Posted August 01, 2026
Jr. GRC Analyst
System One
Rockville, MD, US
Full Time
Job Description
Job Description
JUNIOR GRC ANALYST ROCKVILLE, MD - HYBRID LONG TERM CONTRACT SEEKING SOMEONE WHO HAS WORKED WITH THE SERVICENOW GRC APPLICATION Overview:
- The GRC Analyst supports the administration of Information Security Governance, Risk, and Compliance programs, including policy exception management and enterprise risk register activities using ServiceNow Integrated Risk Management (IRM).
- Review policy exception requests for completeness and required documentation.
- Validate business justifications and request additional information as needed.
- Maintain exception records and track approvals in ServiceNow.
- Monitor expiration dates, coordinate renewals, and produce status reports.
- Conduct risk evaluations using established methodologies and templates.
- Assess business impact, likelihood, and overall risk.
- Identify compensating controls and document risk analyses.
- Prepare risk-based recommendations for management review.
- Maintain analysis records in ServiceNow.
- Create, update, and maintain risk records.
- Track risks identified through assessments, penetration tests, vulnerability scans, security incidents, and other approved sources.
- Monitor mitigation activities, due dates, and risk status.
- Maintain supporting documentation and generate reports.
- Process policy exceptions.
- Maintain risk register records.
- Track approvals and workflows.
- Generate reports and dashboards.
- Communicate with IT staff, business stakeholders, system owners, managers, and security teams.
- Provide professional customer service and clear written and verbal communication.
- Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, Business Information Systems, or a related field.
- CompTIA Security+
- ISACA IT Risk Fundamentals
- NIST Cybersecurity Framework (NCSF) Practitioner
- CISM Fundamentals
- Cybersecurity, audit, or compliance-related certifications
- One (1) year of experience in Information Security, IT Governance, Risk Management, Compliance, Audit, Information Technology, or a related field; or
- Recent graduate with relevant internship or equivalent experience.
- ServiceNow experience
- Microsoft 365 proficiency
- GRC program experience
- Technical documentation experience
- Customer service and project coordination experience
- Basic understanding of cybersecurity, risk management, information security, NIST Cybersecurity Framework, and compliance concepts.
- Strong analytical, organizational, and critical-thinking skills.
- Excellent written and verbal communication skills.
- Attention to detail and ability to manage multiple priorities.
- Ability to work independently and learn new technologies quickly.
- Policy exception reviews and tracking records
- Risk analyses and recommendations
- Risk register entries and updates
- Monthly metrics and quarterly reports
- Executive dashboards
- ServiceNow documentation and reporting artifacts
