Security Governance Risk & Compliance (GRC) Analyst

VirtruWashington, DC
$130,000 - $170,000

About The Position

Virtru is seeking a Security Governance Risk & Compliance (GRC) Analyst to help build a cutting-edge security compliance program aligned with FedRAMP, SOC 2, PCI, HIPAA, GDPR, and other security/privacy frameworks. This role will involve working with modern tools and technologies like Kubernetes, GCP, AWS, and Terraform. The analyst will be a primary point of contact for compliance-related inquiries, leading efforts to achieve and maintain CMMC compliance through gap analyses and roadmap development. They will also support existing FedRAMP, SOC2, and PCI DSS compliance. This is an opportunity to make a significant impact in a growing company with a unique approach to data security that enables sharing rather than preventing it.

Requirements

  • Minimum of 5+ years of information security, IT audit and/or IT Risk Management, or GRC Analyst/Engineer experience
  • Deep understanding of at least few of the following: CMMC, NIST 800-53 & 800-171, FedRAMP, SOC 2, PCI, and/or other global privacy compliance frameworks
  • Technical acumen. Strong understanding of modern cloud technologies (AWS, GCP, Azure, etc.) and familiarity with GRC tools (Hyperproof, Vanta, Drata, etc) and SIEM tools (Datadog, Splunk)
  • Relationship builder with experience working with both business and technical risk and understanding how to translate risk to various levels of the organization
  • Experience training and coaching teams to become better security and privacy practitioners
  • Experience working on an autonomous agile team.
  • Ability to resolve conflicts and drive issues to completion.
  • Ability to work independently with little or no supervision while maintaining a high level of efficiency.

Nice To Haves

  • Thinking outside of the box to respectfully challenge your teammates and managers in the pursuit of excellence
  • Strong sense of urgency with an action-oriented mindset
  • Able to collaborate and adapt to shifting priorities as business needs evolve
  • Comfortable with asynchronous communication including slack, email, zoom, etc.

Responsibilities

  • Manage and implement complex controls frameworks for large systems, consisting of Cloud infrastructure and Software as a Service (SaaS) services (GCP, AWS, GitHub, Okta, etc).
  • Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services.
  • Conduct risk assessments across business units and processes. Identify risk findings and recommend remediation and risk mitigation strategies.
  • Participate in incident response (IR) activities, providing risk analysis and remediation support as needed.
  • Assist or implement automated controls to support risk mitigation efforts across various business units with stakeholders.
  • Incorporate CMMC certification into Virtru’s slate of compliance assessments and ongoing monitoring activities (FedRAMP, SOC 2, PCI).
  • Facilitate the third-party vendor on-boarding and annual review process by evaluating the security of current and prospective partners.
  • Enhance the team with your individualism, spirit, and love of learning.

Benefits

  • Flexible PTO policy
  • 14 holidays
  • $1,500 annual Learning & Development Stipend
  • Frequent company-sponsored team celebrations
  • Access to an Employee Assistance Program
  • Access to Headspace, a mental health app
  • A flat 3% contribution to your retirement account
  • High degree of flexibility
  • Generous parental, medical, and bereavement policies
  • 401K contribution
  • Stock options
  • Full medical, dental, and vision benefits
  • New Hire Swag and IT Welcome boxes
  • Structured semi-annual 360° performance reviews
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service