yoinka

Governance, Risk & Compliance (GRC) Analyst

CHAOS Industries

Washington D.C.Senior
Sign in to applyVerified 1h ago
Location
Washington D.C.
Work model
On-Site
Level
Senior
Posted
1h ago

Skills

Cybersecurity

About this role

CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage—domain dominance. The company's products are powered by Coherent Distributed Networks (CDN™), empowering warfighters, commercial air operators, and border protection teams to act faster, adapt rapidly, and stay ahead of evolving threats.

CHAOS Industries was founded in 2022 and has raised a total of $1 billion in funding from leading investors, including 8VC, Accel, and Valor Equity Partners. The company is headquartered in Los Angeles, with offices in Washington, D.C., San Francisco, San Diego, Seattle, and London. For more information, please visit www.chaosinc.com.

Role Overview

• Own and mature the CHAOS Industries cybersecurity GRC program by establishing governance structure, policies, standards, expectations, and accountability across CHAOS businesses.

• You'll report to the IT/Cybersecurity Program Director and work daily with IT, Cybersecurity, Physical Security, and Manufacturing – teams with different priorities and vocabulary; therefore, you’ll spend real time translating broad requirements into controls people adopt.

• Build and manage cybersecurity risk processes, including risk registers, findings, vulnerabilities, remediation plans, ownership, escalation, and business acceptance.

• If you enjoy designing frameworks that fit the organization rather than forcing the organization to fit a template, and you want direct input into how a defense company governs risk, this is the seat.

Responsibilities

• Own risk assessments across several departments and maintain the centralized risk register.

• Design and maintain a unified, original control framework tailored to CHAOS Industries' operating environment, including a security-by-design approach to systems development and defined: Maximum Tolerable Downtime (MTD), Recovery Point Objective (RPO), and Recovery Time Objective (RTO) for critical systems.

• Write and maintain policy that goes beyond minimum mandatory compliance, building genuine security maturity rather than satisfying the floor of any one requirement.

• Manage GRC tooling and related workflows to support risk assessments, control monitoring, and reporting.

• Prepare for, coordinate, and help run third-party and certification audits, including evidence collection, gap assessments, and auditor liaison.

• Act as the connective tissue between different department to then develop security and compliance requirements for partner teams and drive them to execution.

• Report regularly to the Program Director and executive stakeholders on risk posture, audit status, and program maturity.

• Onsite presence required 4 days per week.

• Travel: up to 25%, primarily to support Manufacturing and Physical Security control validation across company sites.

• Physical demands: occasional access to manufacturing floor environments, including required PPE and periods of standing or walking during facility walkthroughs.

• Support customer, vendor, supplier, and subcontractor cybersecurity risk management, including questionnaires, contract reviews, security expectations, and customer-facing services.

• Coordinate cybersecurity audits, assessments, evidence requests, customer reviews, and remediation tracking in partnership with Legal, Compliance, commercial teams, IT, and business leaders.

Minimum Requirements

• Bachelor’s degree or equivalent experience in computer science, cybersecurity, information security, Information Technology, Information Assurance, or a related field, or equivalent practical experience.

• Deep knowledge of NIST CSF, NIST RMF, the ISO/IEC 27000 series, UK Cyber Essentials, CMMC/NIST

Listing verified 1h ago. Applications go through the company's official careers site.

← Back to Yoinka

Governance, Risk & Compliance (GRC) Analyst at CHAOS Industries, Washington D.C. | Yoinka