> Markdown version of [/jobs/ext/1508742-grc-analyst-rockville-md](https://www.wearedevelopers.com/jobs/ext/1508742-grc-analyst-rockville-md). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Analyst - Rockville, MD - **Company:** Creative Information Technology, Inc - **Location:** Falls Church, VA, United States - **Contract:** Internship / Graduate position - **Skills:** Software System Penetration Testing, Cyber Security, Information Systems, IT Management, Office365, Information Technology, Servicenow, Vulnerability Analysis - **Published:** July 30, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=0c04d861268c0db5 ## About the Role Bachelor's degree in: * Cybersecurity * Information Systems * Information Technology * Computer Science * Business Information Systems, * Certified Information Security Manager - Fundamentals (CISM-F) * NIST Cybersecurity Framework (NCSF) Practitioner * ISACA IT Risk Fundamentals Certificate * ISACA Cybersecurity Audit CertificateHIPAA Security Training or Compliance Certificates Preferred experience * One (1) year of professional Information Security, IT Governance, Compliance, Risk Management, Information Technology, Audit, or related experience.Recent graduate with relevant internship or equivalent experience. * Experience using ServiceNow. * Experience using Office 365 suite of products * Experience with Governance, Risk and Compliance (GRC). * Experience preparing technical documentation. * Experience working in customer service environments.Experience with coordinating projects, tasks and/or workflows. C. Knowledge Basic understanding of: * Cybersecurity principles * Information Security * Risk Management * NIST Cybersecurity Framework * Risk Scoring Systems/Risk Quantitative Frameworks * HIPAA ## Description Join us in driving growth and seizing new business opportunities. Roles & Responsibilities: A. Policy Exception Administration - The contractor shall * Review submitted policy exception requests for completeness. * Verify required documentation has been submitted. * Validate business justifications against County requirements. * Request additional information from departments when necessary. * Maintain exception records within ServiceNow. * Track requests through each stage of the approval process. * Monitor exception expiration dates. * Coordinate renewals and closures.Produce status reports. B. Risk Analysis - Using County-approved methodologies, templates and procedures, the Contractor shall: * Review policy exception requests. * Evaluate business impact. * Evaluate likelihood and risk. * Identify applicable compensating controls. * Prepare written risk analyses. * Prepare approval or denial recommendations for CISO review.Document analysis within ServiceNow. C. Enterprise Risk Register - Maintain the County Information Security Risk Register by: * Creating new risk records. * Updating existing risk records. * Recording risks identified by: o Third-party penetration tests * Third-party security assessments * Internal risk assessments * Vulnerability scanning * Policy Exceptions * Security incidentsOther approved sources * Track mitigation activities. * Monitor due dates. * Update risk status. * Maintain supporting documentation.Generate reports. D. ServiceNow - Utilize ServiceNow IRM to: * Process Policy Exceptions * Maintain Risk Register records * Track approvals * Maintain documentation * Generate reportsProduce dashboards ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [Engineering/Manager Pendulum: Generating compound interest on your career](https://www.wearedevelopers.com/videos/100348-engineering-manager-pendulum-generating-compound-interest-on-your-career) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Quick guide: How to write a Software Developer CV](https://www.wearedevelopers.com/magazine/37-quick-guide-how-to-write-a-software-developer-cv) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)