Security Governance Risk & Compliance (GRC) Analyst

Virtru

Washington (District of Columbia)

Hybrid

USD 130,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible PTO policy
Learning & Development stipend
Headspace access
401K contribution
Stock options

Job summary

Virtru seeks a Security Governance Risk & Compliance Analyst to lead compliance programs across FedRAMP, SOC 2, PCI DSS, HIPAA, GDPR, and related standards. You’ll manage controls for cloud and SaaS platforms, design automation for evidence collection, and drive risk assessments across business units.

You’ll own CMMC integration, support vendor security reviews, and collaborate with cross-functional teams to deliver secure, scalable solutions while enabling secure sharing of data.

Qualifications

  • Minimum of 5+ years of information security, IT audit and/or IT risk management, or GRC analyst/engineer experience.
  • Deep understanding of CMMC, NIST 800-53 & 800-171, FedRAMP, SOC 2, PCI, and other privacy compliance frameworks.
  • Technical acumen with modern cloud technologies (AWS, GCP, Azure) and familiarity with GRC tools and SIEMs.
  • Strong relationship-building skills to translate risk to various levels of the organization.
  • Experience training and coaching teams to become better security and privacy practitioners.

Responsibilities

  • Manage and implement complex controls frameworks for large systems including cloud infrastructure and SaaS services (GCP, AWS, GitHub, Okta).
  • Design and develop automation solutions for evidence collection across cloud infrastructure, endpoints, and SaaS services.
  • Conduct risk assessments across business units, identify findings, and recommend remediation strategies.
  • Participate in incident response activities, providing risk analysis and remediation support.
  • Assist or implement automated controls to support risk mitigation across units.
  • Incorporate CMMC certification into Virtru’s compliance assessments and monitoring.
  • Facilitate vendor onboarding and annual review processes by evaluating security of partners.
  • Enhance the team with your individuality, spirit, and love of learning.

Skills

InfoSec experience
GRC/program governance
Risk management
Cloud platforms
Stakeholder communication

Tools

Hyperproof
Vanta
Drata
Datadog
Splunk
AWS
GCP
Azure

Job description

Security Governance Risk & Compliance (GRC) Analyst

Washington, DC - Remote

About Virtru:

While the rest of the security industry obsesses over locking data down to prevent it from being lost or stolen, we’re doing something fundamentally different at Virtru. We’re setting data free so that you can intentionally share it with others, but without sacrificing security, privacy, or control.

We’ve created both a suite of powerful data protection applications and an open platform that’s sparking an ecosystem of innovation. Through the Trusted Data Format (TDF) open standard, we’re not just protecting data; we’re creating a new paradigm where security enables sharing rather than preventing it.

Think of us as the Android of data protection: a robust platform with an open core that developers and partners can build upon, coupled with our own best‑in‑class applications that showcase what’s possible when you reimagine security from the ground up.

Backed by Iconiq Capital, Bessemer Venture Partners, Foundry Capital, and Tiger Global, we’re helping Fortune 500 companies and government agencies discover that true data security means having the freedom to share, collaborate, and innovate—without compromise.

Compensation: $130,000-$170,000/year

Here at Virtru you’ll help build a cutting‑edge security compliance program aligned with FedRAMP, SOC 2, PCI, HIPAA, GDPR, and any other security/privacy framework you can think of, while getting your hands on some of today’s most important tools and tech like Kubernetes, GCP, AWS, Terraform. We put a high value on input from everyone on our team. Your voice will have a significant impact. With a constantly growing customer base, there is no shortage of challenging and exciting scaling/optimization work to ensure that we can provide the most secure and performant service.

As a GRC Analyst at Virtru, you will be the primary point of contact for compliance‑related inquiries. You will lead and manage the organization’s efforts to achieve and maintain CMMC compliance by conducting gap analyses and developing a roadmap to address compliance requirements. You will also play a vital role in supporting our existing FedRAMP, SOC 2, and PCI DSS compliance.

