What are the responsibilities and job description for the GRC (Governance, Risk & Compliance) Engineer position at DP Professionals (DPP)?
This is a fulltime role
US Citizens only (requires clearance)
No third parties
W2 only
We are seeking a GRC (Governance, Risk & Compliance) Engineer to support the development, implementation, and maintenance of security governance, risk management, and compliance programs. The ideal candidate will have hands-on experience supporting government Authorization to Operate (ATO) processes and be comfortable leveraging modern AI tools to improve security, compliance, documentation, and risk-management workflows.
This is an excellent opportunity for an early-career cybersecurity professional who has direct government compliance experience and wants to grow within a GRC-focused engineering environment.
Key Responsibilities
- Support governance, risk, and compliance activities across information systems and security programs.
- Perform and support Authorization to Operate (ATO) activities within government environments.
- Develop, maintain, and manage security documentation, including System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), risk assessments, and related compliance artifacts.
- Assist with security control implementation, assessment, validation, and continuous monitoring.
- Coordinate with cybersecurity, engineering, IT, and program teams to address security and compliance requirements.
- Identify, document, and track security risks and remediation activities.
- Support audits, assessments, and government compliance reviews.
- Use AI tools and automation technologies to improve GRC processes, documentation, analysis, and workflow efficiency.
- Translate technical security requirements into actionable compliance and risk-management activities.
- Stay current with applicable cybersecurity frameworks, government security requirements, and evolving compliance practices.
Required Qualifications
- 1–3 years of professional experience in Governance, Risk & Compliance, cybersecurity, information assurance, or a related field.
- Direct hands-on experience performing or supporting government ATOs — candidates should have completed or substantially participated in at least one or two government ATO processes.
- Understanding of cybersecurity governance, risk management, security controls, and compliance processes.
- Experience creating or maintaining security and compliance documentation.
- Strong analytical, organizational, and written communication skills.
- Ability to work independently in a remote environment.
- Experience using AI tools to support cybersecurity, compliance, documentation, research, or workflow automation.
Preferred Qualifications
- Experience with NIST Risk Management Framework (RMF) and related NIST publications.
- Familiarity with government security frameworks and authorization processes.
- Experience with POA&Ms, SSPs, security control assessments, and continuous monitoring.
- Cybersecurity or GRC-related certifications such as Security , CySA , CAP, CISM, or CISSP.
- Experience working with GRC platforms or security compliance management tools.
- Familiarity with AI-assisted cybersecurity and compliance workflows.
Salary : $85,000 - $150,000