Demo

GRC Analyst

PKH Enterprises
Washington, DC Full Time
POSTED ON 3/3/2025
AVAILABLE BEFORE 6/3/2025

Job Description

Job Description

GRC Analyst

This opportunity is remote, but may require occasional meetings onsite. Only candidates in the National Capitol Region.

Job Summary : We are seeking a proactive and detail-oriented Cybersecurity Information Assurance Engineer (Junior) / GRC Analyst (Junior) to support the development of information systems assurance programs and enhance the organization’s governance, risk, and compliance (GRC) processes. Under general supervision, the GRC Analyst will assist in implementing security control guidelines, resolving technical issues, and supporting the development of new dashboards, metrics, and automated functionality. The successful candidate will also contribute to federal compliance initiatives, conduct market research, and help streamline cybersecurity operations through automation and policy adherence.

Key Responsibilities :

  • Assist in developing and implementing information systems assurance programs and security control guidelines to ensure compliance with cybersecurity best practices.
  • Support the resolution of technical issues, prioritization of tasks, and development of methods to enhance cybersecurity operations.
  • Prepare activity and progress reports related to information systems audits, ensuring accurate documentation of cybersecurity efforts.
  • Develop new dashboard views to support the Cybersecurity Framework (CSF) and establish performance metrics for improved reporting and decision-making.
  • Define processes for leveraging data from the Continuous Diagnostics and Mitigation (CDM) dashboard and provide support for stakeholder training on its usage.
  • Assist in the automation of existing processes using Power Apps or similar tools to improve operational efficiency.
  • Analyze and review emerging federal information security and privacy policies, directives, and mandates, ensuring timely compliance with specified requirements.
  • Track the ownership of policies and procedures, ensuring the associated implementation timelines are adhered to and compliance requirements are met.
  • Conduct market research and assist in establishing a roadmap for modernizing the organization’s Governance, Risk, and Compliance (GRC) tool, identifying key requirements for improvement.
  • Support agency-led High Value Asset (HVA) assessments in compliance with the Cybersecurity and Infrastructure Security Agency (CISA) Assessment Evaluation and Standardization (AES) Program.
  • Update and enhance the organization’s Entity-Wise Business Impact Analysis (EWBIA) to align with evolving business and cybersecurity needs.

Qualifications :

  • Bachelor’s degree in Cybersecurity, Information Technology, or a related field.
  • Minimum 2 years of experience in cybersecurity or related fields, with exposure to governance, risk, and compliance processes.
  • Possesses IAT Level II certification (e.g., CompTIA Security , GIAC, or equivalent).
  • Familiarity with the Cybersecurity Framework (CSF) and Continuous Diagnostics and Mitigation (CDM) dashboard concepts.
  • Basic understanding of automation tools like Power Apps and experience with process automation is a plus.
  • Knowledge of federal cybersecurity and privacy mandates, with the ability to analyze and assist in the implementation of new policies.
  • Strong attention to detail and the ability to manage multiple tasks effectively.
  • Excellent communication skills, with the ability to prepare reports and documentation for various audiences.
  • Preferred Skills :

  • Exposure to High Value Asset (HVA) assessments and familiarity with CISA’s Assessment Evaluation and Standardization (AES) Program.
  • Experience in conducting Entity-Wise Business Impact Analysis (EWBIA) or similar processes.
  • Basic understanding of API development to support automation and data integration efforts.
  • Company Description

    PKH Enterprises (PKH) is a small, woman-owned professional services firm dedicated to helping clients address challenging policy and technology issues. The PKH team is comprised of professionals with varied backgrounds combining legal, policy and technical expertise and offers the services and experience of business process engineers, senior subject matter experts and certified project managers. Our diverse capabilities help our clients improve performance and achieve innovative solutions to their most complex business problems. Our clients turn to us as partners and trusted advisors, and depend on our ability to anticipate, recognize and address their specific needs. PKHE has a reputation for excellence and remains dedicated to generating successful results for tasks at all levels of project execution.

    To all recruitment agencies : PKH Enterprises does not accept unsolicited agency resumes / CVs. PKH Enterprises is not responsible for any fees related to unsolicited resumes / CVs.

    PKH Enterprises is an Equal O

    Company Description

    PKH Enterprises (PKH) is a small, woman-owned professional services firm dedicated to helping clients address challenging policy and technology issues. The PKH team is comprised of professionals with varied backgrounds combining legal, policy and technical expertise and offers the services and experience of business process engineers, senior subject matter experts and certified project managers. Our diverse capabilities help our clients improve performance and achieve innovative solutions to their most complex business problems. Our clients turn to us as partners and trusted advisors, and depend on our ability to anticipate, recognize and address their specific needs. PKHE has a reputation for excellence and remains dedicated to generating successful results for tasks at all levels of project execution. To all recruitment agencies : PKH Enterprises does not accept unsolicited agency resumes / CVs. PKH Enterprises is not responsible for any fees related to unsolicited resumes / CVs. PKH Enterprises is an Equal O

    If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
    Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

    What is the career path for a GRC Analyst?

    Sign up to receive alerts about other jobs on the GRC Analyst career path by checking the boxes next to the positions that interest you.
    Income Estimation: 
    $74,367 - $98,680
    Income Estimation: 
    $131,676 - $196,560
    Income Estimation: 
    $99,138 - $133,641
    Income Estimation: 
    $94,973 - $125,755
    Income Estimation: 
    $96,228 - $129,772
    Income Estimation: 
    $87,093 - $107,335
    Income Estimation: 
    $111,725 - $147,313
    Income Estimation: 
    $112,673 - $137,290
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $112,673 - $137,290
    Income Estimation: 
    $139,945 - $168,577
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $99,793 - $130,112
    Income Estimation: 
    $125,027 - $157,872
    Income Estimation: 
    $70,462 - $84,818
    Income Estimation: 
    $77,991 - $108,747
    Income Estimation: 
    $87,093 - $107,335
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

    Job openings at PKH Enterprises

    PKH Enterprises
    Hired Organization Address Washington, DC Full Time
    Job Description Correspondence and Operations Analyst – PKH Enterprises is seeking a Correspondence and Operations Analy...
    PKH Enterprises
    Hired Organization Address Washington, DC Full Time
    Job Description Job Description Systems Engineer - PKH Enterprises is looking for Systems Engineers interested in a prop...

    Not the job you're looking for? Here are some other GRC Analyst jobs in the Washington, DC area that may be a better fit.

    GRC Analyst

    Meta Inc, Washington, DC

    Cloud Security GRC Analyst

    Strider Technologies, Vienna, VA

    AI Assistant is available now!

    Feel free to start your new journey!