Enterprise Cybersecurity GRC Governance Analyst
About the role
The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an experienced Information System Security Officer (ISSO) to bridge the gap between high-level policy and technical execution. In this role, you will analyze and translate complex regulatory requirements into clear, actionable enterprise guidance, Standard Operating Procedures (SOPs), and technical standards.
Responsibilities
- Translate complex security and policy requirements into innovative technical documentation, including Standard Operating Procedures (SOPs), implementation guidance, and enterprise standards, to support continuous process improvement and modernization.
- Leverage a strong foundation in business process and change management to gather comprehensive business and security requirements, ensuring enterprise workflows are optimized and automated before being embedded into technical tools.
- Act as a key liaison to gather comprehensive business and security requirements, ensuring enterprise workflows are optimized and automated before being embedded into technical tools.
- Apply configuration management expertise to design, configure, and mature workflows within GRC tools—specifically ServiceNow—while actively facilitating technical integrations with external ticketing, reporting, and workflow systems.
- Drive strategic transformation and modernization of processes in line with federal security program uplifts.
- Reimagine and automate security controls alignment and assessment to create agile, risk-based solutions.
- Lead the integration of security control frameworks and risk management standards in non-federal environments, such as System and Organization Controls 2 Type II (SOC 2 Type II), International Organization for Standardization/International Electrotechnical Commission 27001 (ISO/IEC 27001), and Payment Card Industry Data Security Standard (PCI DSS), and industry-specific regulations, optimizing enterprise practices for compliance and audit readiness.
Requirements
- 8+ years of experience in roles including Security Control Assessor (SCA), Validator, Information System Security Officer (ISSO), Information System Security Engineer (ISSE), or Information Systems Security Manager (ISSM).
- Experience leading business process and change management initiatives, designing and modernizing workflows for authorization, POA&M tracking, and audit evidence collection to drive agility and reduce risk across the organization.
- Experience in configuring, optimizing, and automating Governance, Risk, and Compliance (GRC) platforms, such as ServiceNow, Archer, Xacta, eMASS) to enhance System Security Plan (SSP) development, risk assessment, and control mapping processes.
- Knowledge of National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 revision 4 and 5, NIST SP 800-60, NIST SP 800-171, related SPs, Risk Management Framework (RMF), Federal Information Processing Standards (FIPS) 199, FIPS 200, Federal Risk and Authorization Management Program (FedRAMP), and Federal Information Security Modernization Act (FISMA).
Qualifications
- HS diploma or GED.
Skills
- Strong foundation in business process and change management.
- Experience in configuring, optimizing, and automating Governance, Risk, and Compliance (GRC) platforms, such as ServiceNow, Archer, Xacta, eMASS) to enhance System Security Plan (SSP) development, risk assessment, and control mapping processes.
- Knowledge of National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 revision 4 and 5, NIST SP 800-60, NIST SP 800-171, related SPs, Risk Management Framework (RMF), Federal Information Processing Standards (FIPS) 199, FIPS 200, Federal Risk and Authorization Management Program (FedRAMP), and Federal Information Security Modernization Act (FISMA).
Benefits
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.
Pay
The projected compensation range for this position is $99,000.00 to $225,000.00 (annualized USD).
Schedule
Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.