturing teams to drive risk-based decisions. The role requires a minimum of 5 years in GRC/compliance, DoD exposure, and strong knowledge of NIST and ISO frameworks.

Qualifications

  • Bachelor's degree or equivalent in CS/cybersecurity/IT or related field.
  • Minimum 5 years hands-on GRC or compliance experience.
  • DoD experience or military service preferred.
  • Deep knowledge of NIST CSF, RMF, ISO 27000, UK Cyber Essentials, CMMC/NIST 800-171, NIST 800-53.
  • Experience with third-party audits and evidence collection.
  • Ability to design real, working controls tailored to an organization.

Responsibilities

  • Own risk assessments and centralized risk register.
  • Design and maintain a unified control framework tailored to CHAOS Industries’ environment.
  • Write policy beyond minimum compliance.
  • Manage GRC tooling and related workflows.
  • Prepare for and run third-party and certification audits, including evidence collection and auditor liaison.
  • Act as glue between departments to translate requirements into security controls.
  • Report risk posture and audit status to leadership.
  • Onsite presence four days a week; travel up to 25%.
  • Support security and compliance requirements with Legal, Compliance, IT, and business leaders.

Skills

GRC knowledge
Policy writing
Stakeholder communication
Auditing

Education

Bachelor's degree in CS/cybersecurity/IT or related field

Tools

GRC tooling

Job description

CHAOS Industries is seeking a Governance, Risk & Compliance Analyst to mature the GRC program across the organization. You will establish governance, policies, standards, and accountability, and translate broad requirements into practical controls.

You will work with IT, Cybersecurity, Physical Security, and Manufacturing teams to drive risk-based decisions. The role requires a minimum of 5 years in GRC/compliance, DoD exposure, and strong knowledge of NIST and ISO frameworks.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Strategic GRC & Cyber Risk Analyst
Strategic GRC & Cyber Risk Analyst

Chaos, Inc. • El Segundo (CA)

Hybrid
USD 120,000 - 150,000
Health benefits
401k with company match
Free daily lunch
+2
Defense GRC & Cyber Risk Analyst
Defense GRC & Cyber Risk Analyst

CHAOS Industries • Los Angeles (CA)

On-site
USD 120,000 - 150,000
Health benefits
401k match
FSA/HSA
+5
GRC Analyst — Security by Design for Defense
GRC Analyst — Security by Design for Defense

CHAOS Industries • El Segundo (CA)

On-site
USD 120,000 - 150,000
Health benefits
401k with company match
Free daily lunch
+4
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
GRC Specialist (Governance, Risk & Compliance)
GRC Specialist (Governance, Risk & Compliance)

360CyberX • United States

On-site
USD 70,000 - 90,000
GRC Security Analyst: Automate Compliance & Risk
GRC Security Analyst: Automate Compliance & Risk

Discord • San Francisco (CA)

Hybrid
USD 144,000 - 162,000
Equity
Relocation assistance
IT GRC Lead Analyst
IT GRC Lead Analyst

Westfield Insurance • Westfield Center (OH)

Hybrid
USD 90,000 - 120,000
Hybrid GRC Analyst: Risk, Compliance & Policy
Hybrid GRC Analyst: Risk, Compliance & Policy

Benesch, Friedlander, Coplan & Aronoff • Cleveland (OH)

Hybrid
USD 99,000 - 120,000
Hybrid schedule
Benefits package
Hybrid GRC Cybersecurity Analyst: Lead Risk & Compliance
Hybrid GRC Cybersecurity Analyst: Lead Risk & Compliance

Request Technology, LLC • Chicago (IL)

Hybrid
USD 110,000 - 180,000
GRC Analyst - Hybrid: Risk, Compliance & Security
GRC Analyst - Hybrid: Risk, Compliance & Security

Benesch Law • Cleveland (OH)

Hybrid
USD 99,000 - 120,000
Discretionary bonus
Comprehensive benefits package