SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
CHAOS Industries, a defense technology company founded in 2022 and backed by $1B in funding from 8VC, Accel, and Valor Equity Partners, is seeking a Governance, Risk & Compliance (GRC) Analyst to mature and own the company's cybersecurity GRC program.
You will report to the IT/Cybersecurity Program Director and serve as the connective tissue between IT, Cybersecurity, Physical Security, and Manufacturing teams—translating broad requirements into actionable controls across the organization. This is a hands-on role where you'll design frameworks tailored to CHAOS's operating environment rather than forcing the organization into generic templates.
Key responsibilities include:
- Owning risk assessments across multiple departments and maintaining a centralized risk register
- Designing and maintaining a unified control framework tailored to CHAOS Industries, including security-by-design principles and defined Maximum Tolerable Downtime (MTD), Recovery Point Objective (RPO), and Recovery Time Objective (RTO) for critical systems
- Writing and maintaining policy that builds genuine security maturity beyond minimum compliance requirements
- Managing GRC tooling and workflows to support risk assessments, control monitoring, and reporting
- Preparing for, coordinating, and running third-party and certification audits, including evidence collection, gap assessments, and auditor liaison
- Reporting regularly to the Program Director and executive stakeholders on risk posture, audit status, and program maturity
- Supporting customer, vendor, supplier, and subcontractor cybersecurity risk management, including questionnaires, contract reviews, and security expectations
- Coordinating cybersecurity audits, assessments, and remediation tracking in partnership with Legal, Compliance, commercial teams, IT, and business leaders
Onsite presence required 4 days per week in Washington, D.C. Travel up to 25%, primarily to support Manufacturing and Physical Security control validation across company sites. Role includes occasional access to manufacturing floor environments with required PPE.
REQUIREMENTS:
Minimum:
- Bachelor's degree or equivalent experience in computer science, cybersecurity, information security, IT, Information Assurance, or related field
- Deep knowledge of NIST CSF, NIST RMF, ISO/IEC 27000 series, UK Cyber Essentials, CMMC/NIST 800-171, NIST 800-53
- Experience selecting, implementing, or administering GRC tooling and workflows
- Exposure to widely recognized governance, risk, and compliance frameworks spanning security, privacy, and quality management domains
- Familiarity with OT/ICS security concepts
- Minimum 5 years hands-on GRC or compliance experience combined with prior experience in a DoD environment or military service
- Direct support of third-party or certification audits from evidence collection through closure
- Ability to apply recognized governance, risk, and compliance frameworks to design real, working controls tailored to a specific organization
- Experience performing or directly supporting formal risk assessments (identification, scoring, and treatment) using a defined methodology
Preferred:
- Experience supporting third-party audits in a cloud-centric environment
- Has built or materially contributed to a risk register, control framework, or compliance program
- Has written policy or procedure documentation that a non-security audience could follow and act on