Jobs › Maryland › Crownsville › Director of Governance, Risk & Compliance (GRC)
Director of Governance, Risk & Compliance (GRC)
State of Maryland (DoIT) is hiring for the role of Director of Governance, Risk & Compliance (GRC), Crownsville, MD (On-site). This is an AI Governance role in the governance, risk, and compliance field. Review the full details below and apply directly with State of Maryland (DoIT).
The Director of GRC oversees the creation, management, and execution of risk and controls assessments for Maryland's Department of Information Technology. Responsibilities include implementing a statewide GRC system, managing risk registers and corrective action plans, and ensuring compliance with state and federal security frameworks including NIST standards. Oversees agency maturity assessments, vendor risk evaluations, and system authorization assessments; implements and maintains a statewide GRC module generating risk registers and performance metrics; ensures assessments integrate NIST control frameworks and regulatory requirements; and manages compliance with regulations governing PII, PCI, PHI, CJIS, and FTI data. Minimum qualifications: Bachelor's degree and three years' experience managing GRC programs, building or using GRC platforms aligned with NIST/CIS/ISO 27001, developing cybersecurity policies, or executing system and risk assessments. Preferred certifications include CISSP, CISM, CISA, GRCP, CRISC, or PMI-RMP, along with government cybersecurity governance experience.
Location and market context
This role is based in Crownsville on-site. Local candidates benefit from being close to State of Maryland (DoIT)'s teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About AI governance roles
AI governance sits at the intersection of policy, risk, and engineering. Teams are standing up model inventories, use-case intake and review, risk classification, and control monitoring as regulation and board scrutiny of AI intensify. Roles like this one are typically evaluated against frameworks such as NIST AI RMF, ISO/IEC 42001, the EU AI Act, and internal model-risk and privacy practices.
How to position yourself for this AI governance role
Strong candidates emphasize experience translating policy into operational controls, working across legal, compliance, security, product, and data teams, documenting AI system risks, and supporting governance processes. In your resume and outreach, tie your experience to how State of Maryland (DoIT) would apply NIST AI RMF, ISO/IEC 42001, the EU AI Act, and internal model-risk and privacy practices, and lead with concrete outcomes rather than duties.
Similar GRC roles
- Intelligence Analyst - Critical Infrastructure Protection · University of Baltimore · Baltimore, MD
- Information Systems Security Manager (ISSM) · University of Maryland · College Park, MD
- Critical & Emerging Technology Research Professional · University of Maryland (ARLIS) · College Park, MD
- Cybersecurity Risk Management Manager · State of Maryland (DoIT) · Crownsville, MD
- Compliance Training Technology Specialist · Johns Hopkins University · Baltimore, MD
- Senior Strategist, AI Governance Field Coordination · Future Matters · San Francisco OR Washington DC, California
- Senior Manager - Data & AI Governance · Mercury · San Francisco, CA
- Principal Program Manager, Cyber Security - Frontier AI Models · Comcast · Philadelphia, PA
More GRC jobs in Crownsville
- Lead, Governance, Risk & Compliance (Remote) · Emergent BioSolutions · Gaithersburg, MD
- Senior Compliance Manager · World Relief · Towson, MD
- Chief Compliance Officer · Institutional Shareholder Services · Rockville, MD
Want to be next in a role like this?
Roles like Director of Governance, Risk & Compliance (GRC) in Crownsville, MD open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.