Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Brown Advisory

Cyber GRC Specialist

Brown Advisory

Cyber GRC Specialist strengthening governance, risk, and compliance for independent investment management firm. Coordinating controls, audits, risk registers, and vulnerability remediation across business and technology teams.

Posted 8/11/2026full-timeBaltimore • District of Columbia, Maryland • 🇺🇸 United StatesMid-LevelSenior💰 $95,000 - $115,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in cyber governance, risk management, and compliance, with a strong focus on ISO 27001 and related frameworks. Capable of translating complex security requirements into actionable controls while facilitating cross-functional collaboration and effective communication.

Highest-signal resume keywords
Cyber GovernanceISO 27001 KnowledgeRisk ManagementGRC Platforms ExperienceControl Testing

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Cyber Risk ManagementPolicy ManagementControl OwnershipAudit CoordinationEvidence CollectionVulnerability ManagementRisk Register MaintenanceTechnical Risk TranslationControl Effectiveness MetricsCompliance Deliverables
Soft Skills
Excellent WritingFacilitation SkillsStakeholder ManagementPractical JudgmentClear Communication
Tools & Technologies
VantaArcherServiceNow GRCOneTrustDrata
Certifications & Qualifications
CISACRISCCISMSecurity+ISO 27001 Foundation/Lead Implementer
Industry Keywords
Cyber SecurityInformation SecurityTechnology RiskIT AuditComplianceFinancial ServicesSOC 2NIST CSFCIS ControlsSEC/FINRA Expectations

Tech Stack

Tools & technologies
CloudCyber SecurityServiceNow

About the role

Key responsibilities & impact
  • Support and mature cyber governance routines, including policy management, control ownership, risk acceptance, exception handling, standards maintenance, and leadership reporting
  • Maintain the cyber risk register and document risk decisions, remediation plans, due dates, dependencies, and residual risk
  • Administer and contribute process support to ISO and security-risk management platforms such as Vanta or similar tools
  • Coordinate evidence collection, control testing, audits, client due diligence responses, regulatory requests, and compliance deliverables
  • Translate ISO 27001, regulatory, client, and internal security expectations into practical controls and operating procedures
  • Facilitate cross-functional communications for security change, SaaS inventory, policy enforcement, control adoption, and risk remediation
  • Coordinate vulnerability management governance, including scan-result intake, prioritization, remediation tracking, exception handling, and reporting
  • Partner with security engineers, infrastructure teams, application owners, Compliance, Legal, Operations, and Client Service to close control gaps
  • Develop metrics for control effectiveness, audit readiness, exceptions, overdue remediation, and governance activities
  • Identify process improvements to make security governance repeatable, transparent, and useful

Requirements

What you’ll need
  • Bachelor's degree in cyber security, information systems, risk management, business, or a relevant field preferred; equivalent professional experience will be considered
  • 3-6 years of experience in cyber GRC, information security, technology risk, IT audit, compliance, or related control-management work preferred
  • Working knowledge of ISO 27001, SOC 2, NIST CSF, CIS Controls, SEC/FINRA expectations, privacy requirements, or comparable control frameworks
  • Experience supporting audits, evidence collection, control testing, policy updates, issue tracking, or risk-register maintenance in a regulated environment; financial services experience preferred
  • CISA, CRISC, CISM, Security+, ISO 27001 Foundation/Lead Implementer, or similar professional designation preferred but not required
  • Knowledge of cyber risk registers, exception management, control testing, evidence management, policy lifecycle management, and audit coordination
  • Experience with GRC or trust-management platforms such as Vanta, Archer, ServiceNow GRC, OneTrust, Drata, or similar tools
  • Knowledge of vulnerability management governance, prioritization, remediation tracking, aging analysis, exception workflows, and executive reporting
  • Strong knowledge of cyber security controls across identity, endpoint, cloud, network, data protection, application security, and third-party risk
  • Excellent writing, facilitation, and stakeholder-management skills
  • Ability to translate technical risk into clear business language
  • Practical judgment in enforcing, escalating, and developing workable control paths
  • Ability to take ownership and move initiatives forward without constant oversight
  • Ability to balance technical depth, process discipline, and business judgment
  • Ability to communicate clearly with technical and non-technical colleagues
  • Must be authorized to work in the United States without current or future employer-sponsored work authorization

Benefits

Comp & perks
  • Medical
  • Dental
  • Vision
  • Wellness program participation incentive
  • Financial wellness program
  • Fitness event fee reimbursement
  • Gym membership discounts
  • Colleague Assistance Program
  • Telemedicine Program (for those enrolled in Medical)
  • Adoption Benefits
  • Daycare late pick-up fee reimbursement
  • Basic Life & Accidental Death & Dismemberment Insurance
  • Voluntary Life & Accidental Death & Dismemberment Insurance
  • Short Term Disability
  • Paid parental leave
  • Group Long Term Disability
  • Pet Insurance
  • 401(k) (50% employer match up to IRS limit, 4 year vesting)
  • Competitive compensation package
  • Bonus or long-term incentive eligibility (if applicable)