Senior GRC & Third-Party Risk Lead, Data Protection

Peraton

Herndon (VA)

On-site

USD 104,000 - 166,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Peraton is seeking a Senior GRC / Third-Party Risk / Data Protection Analyst in the United States to own the governance, risk, and compliance engine for the engagement, including policy creation, control testing, and POA&Ms management, and to oversee third-party risk and data protection programs for health‑related contract work.

The role involves working with security leadership, vendors, and incident response teams to ensure an audit-ready posture against NIST SP 800‑53 Rev.

Qualifications

  • Bachelor's degree in information systems, cybersecurity, or business with security concentration (or 4 extra years of relevant experience).
  • 8+ years in security governance, risk, and compliance, third‑party risk management, or data protection.
  • Active CISA or CGRC certification.
  • Experience with NIST SP 800‑53 Rev. 5 control assessments and POA&M lifecycle.
  • Experience with third‑party/vendor security risk management including SIG/CAIQ frameworks.

Responsibilities

  • Own policy and control documentation; write and maintain security policies, procedures, and standards.
  • Test controls, perform gap analysis, and manage POA&M remediation and closure.
  • Keep program audit-ready by maintaining evidence libraries and control mappings.
  • Run third‑party security risk management: vendor due diligence, assessments, reviews.
  • Lead data protection: classify data, apply data handling controls including encryption and access controls.
  • Support insider threat program and coordinate with privacy, HR, and legal teams.
  • Comply with IRS Publication 1075 and ARC‑AMPE obligations and participate in incident response rotation.

Skills

GRC governance
Risk management
Compliance testing
Policy writing
DLP / data protection

Education

Bachelor's degree in information systems or cybersecurity

Tools

NIST SP 800-53 Rev.5
GRC platforms
CAIQ/SIG questionnaires
Microsoft Purview / DLP

Job description

Peraton is seeking a Senior GRC / Third-Party Risk / Data Protection Analyst in the United States to own the governance, risk, and compliance engine for the engagement, including policy creation, control testing, and POA&Ms management, and to oversee third-party risk and data protection programs for health‑related contract work.

The role involves working with security leadership, vendors, and incident response teams to ensure an audit-ready posture against NIST SP 800‑53 Rev.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC & Third-Party Risk Lead – Data Protection
Senior GRC & Third-Party Risk Lead – Data Protection

Peraton • Reston (VA)

On-site
USD 104,000 - 166,000
Senior GRC & Data Protection Lead
Senior GRC & Data Protection Lead

Peraton • Northern (KY)

Hybrid
USD 104,000 - 166,000
Senior GRC & Data Protection Analyst — Third-Party Risk
Senior GRC & Data Protection Analyst — Third-Party Risk

Peraton Labs • United States

On-site
USD 104,000 - 166,000
Medical insurance
Dental insurance
Vision insurance
+8
Senior GRC & Privacy Leader: Risk, Compliance & Security
Senior GRC & Privacy Leader: Risk, Compliance & Security

O'Neil Digital Solutions, LLC • Plano (TX)

On-site
USD 150,000 - 190,000
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
Senior GRC Analyst: TPRM & Human Risk
Senior GRC Analyst: TPRM & Human Risk

Gilder Search Group • Phoenix (AZ)

On-site
USD 80,000 - 120,000
Comprehensive Benefits Package
Discretionary Annual Bonus
Flexible Spending Accounts
Senior Third-Party Risk Analyst – Security GRC
Senior Third-Party Risk Analyst – Security GRC

Anthropic • United States

Hybrid
USD 255,000 - 270,000
Competitive compensation
Generous vacation & parental leave
Equity donation matching
+1
Governance, Risk & Compliance Analyst (Third-Party Risk Analyst)
Governance, Risk & Compliance Analyst (Third-Party Risk Analyst)

recruit22 • Chicago (IL)

On-site
USD 65,000 - 90,000
Senior GRC Analyst - IT Risk & Compliance Leader
Senior GRC Analyst - IT Risk & Compliance Leader

3M HEALTHCARE • San Diego (CA)

On-site
USD 85,000 - 122,000
Competitive salary
Bonus opportunities
Tuition assistance
+5
GRC Analyst: Third-Party Risk & Vendor Oversight
GRC Analyst: Third-Party Risk & Vendor Oversight

United States Digital Space LLC • Boston (MA)

On-site
USD 70,000 - 110,000