Jobs › Director of Governance, Risk & Compliance (GRC)
Director of Governance, Risk & Compliance (GRC)
Job at a glance
- Category
- AI Governance
- Work arrangement
- On-site
- Location
- Crownsville, MD
- Posted
- Aug 18, 2026
Free. One click to unsubscribe. We never share your address.
State of Maryland (DoIT) is hiring a Director of Governance, Risk & Compliance (GRC) in Crownsville, MD. This is a AI Governance job in the governance, risk, and compliance field. Review the full details below and apply directly with State of Maryland (DoIT).
The Director of GRC oversees the creation, management, and execution of risk and controls assessments for Maryland's Department of Information Technology. Responsibilities include implementing a statewide GRC system, managing risk registers and corrective action plans, and ensuring compliance with state and federal security frameworks including NIST standards. Oversees agency maturity assessments, vendor risk evaluations, and system authorization assessments; implements and maintains a statewide GRC module generating risk registers and performance metrics; ensures assessments integrate NIST control frameworks and regulatory requirements; and manages compliance with regulations governing PII, PCI, PHI, CJIS, and FTI data. Minimum qualifications: Bachelor's degree and three years' experience managing GRC programs, building or using GRC platforms aligned with NIST/CIS/ISO 27001, developing cybersecurity policies, or executing system and risk assessments. Preferred certifications include CISSP, CISM, CISA, GRCP, CRISC, or PMI-RMP, along with government cybersecurity governance
Full responsibilities and requirements are on State of Maryland (DoIT)'s application page.
Apply for this job →Location and market context
This job is based in Crownsville, MD on-site. Local candidates benefit from being close to State of Maryland (DoIT)'s teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About AI governance jobs
AI governance sits at the intersection of policy, risk, and engineering. Teams are standing up model inventories, use-case intake and review, risk classification, and control monitoring as regulation and board scrutiny of AI intensify. Jobs like this one are typically evaluated against frameworks such as NIST AI RMF, ISO/IEC 42001, the EU AI Act, and internal model-risk and privacy practices.
How to position yourself for this AI governance job
Strong candidates emphasize experience translating policy into operational controls, working across legal, compliance, security, product, and data teams, documenting AI system risks, and supporting governance processes. In your resume and outreach, tie your experience to how State of Maryland (DoIT) would apply NIST AI RMF, ISO/IEC 42001, the EU AI Act, and internal model-risk and privacy practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
More GRC jobs: All GRC jobs · Search by category & location