SlipstreamJobsFresh Startup & VC-Backed Jobs

Governance, Risk & Compliance (GRC) Analyst

Chaos - Washington, DC, United States - Hybrid - posted 2026-09-10

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

CHAOS Industries, a defense technology company founded in 2022 and backed by $1B in funding from 8VC, Accel, and Valor Equity Partners, is seeking a Governance, Risk & Compliance (GRC) Analyst to mature and own the company's cybersecurity GRC program. You will report to the IT/Cybersecurity Program Director and serve as the connective tissue between IT, Cybersecurity, Physical Security, and Manufacturing teams—translating broad requirements into actionable controls across the organization. This is a hands-on role where you'll design frameworks tailored to CHAOS's operating environment rather than forcing the organization into generic templates. Key responsibilities include: - Owning risk assessments across multiple departments and maintaining a centralized risk register - Designing and maintaining a unified control framework tailored to CHAOS Industries, including security-by-design principles and defined Maximum Tolerable Downtime (MTD), Recovery Point Objective (RPO), and Recovery Time Objective (RTO) for critical systems - Writing and maintaining policy that builds genuine security maturity beyond minimum compliance requirements - Managing GRC tooling and workflows to support risk assessments, control monitoring, and reporting - Preparing for, coordinating, and running third-party and certification audits, including evidence collection, gap assessments, and auditor liaison - Reporting regularly to the Program Director and executive stakeholders on risk posture, audit status, and program maturity - Supporting customer, vendor, supplier, and subcontractor cybersecurity risk management, including questionnaires, contract reviews, and security expectations - Coordinating cybersecurity audits, assessments, and remediation tracking in partnership with Legal, Compliance, commercial teams, IT, and business leaders Onsite presence required 4 days per week in Washington, D.C. Travel up to 25%, primarily to support Manufacturing and Physical Security control validation across company sites. Role includes occasional access to manufacturing floor environments with required PPE. REQUIREMENTS: Minimum: - Bachelor's degree or equivalent experience in computer science, cybersecurity, information security, IT, Information Assurance, or related field - Deep knowledge of NIST CSF, NIST RMF, ISO/IEC 27000 series, UK Cyber Essentials, CMMC/NIST 800-171, NIST 800-53 - Experience selecting, implementing, or administering GRC tooling and workflows - Exposure to widely recognized governance, risk, and compliance frameworks spanning security, privacy, and quality management domains - Familiarity with OT/ICS security concepts - Minimum 5 years hands-on GRC or compliance experience combined with prior experience in a DoD environment or military service - Direct support of third-party or certification audits from evidence collection through closure - Ability to apply recognized governance, risk, and compliance frameworks to design real, working controls tailored to a specific organization - Experience performing or directly supporting formal risk assessments (identification, scoring, and treatment) using a defined methodology Preferred: - Experience supporting third-party audits in a cloud-centric environment - Has built or materially contributed to a risk register, control framework, or compliance program - Has written policy or procedure documentation that a non-security audience could follow and act on

Similar roles