GRC Analyst

Booz Allen HamiltonBethesda, MD
$62,000 - $141,000Remote

About The Position

In this role, you’ll turn complex risk into clear action by supporting Risk Management Framework (RMF) activities and driving Assessment and Authorization (A&A) packages through an Authorization to Operate (ATO). You’ll partner with engineering and mission teams to scope controls, assess risk, remediate gaps, and sustain continuous monitoring so systems remain secure and compliant.

Requirements

  • 3+ years of experience within cyber risk management or security compliance functions
  • Experience applying NIST RMF across categorization, control selection or implementation, assessment, authorization, and continuous monitoring
  • Experience supporting A&A efforts and coordinating ATO decisions with authorizing officials
  • Experience performing security control assessments and producing artifacts such as Security Assessment Reports (SAR) and Plans of Action and Milestones (POA&Ms)
  • Experience developing and maintaining security documentation, including System Security Plans (SSP) and control implementation statements
  • Knowledge of NIST SP 800‑53 Rev.5 control families and tailoring controls to impact levels
  • Knowledge of FISMA processes supporting RMF and authorization decisions
  • Public Trust clearance
  • Bachelor’s degree and 3+ years of experience in information security, or 5+ years of experience in information security in lieu of a degree

Nice To Haves

  • Experience supporting A&A activities at health or research-focused government entities
  • Experience communicating complex security concepts clearly to non‑technical stakeholders and senior leaders
  • Experience producing concise A&A documentation and executive‑ready summaries
  • Knowledge of structured writing and plain‑language techniques for technical documentation
  • Knowledge of stakeholder analysis and change management to drive adoption of security recommendations
  • Ability to write crisply, edit meticulously, and proofread to ensure consistency across artifacts
  • Ability to facilitate working sessions, build consensus, and present recommendations confidently
  • Master's degree

Responsibilities

  • Support Risk Management Framework (RMF) activities.
  • Drive Assessment and Authorization (A&A) packages through an Authorization to Operate (ATO).
  • Partner with engineering and mission teams to scope controls.
  • Assess risk.
  • Remediate gaps.
  • Sustain continuous monitoring so systems remain secure and compliant.
  • Translate technical findings into risk statements and remediation recommendations aligned to mission and business priorities.
  • Plan and execute continuous monitoring (ConMon).
  • Track residual risk.
  • Drive closure of POA&Ms.

Benefits

  • health
  • life
  • disability
  • financial
  • retirement benefits
  • paid leave
  • professional development
  • tuition assistance
  • work-life programs
  • dependent care
  • recognition awards program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service