About the job
Quartermaster AI develops advanced AI and robotics for open-ocean applications, helping secure and manage maritime resources. The company’s systems enable vessels to sense, compute, and communicate, supporting maritime domain awareness for national security and maritime organizations.
To advance this mission, Quartermaster AI is hiring a Governance, Risk, and Compliance (GRC) Manager in Arlington, VA. This leader will build the trust frameworks required for collaboration with government and industry partners, shaping the company’s security posture and compliance strategy.
Role overview
The GRC Manager is responsible for designing and running the company’s governance, risk, and compliance program. This includes developing compliance infrastructure from the ground up and translating complex regulatory requirements into scalable, automation-driven processes that support engineering teams. The position reports directly to security leadership and acts as the primary authority on information security governance, regulatory compliance, and organizational risk. This foundational role influences Quartermaster AI’s growth and operational strategy.
Key responsibilities
- Develop and manage the enterprise GRC program, including policies, standards, and procedures that align with NIST SP 800-171, CMMC 2.0, and other federal frameworks.
- Lead the CMMC Level 2 certification process from initial gap analysis through remediation, System Security Plan (SSP) development, and coordination with third-party assessors (C3PAOs).
- Establish and maintain a risk management framework, conduct regular risk assessments, and present risk posture and mitigation strategies to executive leadership.
- Implement continuous monitoring and compliance automation to maintain adherence to NIST 800-171 controls across all 14 security families.
- Act as the main contact for regulatory audits, government compliance reviews, and customer security questions.
- Work with Engineering, Product, and Operations teams to integrate security and compliance requirements into development workflows.
- Develop and maintain the Plan of Action & Milestones (POA&M) process to track compliance and remediation activities.
