GRC Analyst - Rockville, MD

Creative Information Technology, Inc
Falls Church, VA, United States
13 days ago

Role details

Contract type
Internship / Graduate position
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Cyber Security Information Systems IT Management Office365 Information Technology Servicenow Vulnerability Analysis

Job description

Join us in driving growth and seizing new business opportunities. Roles & Responsibilities: A. Policy Exception Administration - The contractor shall

  • Review submitted policy exception requests for completeness.
  • Verify required documentation has been submitted.
  • Validate business justifications against County requirements.
  • Request additional information from departments when necessary.
  • Maintain exception records within ServiceNow.
  • Track requests through each stage of the approval process.
  • Monitor exception expiration dates.
  • Coordinate renewals and closures.Produce status reports.

B. Risk Analysis - Using County-approved methodologies, templates and procedures, the Contractor shall:

  • Review policy exception requests.
  • Evaluate business impact.
  • Evaluate likelihood and risk.
  • Identify applicable compensating controls.
  • Prepare written risk analyses.
  • Prepare approval or denial recommendations for CISO review.Document analysis within ServiceNow.

C. Enterprise Risk Register - Maintain the County Information Security Risk Register by:

  • Creating new risk records.
  • Updating existing risk records.
  • Recording risks identified by: o Third-party penetration tests
  • Third-party security assessments
  • Internal risk assessments
  • Vulnerability scanning
  • Policy Exceptions
  • Security incidentsOther approved sources

  • Track mitigation activities.
  • Monitor due dates.
  • Update risk status.
  • Maintain supporting documentation.Generate reports.

D. ServiceNow - Utilize ServiceNow IRM to:

  • Process Policy Exceptions
  • Maintain Risk Register records
  • Track approvals
  • Maintain documentation
  • Generate reportsProduce dashboards

Requirements

Bachelor’s degree in:

  • Cybersecurity
  • Information Systems
  • Information Technology
  • Computer Science
  • Business Information Systems, * Certified Information Security Manager - Fundamentals (CISM-F)
  • NIST Cybersecurity Framework (NCSF) Practitioner
  • ISACA IT Risk Fundamentals Certificate
  • ISACA Cybersecurity Audit CertificateHIPAA Security Training or Compliance Certificates

Preferred experience

  • One (1) year of professional Information Security, IT Governance, Compliance, Risk Management, Information Technology, Audit, or related experience.Recent graduate with relevant internship or equivalent experience.

  • Experience using ServiceNow.
  • Experience using Office 365 suite of products
  • Experience with Governance, Risk and Compliance (GRC).
  • Experience preparing technical documentation.
  • Experience working in customer service environments.Experience with coordinating projects, tasks and/or workflows.

C. Knowledge Basic understanding of:

  • Cybersecurity principles
  • Information Security
  • Risk Management
  • NIST Cybersecurity Framework
  • Risk Scoring Systems/Risk Quantitative Frameworks
  • HIPAA

About the company

Creative Information Technology Inc (CITI) is an esteemed IT enterprise renowned for its exceptional customer service and innovation. We serve both government and commercial sectors, offering a range of solutions such as Healthcare IT, Human Services, Identity Credentialing, Cloud Computing, and Big Data Analytics. With clients in the US and abroad, we hold key contract vehicles including GSA IT Schedule 70, NIH CIO-SP3, GSA Alliant, and DHS-Eagle II.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · WWC 2025

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah · WWC 2025

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

2:27 min

Establishing a simulated technical environment for the workflow demo

Tobias Dunn-Krahn · LIVE

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · WWC Europe 2026

5:00 min

Managing complex state with scope-based resource management

Bjarne Stroustrup · WWC 2022

Videos

See all

Related articles

See all