GRC Lead

NextgenID Inc

  • Fairfax, VA
  • 22 days ago
  • $95,000–$120,000 Per Year

Highlights

We verify and credential identity at the highest assurance level (IAL3) for federal agencies and enterprises, which means our authorizations - FedRAMP, Kantara, UK digital identity (DIATF/DVS), and the security assurances our customers depend on - are core to the business. Kantara 800-63A (IAL3) certification maintained, with a planned path from Rev 3 to Rev 4. A functioning GRC tooling and evidence pipeline (Vanta) that keeps documentation and submissions current with less manual effort.

Numbers & Facts

LocationFairfax, VA
Salary$95,000–$120,000 Per Year

Description

GRC Lead

Location: Onsite - Fairfax, VA · U.S. Citizen Required (FedRAMP / Federal Customer)

Type: Full Time

Job description

NextgenID is hiring a GRC Lead to own our governance, risk, and compliance program end-to-end. We verify and credential identity at the highest assurance level (IAL3) for federal agencies and enterprises, which means our authorizations - FedRAMP, Kantara, UK digital identity (DIATF/DVS), and the security assurances our customers depend on - are core to the business. You own the compliance calendar, the risk register, the audit and assessment relationships, and the evidence that proves our posture. You lead a GRC Analyst and report to the CTO & EVP. This is a working leadership role: you set the program, and you also do the senior, judgment-heavy work yourself.

Salary Range: $95,000-$120,000

Role Fit & Non-Negotiables

  • Onsite at our Fairfax, VA headquarters. This is a hands-on leadership role, not remote.
  • U.S. citizen, required for FedRAMP and federal-customer obligations.
  • Five or more years in governance, risk, and compliance, including ownership of a formal authorization or audit program.
  • Direct experience with FedRAMP, FISMA, or an equivalent federal framework, and with third-party (3PAO) assessments.
  • Able to make and defend risk decisions and to sign off on evidence that goes to assessors and customers.

What You Will Own (90 to 180 Day Outcomes)

  • A single, authoritative compliance calendar and program plan across FedRAMP, Kantara, UK DVS, SOC 2, and customer questionnaires.
  • The FedRAMP 20x authorization effort carried toward submission, including the 3PAO relationship, Trust Center publication, and machine-readable (OSCAL) control package.
  • A current, governed risk register and monthly POA&M process, with documented risk decisions and compensating controls.
  • Kantara 800-63A (IAL3) certification maintained, with a planned path from Rev 3 to Rev 4.
  • A functioning GRC tooling and evidence pipeline (Vanta) that keeps documentation and submissions current with less manual effort.
  • A GRC Analyst onboarded, directed, and delivering, with the departing analyst's and intern's workstreams fully absorbed.

Core Responsibilities

Compliance Program Leadership - own the program, the calendar, and the standard.

  • Own the compliance calendar and program plan across FedRAMP, FISMA, Kantara/NIST 800-63, UK DIATF/DVS, SOC 2, and ADA.
  • Set GRC policy, standards, and process, and keep them current and version-controlled.
  • Report compliance status, risk posture, and audit readiness to the CTO and leadership.

Authorizations & External Assessments - lead audits, 3PAOs, and certification bodies.

  • Lead FedRAMP 20x authorization: 3PAO selection and relationship, ATO timeline, Trust Center publication, and the OSCAL submission strategy.
  • Own the Kantara certification program (800-63A, IAL3) and the Rev 3 to Rev 4 transition strategy.
  • Own the UK DVS / DIATF certification, including scoping and gap-assessment leadership.

Risk Management - own the risk register and the decisions that carry risk.

  • Maintain the enterprise and vendor risk register and govern the monthly POA&M process.
  • Make and document risk decisions, risk adjustments, and compensating controls, including vendor vulnerabilities.
  • Set vulnerability remediation priorities and pentest readiness with the engineering and DevSecOps leads.

Vendor & Customer Assurance - prove our posture to third parties without slowing the business.

  • Own third-party and vendor risk assessments across our tooling and supply chain.
  • Own the security-questionnaire program (final review and sign-off) and represent our posture to customers and prospects.
  • Partner with Growth and Legal on assurance commitments and trust-center content.

Team & Tooling - deliver the program through the analyst and the toolchain.

