GRC Analyst – Rockville, MD

Creative Information Technology, Inc.Falls Church, VA
Onsite

About The Position

Creative Information Technology Inc (CITI) is an esteemed IT enterprise renowned for its exceptional customer service and innovation. We serve both government and commercial sectors, offering a range of solutions such as Healthcare IT, Human Services, Identity Credentialing, Cloud Computing, and Big Data Analytics. With clients in the US and abroad, we hold key contract vehicles including GSA IT Schedule 70, NIH CIO-SP3, GSA Alliant, and DHS-Eagle II. Join us in driving growth and seizing new business opportunities.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Systems, Information Technology, Computer Science, or Business Information Systems.
  • Basic understanding of Cybersecurity principles, Information Security, Risk Management, NIST Cybersecurity Framework, Risk Scoring Systems/Risk Quantitative Frameworks, and HIPAA.

Nice To Haves

  • CompTIA Security+ (Sec+)
  • Certified Information Security Manager – Fundamentals (CISM‑F)
  • NIST Cybersecurity Framework (NCSF) Practitioner
  • ISACA IT Risk Fundamentals Certificate
  • ISACA Cybersecurity Audit Certificate
  • HIPAA Security Training or Compliance Certificates
  • One (1) year of professional Information Security, IT Governance, Compliance, Risk Management, Information Technology, Audit, or related experience.
  • Recent graduate with relevant internship or equivalent experience.
  • Experience using ServiceNow.
  • Experience using Office 365 suite of products
  • Experience with Governance, Risk and Compliance (GRC).
  • Experience preparing technical documentation.
  • Experience working in customer service environments.
  • Experience with coordinating projects, tasks and/or workflows.

Responsibilities

  • Review submitted policy exception requests for completeness.
  • Verify required documentation has been submitted.
  • Validate business justifications against County requirements.
  • Request additional information from departments when necessary.
  • Maintain exception records within ServiceNow.
  • Track requests through each stage of the approval process.
  • Monitor exception expiration dates.
  • Coordinate renewals and closures.
  • Produce status reports.
  • Review policy exception requests.
  • Evaluate business impact.
  • Evaluate likelihood and risk.
  • Identify applicable compensating controls.
  • Prepare written risk analyses.
  • Prepare approval or denial recommendations for CISO review.
  • Document analysis within ServiceNow.
  • Creating new risk records.
  • Updating existing risk records.
  • Recording risks identified by third-party penetration tests, third-party security assessments, internal risk assessments, vulnerability scanning, policy exceptions, security incidents, and other approved sources.
  • Track mitigation activities.
  • Monitor due dates.
  • Update risk status.
  • Maintain supporting documentation.
  • Generate reports.
  • Process Policy Exceptions
  • Maintain Risk Register records
  • Track approvals
  • Maintain documentation
  • Generate reports
  • Produce dashboards
  • Regularly communicate with Department IT Staff, Department Management, Information System Owners, County Leadership, and Office of Enterprise Information Security.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service