Quartermaster AI logoQuartermaster AI logo

Governance, Risk, and Compliance (GRC) Manager

Quartermaster AIArlington, VA
On-site Full-time

Clicking Apply Now takes you to AutoApply where you can tailor your resume and apply.


Experience Level

Manager

Qualifications

Qualifications:- Proven experience in governance, risk management, and compliance, preferably in a technology or defense environment.- Strong understanding of NIST SP 800-171, CMMC 2.0, and federal compliance frameworks.- Excellent analytical and problem-solving skills, with the ability to communicate complex concepts clearly.- Experience in leading compliance certification processes and audits.- Ability to work cross-functionally and build relationships across teams.- Relevant certifications (e.g., CISSP, CISM, CRISC) are a plus.

About the job

Quartermaster AI develops advanced AI and robotics for open-ocean applications, helping secure and manage maritime resources. The company’s systems enable vessels to sense, compute, and communicate, supporting maritime domain awareness for national security and maritime organizations.

To advance this mission, Quartermaster AI is hiring a Governance, Risk, and Compliance (GRC) Manager in Arlington, VA. This leader will build the trust frameworks required for collaboration with government and industry partners, shaping the company’s security posture and compliance strategy.

Role overview

The GRC Manager is responsible for designing and running the company’s governance, risk, and compliance program. This includes developing compliance infrastructure from the ground up and translating complex regulatory requirements into scalable, automation-driven processes that support engineering teams. The position reports directly to security leadership and acts as the primary authority on information security governance, regulatory compliance, and organizational risk. This foundational role influences Quartermaster AI’s growth and operational strategy.

Key responsibilities

  • Develop and manage the enterprise GRC program, including policies, standards, and procedures that align with NIST SP 800-171, CMMC 2.0, and other federal frameworks.
  • Lead the CMMC Level 2 certification process from initial gap analysis through remediation, System Security Plan (SSP) development, and coordination with third-party assessors (C3PAOs).
  • Establish and maintain a risk management framework, conduct regular risk assessments, and present risk posture and mitigation strategies to executive leadership.
  • Implement continuous monitoring and compliance automation to maintain adherence to NIST 800-171 controls across all 14 security families.
  • Act as the main contact for regulatory audits, government compliance reviews, and customer security questions.
  • Work with Engineering, Product, and Operations teams to integrate security and compliance requirements into development workflows.
  • Develop and maintain the Plan of Action & Milestones (POA&M) process to track compliance and remediation activities.

About Quartermaster AI

Quartermaster AI is dedicated to revolutionizing maritime security through innovative AI and robotic technologies that enhance the safety and sustainability of ocean resources. We aim to provide vital infrastructure for national security and maritime industries, ensuring that our solutions are both effective and responsible.

Similar jobs

Browse all companies, explore by city & role, or SEO search pages.

Tailoring 0 resumes

We'll move completed jobs to Ready to Apply automatically.