  • Lead, mentor, and prioritize the work of the GRC Analyst and absorb the departing intern's workstreams.
  • Own GRC tooling strategy and the evidence pipeline (Vanta, Qualys, OSCAL).
  • Coordinate engineering, DevSecOps, operations, and legal contributors to compliance deliverables.

What You Must Have Already Done

  • Owned a federal authorization or audit program (FedRAMP, FISMA, StateRAMP, or equivalent) through a 3PAO or independent assessment.
  • Built and maintained a risk register and a POA&M process, and defended risk decisions to an assessor or customer.
  • Interpreted a control framework (NIST 800-53, 800-63, or ISO 27001) and translated it into policy, procedure, and evidence.
  • Managed an external assessor or certification-body relationship end to end.
  • Led or mentored analysts and coordinated cross-functional contributors to a compliance deadline.

Required Qualifications

  • Five or more years in governance, risk, and compliance, security compliance, or audit, with program ownership.
  • Direct experience with FedRAMP and/or FISMA, including continuous monitoring (ConMon) and 3PAO assessment.
  • Working command of NIST SP 800-53 and NIST SP 800-63 (identity assurance), and of risk-assessment methodology.
  • Experience owning a risk register, a POA&M process, and a vendor-risk program.
  • Experience managing external assessors, auditors, or certification bodies.
  • Experience with GRC or compliance-automation tooling (Vanta or similar) and vulnerability tools (Qualys or Nessus).
  • Ability to make, document, and defend risk decisions.
  • Excellent written and verbal communication for assessors, customers, and executives.
  • Must be able to work onsite in Fairfax, VA; U.S. citizen (FedRAMP / federal customer).

Preferred Qualifications

  • CISA, CRISC, CISSP, or CISM certification.
  • Experience with Kantara / NIST 800-63 identity assurance (IAL2 / IAL3) certification.
  • Experience with international identity frameworks (UK DIATF / DVS) or ISO 27001 certification.
  • Experience with OSCAL or machine-readable control packages for FedRAMP 20x.
  • Background in a federal-contractor or IDaaS / identity-security environment.
  • Experience managing security questionnaires (CAIQ, CCRA, customer InfoSec assessments).
  • Familiarity with SOC 2 and ADA / Section 508 accessibility assessments.

Signals We Look For

  • You own the calendar in your head: you know what is due, to whom, and what evidence proves it.
  • You make risk calls and defend them with documented reasoning, not hand-waving.
  • You turn a framework into a short list of what has to be done, and get it done.
  • You keep assessors and customers confident because your evidence is clean and current.
  • You lead through other teams, coordinating engineering and operations without owning their headcount.

What Success Looks Like

  • FedRAMP 20x reaches submission on schedule, with a published Trust Center and a machine-readable control package.
  • Kantara IAL3 certification stays current, with a credible Rev 4 transition plan.
  • A single risk register and monthly POA&M process run on cadence, with documented risk decisions.
  • Customer questionnaires and external assessments are answered accurately and on time, with no material findings from poor evidence.
  • The GRC Analyst is productive and the departing analyst's and intern's workstreams continue without gaps.

Why NextgenID

NextgenID builds the compliance-grade identity infrastructure that federal agencies and enterprises rely on to verify and credential identity at IAL3. Compliance is not overhead here - it is the product's license to operate. As GRC Lead, you own the authorizations and the evidence that let us sell and deliver, and you will see your work directly in every certification we hold and every customer we win. For the right person, this is the path to a GRC Manager or Director role as the program grows.

Qualifications & Skills

Benefits

To Apply

Please submit your resume and a cover letter detailing your relevant experience and how you meet the qualifications outlined above to careers@nextgenid.com. We look forward to reviewing your application and considering you for this exciting opportunity to contribute to our innovative identity technology startup.

About NextgenID

NextgenID focuses on improving the efficiency and speed of mission critical, high assurance identity enrollment and credentialing operations that are essential to hundreds of millions of users worldwide.

Our technologies are engineered to dramatically reduce the time and cost of capturing accurate data when creating a digital identity. Our industry-neutral solutions revolve around "Supervised Remote-Identity Proofing" to automatically, securely and "remotely" perform all proofing, enrollment and credentialing processes and workflows for our customers. The industry is taking notice as we are now working with some of the largest agencies in the US Defense, intelligence, Civil, State and Local government markets, as well as other national governments and commercial organizations throughout the world.

Similar Jobs