Security Compliance & Privacy Analyst (GRC)
DCL seeks a detail-oriented governance, risk, and compliance (GRC) analyst to keep a Maryland statewide program audit-ready. You will assess security controls, maintain privacy and data-protection procedures for sensitive family and provider information, and assemble the evidence that auditors and State reviewers rely on.
- Location
- Hybrid — Baltimore, MD area (within 50 miles of downtown Baltimore)
- Engagement type
- W-2 (1099 considered)
- Pay range
- $53.00–$65.00 per hour, based on experience and certifications
- Schedule
- Full-time during the 4-month transition-in, then part-time (about 20 hrs/week)
- Start
- Contingent upon contract award (anticipated spring 2027)
This position is contingent upon contract award to DCL’s prime contractor partner and execution of DCL’s subcontract. Anticipated start is spring 2027 (subject to the State’s award timeline), beginning with a four-month transition-in period.
Key responsibilities
- Assess security controls against State of Maryland policy and NIST SP 800-53; document findings and track corrective actions to closure.
- Develop and maintain privacy and data-protection procedures for PII, including data handling, retention, secure transmission, and secure return or deletion of State data.
- Prepare and organize audit evidence supporting SOC 2 Type II, State, and federal audit requests.
- Track 100% completion of required State security and privacy training for program staff.
- Support the Security Plan, security policies, and vendor-risk documentation during transition-in.
Required qualifications
- 3+ years of security compliance, IT audit, or privacy experience.
- At least one of: CISA, CRISC, CIPP/US, CIPT, CAP/CGRC, or Security+.
- Working knowledge of NIST SP 800-53 and privacy principles for PII.
- Strong writing and documentation skills; comfortable working to audit and contract deadlines.
- Authorized to work in the United States; all work must be performed within the continental United States.
- Ability to pass a background check and to complete required State of Maryland security and privacy training and confidentiality agreements before accessing program systems or data.
Preferred qualifications
- Experience supporting public-benefit, human-services, or education programs.
- Familiarity with SOC 2, IRS Publication 1075, or HIPAA control requirements.
- Experience with GRC tools (e.g., ServiceNow GRC, Archer, or similar).
- Veterans and military spouses are encouraged to apply.
Apply for Security Compliance & Privacy Analyst (GRC)
Email a current resume, copies of your certifications, your availability, and confirmation of the pay range to careers@dummarsconsultants.com with the subject line “Security Compliance & Privacy Analyst — DCL Baltimore.” Applications are reviewed on a rolling basis.
Email careers@dummarsconsultants.comDummars Consultants LLC is an Equal Opportunity Employer. As a Service-Disabled Veteran-Owned Small Business (SDVOSB) and SWaM-certified firm, we are committed to a diverse and inclusive workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, veteran status, or any other characteristic protected by federal or Maryland law. All candidate information is handled in confidence.