Senior GRC & Third-Party Risk Lead – Data Protection

Peraton

Reston (VA)

On-site

USD 104,000 - 166,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Peraton is seeking a Senior GRC / Third-Party Risk / Data Protection Analyst to own the governance, risk, and compliance engine for the engagement, including policy, control testing, POA&Ms, and third-party security risk management. The role covers data protection, insider threat, and privacy obligations across California health benefits programs.

You will collaborate with security leadership, vendors, and incident response teams to maintain an audit-ready posture against NIST 800-53 Rev.

Qualifications

  • Bachelor's degree in a relevant field or 4 years of additional experience.
  • 8+ years in security governance, risk, and compliance or data protection.
  • Active CISA or CGRC certification.
  • Experience assessing controls against NIST SP 800-53 Rev. 5 and POA&Ms lifecycle.
  • Third-party risk management experience with questionnaire frameworks like SIG/CAIQ.
  • Data classification and data-flow mapping with enterprise DLP platforms.
  • Precise compliance writing and knowledge of a GRC platform.

Responsibilities

  • Own policy and control documentation, including standards and control narratives.
  • Test controls, perform gap analysis, and manage POA&Ms through remediation.
  • Maintain audit-ready evidence and support independent assessments as evidence provider.
  • Lead third-party security risk management, vendor assessments, and continuous monitoring.
  • Lead data protection activities: classify data, apply controls, implement encryption and access controls.
  • Support insider threat program with use-case development and escalation procedures.
  • Support IRS Publication 1075 and ARC‑AMPE compliance activities and privacy addenda obligations.

Skills

Governance & Risk
Policy writing
Vendor risk mgmt
Data protection
DLP platforms

Education

Bachelor's degree in information systems, cybersecurity, or business with security concentration

Tools

NIST SP 800-53 Rev. 5
SIG/CAIQ frameworks
CAIQ
Purview / Netskope / Forcepoint DLP

Job description

Peraton is seeking a Senior GRC / Third-Party Risk / Data Protection Analyst to own the governance, risk, and compliance engine for the engagement, including policy, control testing, POA&Ms, and third-party security risk management. The role covers data protection, insider threat, and privacy obligations across California health benefits programs.

You will collaborate with security leadership, vendors, and incident response teams to maintain an audit-ready posture against NIST 800-53 Rev.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC & Data Protection Lead
Senior GRC & Data Protection Lead

Peraton • Northern (KY)

Hybrid
USD 104,000 - 166,000
Senior GRC & Third-Party Risk Lead, Data Protection
Senior GRC & Third-Party Risk Lead, Data Protection

Peraton • Herndon (VA)

On-site
USD 104,000 - 166,000
Senior GRC & Data Protection Analyst — Third-Party Risk
Senior GRC & Data Protection Analyst — Third-Party Risk

Peraton Labs • United States

On-site
USD 104,000 - 166,000
Medical insurance
Dental insurance
Vision insurance
+8
Senior GRC / Third-Party Risk / Data Protection Analyst
Senior GRC / Third-Party Risk / Data Protection Analyst

Peraton • Herndon (VA)

On-site
USD 104,000 - 166,000
Senior GRC / Third-Party Risk / Data Protection Analyst
Senior GRC / Third-Party Risk / Data Protection Analyst

Peraton • Reston (VA)

On-site
USD 104,000 - 166,000
External Job Posting Title Senior GRC / Third-Party Risk / Data Protection Analyst
External Job Posting Title Senior GRC / Third-Party Risk / Data Protection Analyst

Peraton • Northern (KY)

Hybrid
USD 104,000 - 166,000
Senior GRC & Privacy Leader: Risk, Compliance & Security
Senior GRC & Privacy Leader: Risk, Compliance & Security

O'Neil Digital Solutions, LLC • Plano (TX)

On-site
USD 150,000 - 190,000
Senior Third-Party Risk Analyst – Security GRC
Senior Third-Party Risk Analyst – Security GRC

Anthropic • United States

Hybrid
USD 255,000 - 270,000
Competitive compensation
Generous vacation & parental leave
Equity donation matching
+1
Governance, Risk & Compliance Analyst (Third-Party Risk Analyst)
Governance, Risk & Compliance Analyst (Third-Party Risk Analyst)

recruit22 • Chicago (IL)

On-site
USD 65,000 - 90,000
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1