> Markdown version of [/jobs/ext/2601177-cyber-grc-specialist](https://www.wearedevelopers.com/jobs/ext/2601177-cyber-grc-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber GRC Specialist - **Company:** Brown, LLC - **Location:** Baltimore, MD, United States - **Experience:** Experienced - **Salary:** $95,000.0 - $115,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software as a Service, Cloud Computing, CompTIA Security+, Cyber Security, Information Systems, Issue Tracking Systems, Information Technology Audit, Software Vulnerability Management, Software Security, CIS Benchmarks, Servicenow - **Published:** August 6, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c543699eee6f2c09 ## About the Role * Bachelor's degree in cyber security, information systems, risk management, business, or a relevant field preferred; equivalent professional experience will be considered. * 3-6 years of experience in cyber GRC, information security, technology risk, IT audit, compliance, or related control-management work preferred. * Working knowledge of ISO 27001, SOC 2, NIST CSF, CIS Controls, SEC/FINRA expectations, privacy requirements, or comparable control frameworks. * Experience supporting audits, evidence collection, control testing, policy updates, issue tracking, or risk-register maintenance in a regulated environment; financial services experience preferred. * CISA, CRISC, CISM, Security+, ISO 27001 Foundation/Lead Implementer, or similar professional designation preferred but not required. Technical Skills * Cyber risk registers, exception management, control testing, evidence management, policy lifecycle management, and audit coordination. * GRC or trust-management platforms such as Vanta, Archer, ServiceNow GRC, OneTrust, Drata, or similar tools. * Vulnerability management governance, including prioritization, remediation tracking, aging analysis, exception workflows, and executive reporting. * Strong knowledge of cyber security controls across identity, endpoint, cloud, network, data protection, application security, and third-party risk. * Excellent writing, facilitation, and stakeholder-management skills, including the ability to turn technical risk into clear business language. * Practical judgment about when to enforce, when to escalate, and when to help the business find a workable control path. * Demonstrates curiosity and a continuous improvement mindset by identifying opportunities to enhance processes, improve efficiency, and thoughtfully leverage new technologies and tools, including AI-enabled productivity solutions Personal Attributes * Take ownership and move initiatives forward without constant oversight. * Balance technical depth, process discipline, and sound business judgment. * Approach risk management pragmatically rather than theoretically. * Thrive in collaborative, high-accountability environments. * Communicate clearly with technical and non-technical colleagues. * Bring an entrepreneurial mindset to building and improving security capabilities. Applicants must be authorized to work in the United States without the need for current or future employer-sponsored work authorization (e.g., H-1B , O-1, F-1 (OPT), TN, or any other non-immigrant visa classifications that require employer support or sponsorship). ## Description Brown Advisory is currently seeking a Cyber GRC Specialist to support and mature the firm's governance, risk, compliance, and control-management routines. This blended role is designed for someone who can translate security requirements into practical business processes, drive evidence and accountability, and communicate clearly with technical and non-technical stakeholders. As part of a lean Information Security team within a mid-sized financial services organization, this individual will serve as a central coordinator for cyber risk, policy management, control testing, audit readiness, client and regulatory response support, and vulnerability remediation governance. The role is not intended to be a hands-on vulnerability engineering role; rather, it ensures the process, ownership, exceptions, reporting, and governance routines are working. Blended Role Coverage Primary emphasis: Cyber GRC support for policies, controls, cyber risk tracking, audit coordination, exceptions, and governance routines. Blended coverage: Cyber Risk / Compliance Analyst work, ISO and risk-platform support, evidence coordination, client/regulatory response support, communications, and vulnerability governance., * Support and mature core cyber governance routines, including policy management, control ownership, risk acceptance, exception handling, standards maintenance, and periodic leadership reporting. * Maintain the cyber risk register and partner with technology and business owners to document risk decisions, remediation plans, due dates, dependencies, and residual risk. * Serve as a key administrator and process contributor for ISO and security-risk management platforms such as Vanta or similar tools. * Coordinate evidence collection, control testing, audit requests, client due diligence responses, regulatory requests, and recurring compliance deliverables. * Translate ISO 27001, regulatory, client, and internal security expectations into practical controls and operating procedures appropriate for Brown Advisory's size and risk profile. * Facilitate cross-functional communications for security change, SaaS inventory, policy enforcement, control adoption, and risk remediation. * Coordinate vulnerability management governance, including scan-result intake, prioritization routines, remediation tracking, exception handling, and reporting. * Partner with security engineers, infrastructure teams, application owners, Compliance, Legal, Operations, and Client Service to close control gaps in a business-aligned manner. * Develop clear metrics for control effectiveness, audit readiness, exceptions, overdue remediation, and recurring governance activities. * Identify process improvements that make security governance more repeatable, transparent, and useful without creating unnecessary bureaucracy. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [The Best Job Search Websites of 2025](https://www.wearedevelopers.com/magazine/368-the-best-job-search-websites-of-2025)