Apply Edge Start your job search

Governance, Risk, and Compliance Analyst

NextgenID · Northern Virginia, VA

Apply & track with Apply Edge
GRC AnalystCyber & GRC · Analyst (L2) | Onsite — Fairfax, VA (HQ) | U.S. Citizen Required (FedRAMP / Federal Customer)Governance, Risk & Compliance Analyst · Reports to: GRC LeadNOTICE OF CONFIDENTIALITY: This document contains CONFIDENTIAL and PROPRIETARY BUSINESS INFORMATION owned by NextgenID. Unauthorized use, disclosure, or copying of this information is strictly prohibited. Distribution is limited to authorized recipients only.THE ROLENextgenID is hiring a GRC Analyst to do the hands-on work that keeps our compliance program running. We verify and credential identity at the highest assurance level (IAL3) for federal agencies and enterprises, so evidence, documentation, and audit support are constant, real work. You maintain our control documentation and evidence, run the operational side of our FedRAMP, Kantara, and UK digital-identity efforts, keep the POA&M and vulnerability tracking current, and complete the security questionnaires our customers send. You report to the GRC Lead and work across engineering, DevSecOps, operations, and the document team.This is an execution role with room to grow. You turn framework requirements into finished evidence, keep trackers and repositories current, coordinate assessment logistics, and draft the documents the GRC Lead reviews and signs. You will pick up active FedRAMP 20x, Kantara 800-63A, and UK DVS workstreams, along with tasks handed off from a departing analyst and intern, and keep them moving without dropping detail.ROLE FIT & NON-NEGOTIABLES•    Onsite at our Fairfax, VA headquarters. This role is hands-on and evidence-heavy.•    U.S. citizen, required for FedRAMP and federal-customer obligations.•    Two or more years in GRC, security compliance, audit support, or a closely related role.•    Comfortable owning documentation, evidence, and trackers to a deadline.•    Detail-oriented and discreet with sensitive security information.WHAT YOU WILL OWN (90 TO 180 DAY OUTCOMES)•    Current, well-organized control documentation and evidence repositories, moving from SharePoint into Vanta.•    The operational FedRAMP evidence effort: control documentation, gap-finding tracking, and Trust Center content drafts.•    A monthly POA&M produced from Qualys findings using the FedRAMP template, with remediation tracked to closure.•    Completed, consistent security questionnaires delivered on time for GRC Lead review.•    The UK DVS documentation package and Kantara assessment materials kept current and submission-ready.CORE RESPONSIBILITIESCompliance Documentation & EvidenceKeep the record current and audit-ready.•    Maintain control documentation, policies, and procedures, and migrate evidence into Vanta.•    Gather and organize evidence from engineering, DevSecOps, and operations leads.•    Convert implemented controls into machine-readable (OSCAL / JSON) format for FedRAMP submission.Authorization & Assessment SupportRun the operational side of our certifications.•    Refine and maintain the UK DVS / DIATF documentation package and scoping forms.•    Prepare Kantara assessment materials (SoCA, S3A, KAR) and the Rev 4 gap working draft.•    Coordinate assessment and pentest logistics, scheduling, and evidence with assessors and leads.Vulnerability & POA&M TrackingKeep the remediation record honest.•    Produce the monthly POA&M from Qualys findings using the FedRAMP template.•    Track vulnerability remediation and compensating controls with the RedTeam / DevSecOps leads.•    Maintain vulnerability and vendor-risk evidence logs (for example, the BeyondTrust remediation log).Customer & Vendor Assurance SupportAnswer the questionnaires and support vendor risk.•    Complete security questionnaires (for example, CCRA and customer InfoSec assessments) consistent with prior responses.•    Support third-party and vendor risk assessments and evidence requests.•    Route completed responses to the GRC Lead and management for review before submission.Research & Program SupportSupport the wider compliance effort.•    Provide compliance and privacy research to the document and product teams.•    Support ADA / Section 508 assessments and international import certification documentation (BIS, WPC, ATA Carnet).•    Help configure and maintain GRC tooling (Vanta) and keep the compliance calendar updated.WHAT YOU MUST HAVE ALREADY DONE•    Gathered and organized audit evidence and maintained compliance documentation to a deadline.•    Worked with a control framework (NIST 800-53, 800-63, ISO 27001, or SOC 2) on real evidence or gap work.•    Tracked vulnerabilities or POA&M items and coordinated remediation with technical teams.•    Completed a customer or vendor security questionnaire using documented evidence.•    Kept a tracker, repository, or evidence log accurate across many moving items.QUALIFICATIONSRequired•    Two or more years in GRC, security compliance, audit support, or a closely related role.•    Working knowledge of NIST SP 800-53 and/or NIST SP 800-63, ISO 27001, or SOC 2.•    Experience gathering evidence and maintaining compliance documentation.•    Experience with vulnerability or POA&M tracking and remediation coordination.•    Familiarity with vulnerability tooling (Qualys or Nessus) and evidence / GRC platforms (Vanta or similar).•    Strong writing and documentation skills for policies, procedures, and questionnaire responses.•    Highly organized and detail-oriented, able to manage many concurrent items.•    Discreet and reliable with sensitive security and compliance information.•    Must be able to work onsite in Fairfax, VA; U.S. citizen (FedRAMP / federal customer).Preferred•    Security+, GRCP, CySA+, or progress toward CISA.•    Exposure to FedRAMP or FISMA continuous monitoring (ConMon) and 3PAO assessments.•    Experience with Kantara / NIST 800-63 identity assurance or UK DIATF / DVS.•    Familiarity with OSCAL or machine-readable control formats.•    Experience with security questionnaires (CAIQ, CCRA, customer InfoSec assessments).•    Background in an IDaaS, cloud, or federal-contractor environment.SIGNALS WE LOOK FOR•    You keep trackers and evidence current without being chased.•    You read a control and know what evidence proves it.•    You write clearly enough that your draft needs little rework before sign-off.•    You chase the last 10 percent of detail that makes evidence audit-ready.•    You handle sensitive information with discretion and never submit without review.WHAT SUCCESS LOOKS LIKE•    Control documentation and evidence are current, organized, and audit-ready in Vanta.•    The monthly POA&M is produced on time and remediation is tracked to closure.•    UK DVS and Kantara materials are submission-ready ahead of each deadline.•    Security questionnaires are completed accurately and on time for GRC Lead review.•    Inherited workstreams from the departing analyst and intern continue without gaps.WHY NEXTGENIDNextgenID builds the compliance-grade identity infrastructure that federal agencies and enterprises rely on to verify and credential identity at IAL3. Compliance is the product's license to operate, and the evidence you produce is what makes it real. As GRC Analyst, you will see your work in every certification we hold and every customer questionnaire we clear, and you will grow into deeper risk and program ownership. For the right person, this is the path to a senior GRC or GRC Lead role.About NextgenIDNextgenID is a trusted identity assurance, management, and credentialing company. Our platform performs onsite attended and Supervised Remote In-person Proofing (SRIP) to verify, authenticate, and credential identity at the highest assurance level (IAL3), conforming to HSPD-12 and NIST SP 800-63-4. We operate at the intersection of multi-modal biometrics, ICAM, and mission-critical security, on a multi-tenant network serving federal agencies, enterprises, and critical infrastructure operators.NextgenID is an Equal Opportunity Employer. We do not discriminate based on race, color, religion, sex, national origin, age, disability, veteran status, or any other characteristic protected by applicable law.