Governance, Risk & Compliance Engineer
Cognizant · Blue Ash, OH · 1 mo ago
HybridFull-time
About the role
As a Governance, Risk & Compliance (GRC) Engineer, you will support the implementation, assessment, and continuous improvement of security and compliance controls across the organization. You will collaborate with the Governance, Risk & Compliance team and work alongside Security, IT, Infrastructure, PMO, Facilities, and business stakeholders.
Responsibilities
- Support implementation and validation of security and compliance controls aligned to NIST SP 800-171 and CMMC Level 2.
- Conduct risk assessments, document findings, residual risks, and mitigation plans, and track remediation activities through closure.
- Prepare audit evidence and support internal and external audits to ensure ongoing compliance readiness.
- Develop and maintain compliance, risk, and remediation reporting for stakeholders and leadership teams.
- Partner with cross-functional teams to embed compliance requirements into business and technology processes while driving continuous improvement initiatives.
Work model
This is a hybrid position requiring regular attendance at a Cognizant or client office in Blue Ash, Ohio. Hybrid work arrangements may change based on project, business, or client requirements.
Requirements
- 3–7 years of experience in Governance, Risk & Compliance, Information Security, Risk Management, Audit, or a related discipline.
- Experience supporting security and compliance frameworks, including NIST SP 800-171 and/or CMMC.
- Working knowledge of risk management practices, remediation tracking, and audit support activities.
- Experience with ServiceNow ITSM and vulnerability management tools such as Qualys.
- Strong communication, stakeholder management, and analytical skills with the ability to work across technical and business teams.
Qualifications
- Security+, CISA, CISM, CISSP, ISO 27001 Lead Implementer/Auditor, CCP, or CMMC-related certifications.
- Experience supporting ISO 27001 compliance programs and security awareness initiatives.
- Experience maintaining audit-ready documentation and evidence repositories.
- Knowledge of regulatory and contractual compliance requirements within complex enterprise environments.
- Experience identifying opportunities for automation and process improvement within GRC functions.