
GRC Consultant – Governance, Risk, and Compliance
Posted Sep 23

Posted Sep 23
This is a fully remote position, open to applicants in India.
• Develop and uphold corporate security governance frameworks.
• Create information security policies, procedural standards, and control guidelines that align with global best practices.
• Lead thorough enterprise risk assessments.
• Identify vulnerabilities in infrastructure, assess operational impacts, evaluate threat probabilities, and maintain remediation registers.
• Coordinate campaigns for regulatory compliance audit readiness.
• Verify configurations against standards such as ISO 27001, SOC 2 Type II, NIST, PCI-DSS, GDPR, or HIPAA.
• Oversee third-party vendor risk assessment processes.
• Review security posture configurations and SOC reports from external service providers.
• Establish guidelines for contract security data.
• Manage internal control validation audits.
• Assess control effectiveness across identity management systems, change configuration lines, asset trackers, and incident logging frameworks.
• Conduct security awareness programs and compliance training initiatives.
• Develop materials to educate workforce divisions on corporate data protection responsibilities and the risks of social engineering.
• Collaborate with internal executive stakeholders and external auditors.
• Compile compliance evidence packages, document control deficiencies, and present risk posture matrices.
• 5 to 9 years of experience in core information technology audit or security compliance.
• At least 4 years of focused experience in delivering information security governance, conducting risk assessments, and performing compliance audits.
• Strong technical expertise in specialized GRC software ecosystems, such as OneTrust, ServiceNow GRC, and MetricStream.
• Experience with risk modeling frameworks and evidence documentation.
• Comprehensive understanding of information security perimeters, data privacy regulations, identity governance standards, and audit remediation processes.
• Required certification: CISA, CRISC, or CISM.
• CISSP designation is preferred.
• Previous consulting experience in managing complex multi-framework compliance alignments for enterprise cloud infrastructures or global financial institutions is advantageous.
• Remote position.
• Contract employment.
Globalli
Arclin
Stripe
Deepgram
Get handpicked remote jobs straight to your inbox weekly.