Virtual Information Security Officer (GRC Delivery)

Assura, Inc.

Richmond (VA)

On-site

USD 80,000 - 110,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Assura is seeking a Virtual Information Security Officer (VISO) to deliver day-to-day security program work for Assura clients in a delivery role, under supervision. The analyst-level position focuses on executing tasks, supporting assessments, and maintaining client communication while building toward greater responsibility.

The ideal candidate has 3–5 years in cybersecurity/GRC, with familiarity in NIST 800-53 and related frameworks, and experience updating GRC deliverables.

Qualifications

  • 3-5 years of relevant experience in cybersecurity, GRC, risk, compliance, audit, or information security.
  • Familiarity with at least one regulatory framework (e.g., NIST 800-53, HIPAA, PCI DSS).
  • Strong working knowledge of NIST 800-53 across AC, IA, CM, SI, SC, AU, SA, AT.
  • Experience updating or developing GRC deliverables (policies, procedures, standards, BIA, IR/DR docs, SSPs, VM plans, TPRM docs).
  • Ability to take direction and reliably carry instructions to completion.
  • Strong writing, documentation, and client communication skills.
  • Independent research and problem-solving when gaps arise.

Responsibilities

  • Perform assigned GRC service and planning tasks under direction of a Senior VISO or GRC Director.
  • Support security assessments and identify risks, issues, and basic remediation activities under supervision.
  • Maintain and develop core deliverables: policies, procedures, standards, BIA, IR/DR docs, SSPs, VM plans, TPRM docs.
  • Facilitate client meetings, track follow-ups, and communicate clearly with clients and Assura colleagues.
  • Interact directly with clients (once trained) without constant senior intervention.
  • Support audit and compliance activities—preparing compliant documentation and remediation plans.
  • Deliver client security awareness training within established parameters (e.g., KnowBe4).
  • Manage deadlines and quality expectations, including review steps.
  • Conduct independent research to close gaps or answer questions before escalation.

Skills

GRC experience
Regulatory knowledge
Audit support
Policy writing
Client communication

Job description

Assura is seeking a Virtual Information Security Officer (VISO) to deliver day-to-day security program work for Assura clients in a delivery role, under supervision. The analyst-level position focuses on executing tasks, supporting assessments, and maintaining client communication while building toward greater responsibility.

The ideal candidate has 3–5 years in cybersecurity/GRC, with familiarity in NIST 800-53 and related frameworks, and experience updating GRC deliverables.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Officer
Information Security Officer

Assura, Inc. • Richmond (VA)

On-site
USD 80,000 - 110,000
Information Security Consultant
Information Security Consultant

Hatch IT • United States

Remote
USD 180,000 - 230,000
Senior Virtual Information Security Officer – GRC Strategy
Senior Virtual Information Security Officer – GRC Strategy

Hatch IT • United States

Remote
USD 180,000 - 230,000
InfoSec Compliance & GRC Leader (Automation)
InfoSec Compliance & GRC Leader (Automation)

Koitecc Solutions • Reston (VA), Northern (KY)

Hybrid
USD 136,000 - 184,000
Discretionary bonus
Stock awards
InfoSec Delivery Consultant: GRC & ISO 27001 Expert
InfoSec Delivery Consultant: GRC & ISO 27001 Expert

Algoappdigital • United States

On-site
USD 80,000 - 110,000
Infosec or GRC Leader
Infosec or GRC Leader

Avantdigitalnow • San Francisco (CA)

On-site
USD 95,000 - 130,000
GRC Analyst – SecOps
GRC Analyst – SecOps

Bright Defense, LLC. • United States

On-site
USD 70,000 - 90,000
Remote vCISO Manager: Lead Security & Compliance Programs
Remote vCISO Manager: Lead Security & Compliance Programs

Workstreet, Inc. • United States

On-site
USD 180,000 - 240,000
Career development
Technical training
Competitive compensation
+2
Senior Cyber Security & GRC Engineer
Senior Cyber Security & GRC Engineer

Emergent Staffing • Hartford (CT)

On-site
USD 130,000 - 180,000
Lead Global GRC & Security Compliance Program
Lead Global GRC & Security Compliance Program

Ivalua • Pittsburgh

On-site
USD 112,000 - 208,000
Medical benefits
Dental benefits
Vision benefits
+1