Responsibilities
  • Manage and implement complex controls frameworks for large systems, including cloud infrastructure and SaaS services (GCP, AWS, GitHub, Okta, etc.).
  • Design and develop automation solutions for evidence collection across cloud infrastructure, endpoints, and SaaS services.
  • Conduct risk assessments across business units and processes, identify risk findings, and recommend remediation and risk‑mitigation strategies.
  • Participate in incident response activities, providing risk analysis and remediation support as needed.
  • Assist or implement automated controls to support risk mitigation efforts across various business units with stakeholders.
  • Incorporate CMMC certification into Virtru’s slate of compliance assessments and ongoing monitoring activities (FedRAMP, SOC 2, PCI).
  • Facilitate the third‑party vendor on‑boarding and annual review process by evaluating the security of current and prospective partners.
  • Enhance the team with your individualism, spirit, and love of learning.
Skills that Will Help You Thrive
  • Minimum of 5+ years of information security, IT audit and/or IT risk management, or GRC analyst/engineer experience.
  • Deep understanding of at least a few of the following: CMMC, NIST 800‑53 & 800‑171, FedRAMP, SOC 2, PCI, and/or other global privacy compliance frameworks.
  • Technical acumen: strong understanding of modern cloud technologies (AWS, GCP, Azure, etc.) and familiarity with GRC tools (Hyperproof, Vanta, Drata, etc.) and SIEM tools (Datadog, Splunk).
  • You’re a relationship builder and have worked with both business and technical risk and understand how to translate risk to various levels of the organization.
  • Experience training and coaching teams to become better security and privacy practitioners.
  • Like working on an autonomous agile team. At Virtru, you will have ownership of security, but you’ll collaborate with everyone to ensure we produce and implement the right solutions.
  • Ability to resolve conflicts and drive issues to completion.
  • Work independently with little or no supervision while maintaining a high level of efficiency.
Values that Will Set You Up for Success
  • Thinking outside of the box to respectfully challenge teammates and managers in pursuit of excellence.
  • Strong sense of urgency with an action‑oriented mindset.
  • Ability to collaborate and adapt to shifting priorities as business needs evolve.
  • Comfortable with asynchronous communication including Slack, email, Zoom, etc.
Benefits
  • Flexible PTO policy— we strongly encourage you to take time off (in addition to 14 holidays) to ensure that you are getting the proper time needed to unplug and recharge.
  • $1,500 annual Learning & Development stipend focused on providing you the resources to continually learn and professionally grow.
  • Frequent company‑sponsored team celebrations that provide ample opportunities to connect with teammates.
  • Access to an Employee Assistance Program.
  • Access to Headspace, a mental health app tailored to your specific needs.
  • A flat 3% contribution to your retirement account.
  • High degree of flexibility— need to take care of a family emergency? We give you the time and space to do so.
Additional Perks
  • Competitive compensation.
  • Generous parental, medical, and bereavement policies.
  • 401 K contribution and stock options.
  • Full medical, dental, and vision benefits.
  • New‑Hire swag and IT welcome boxes.
  • Structured semi‑annual 360° performance reviews.

Virtru is committed to building an inclusive environment for people of all backgrounds and everyone is encouraged to apply. Virtru is an Equal Opportunity Employer and does not discriminate on the basis of race, color, gender, religion, disability, national origin, protected veteran status, age, or any other status protected by applicable national, federal, state, or local law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Governance Risk & Compliance (GRC) Analyst
Security Governance Risk & Compliance (GRC) Analyst

Virtru • United States

On-site
USD 130,000 - 170,000
Flexible PTO
$1,500 learning & development stipend
Team celebrations
+4
Technical Program Manager - Security Clearance Required
Technical Program Manager - Security Clearance Required

Virtru • Washington

On-site
USD 170,000 - 220,000
Flexible PTO
Learning stipend
Headspace access
+4
Technical Program Manager - Security Clearance Required
Technical Program Manager - Security Clearance Required

Virtru • Washington

Hybrid
USD 130,000 - 170,000
Flexible PTO
Learning & Development Stipend
Team celebrations
+4
Forward Deployed Engineer - Security Clearance Required
Forward Deployed Engineer - Security Clearance Required

Virtru • Livermore (KY)

On-site
USD 170,000 - 220,000
Flexible PTO policy
Learning & Development stipend
Home-Office stipend
+1
Senior Full Stack Engineer
Senior Full Stack Engineer

Virtru • Washington

Hybrid
USD 150,000 - 170,000
Flexible PTO
Learning stipend
Team celebrations
+3
Operations Analyst
Operations Analyst

Virtru • Washington

Hybrid
USD 110,000 - 130,000
Flexible PTO
Learning & Development stipend
Team celebrations
+3
Solutions Architect
Solutions Architect

Virtru • Washington

On-site
USD 200,000 - 230,000
Flexible PTO
Learning & Development stipend
Team celebrations
+4
Global Public Sector Customer Success Manager - National Security Ecosystem
Global Public Sector Customer Success Manager - National Security Ecosystem

Virtru • Washington

On-site
USD 180,000 - 200,000
Flexible PTO policy
Learning & Development stipend
Headspace access
+3
Solutions Architect
Solutions Architect

Virtru • Washington

Hybrid
USD 200,000 - 230,000
Flexible PTO policy
Annual Learning & Development Stipend
Company-sponsored team celebrations
+4
Sr. Product Manager
Sr. Product Manager

Virtru • Washington

Hybrid
USD 165,000 - 200,000
Flexible PTO
Learning & Development stipend
Headspace access
+1