Remote GRC Analyst: CMMC, FedRAMP, SOC 2 & PCI

Virtru

Washington (District of Columbia)

Hybrid

USD 130,000 - 170,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Flexible PTO policy
Learning & Development stipend
Headspace access
401K contribution
Stock options

Job summary

Virtru seeks a Security Governance Risk & Compliance Analyst to lead compliance programs across FedRAMP, SOC 2, PCI DSS, HIPAA, GDPR, and related standards. You’ll manage controls for cloud and SaaS platforms, design automation for evidence collection, and drive risk assessments across business units.

You’ll own CMMC integration, support vendor security reviews, and collaborate with cross-functional teams to deliver secure, scalable solutions while enabling secure sharing of data.

Qualifications

  • Minimum of 5+ years of information security, IT audit and/or IT risk management, or GRC analyst/engineer experience.
  • Deep understanding of CMMC, NIST 800-53 & 800-171, FedRAMP, SOC 2, PCI, and other privacy compliance frameworks.
  • Technical acumen with modern cloud technologies (AWS, GCP, Azure) and familiarity with GRC tools and SIEMs.
  • Strong relationship-building skills to translate risk to various levels of the organization.
  • Experience training and coaching teams to become better security and privacy practitioners.

Responsibilities

  • Manage and implement complex controls frameworks for large systems including cloud infrastructure and SaaS services (GCP, AWS, GitHub, Okta).
  • Design and develop automation solutions for evidence collection across cloud infrastructure, endpoints, and SaaS services.
  • Conduct risk assessments across business units, identify findings, and recommend remediation strategies.
  • Participate in incident response activities, providing risk analysis and remediation support.
  • Assist or implement automated controls to support risk mitigation across units.
  • Incorporate CMMC certification into Virtru’s compliance assessments and monitoring.
  • Facilitate vendor onboarding and annual review processes by evaluating security of partners.
  • Enhance the team with your individuality, spirit, and love of learning.

Skills

InfoSec experience
GRC/program governance
Risk management
Cloud platforms
Stakeholder communication

Tools

Hyperproof
Vanta
Drata
Datadog
Splunk
AWS
GCP
Azure

Job description

Virtru seeks a Security Governance Risk & Compliance Analyst to lead compliance programs across FedRAMP, SOC 2, PCI DSS, HIPAA, GDPR, and related standards. You’ll manage controls for cloud and SaaS platforms, design automation for evidence collection, and drive risk assessments across business units.

You’ll own CMMC integration, support vendor security reviews, and collaborate with cross-functional teams to deliver secure, scalable solutions while enabling secure sharing of data.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC Security Analyst: Compliance, Risk & Controls Lead
GRC Security Analyst: Compliance, Risk & Controls Lead

Virtru • United States

Hybrid
USD 130,000 - 170,000
Flexible PTO
Learning stipend
Team events
+4
Remote GRC Analyst — Security & Compliance
Remote GRC Analyst — Security & Compliance

Webhosting • San Francisco (CA), New York (NY)

Hybrid
USD 134,000 - 202,000
GRC & Compliance Strategist for Cloud Security & Audits
GRC & Compliance Strategist for Cloud Security & Audits

Vercel Inc. • United States

Hybrid
USD 134,000 - 202,000
Equity
Healthcare package
Mentorship & events
+2
GRC & Risk Analyst – SOC 2, ISO 27001, PCI
GRC & Risk Analyst – SOC 2, ISO 27001, PCI

CloudData • United States

On-site
USD 80,000 - 100,000
Remote GRC Analyst: Cloud Security & Risk
Remote GRC Analyst: Cloud Security & Risk

Upwind Security, Inc. • Northern (KY)

Hybrid
USD 70,000 - 110,000
Security Governance Risk & Compliance (GRC) Analyst
Security Governance Risk & Compliance (GRC) Analyst

Virtru • Washington

Hybrid
USD 130,000 - 170,000
Flexible PTO policy
Learning & Development stipend
Headspace access
+2
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
GRC Lead: Risk & Compliance for Tech Platforms
GRC Lead: Risk & Compliance for Tech Platforms

Averity • New York (NY)

On-site
USD 90,000 - 140,000
Remote Senior Security Compliance Lead - PCI DSS & FedRAMP
Remote Senior Security Compliance Lead - PCI DSS & FedRAMP

Entrust • United States

On-site
USD 120,000 - 150,000
Fully remote
GRC Engineering Manager: Lead Secure Cloud Compliance
GRC Engineering Manager: Lead Secure Cloud Compliance

Workstreet • Northern (KY)

Hybrid
USD 150,000 - 190,000
Career Development
Role-Related Training
Competitive Compensation
+2