Principal/Senior Consultant, Governance, Risk & Compliance

Posted Aug 25

This is a fully remote position, open to applicants in United States.

📋 Description

• Oversee intricate client engagements from initial discovery and planning through assessment, reporting, and executive presentations.

• Conduct interviews with stakeholders, including executives, technology leaders, system owners, control owners, legal and compliance personnel, business leaders, and subject matter experts.

• Analyze policies, standards, procedures, system documentation, architecture diagrams, data flows, previous assessments, audit reports, control evidence, technical configurations, and other relevant artifacts.

• Assess the design, implementation, and operational effectiveness of cybersecurity, privacy, resiliency, and technology controls.

• Identify control deficiencies, risks, exceptions, dependencies, and areas for enhancement.

• Formulate risk-based recommendations, remediation roadmaps, action plans, maturity models, and prioritized implementation strategies.

• Create assessment reports, control workpapers, executive summaries, presentations, dashboards, and other audit-compliant deliverables.

• Present findings to technical teams, executives, boards, auditors, assessors, and client stakeholders.

• Lead or assist in advisory, readiness, assessment, audit, and remediation services related to cybersecurity, privacy, cloud security, business continuity, third-party risk, and governance frameworks.

• Aid clients in establishing or enhancing cybersecurity governance, enterprise risk management, control, compliance, privacy, and assurance programs.

• Develop cybersecurity strategies, target operating models, governance structures, policies, standards, procedures, and multi-year roadmaps.

• Support vCISO, vDPO, GRC-as-a-Service, and strategic program management engagements.

• Facilitate workshops focused on risk, control, and governance.

• Assist with executive and board-level reporting.

• Help with audit preparations, regulatory inquiries, customer assurance requests, and third-party assessments.

• Provide guidance on vendor risk management, mergers and acquisitions, security awareness, vulnerability management governance, incident response readiness, and cybersecurity investment priorities.

• Transform regulatory, contractual, risk, and control requirements into actionable guidance for technical and business teams.

• Evaluate controls across Azure, Microsoft 365, AWS, Google Cloud Platform, SaaS, on-premises, hybrid, and multi-cloud environments.

• Review technical evidence related to identity and access management, logging and monitoring, vulnerability management, endpoint protection, network security, encryption, data protection, backup and recovery, secure configuration, and incident response.

• Collaborate with Pellera specialists across various technology and cybersecurity disciplines.

• Support initiatives for cloud migration and modernization.

• Assist with pre-sales discovery, solution development, project scoping, estimation, proposal creation, and client presentations.

• Contribute to methodologies, templates, accelerators, workpapers, delivery standards, service development, client education, and thought leadership.

• Mentor junior consultants and identify legitimate follow-on opportunities.


⛳️ Requirements

• A minimum of fifteen years of progressively responsible experience in cybersecurity, information technology, governance, risk, compliance, internal audit, external audit, privacy, or related fields.

• Candidates with a strong combination of consulting expertise, framework knowledge, technical skills, and leadership experience will also be considered.

• Experience in a consulting, professional services, audit, advisory, or client-facing setting.

• Proven ability to independently manage complex cybersecurity or GRC engagements.

• Comprehensive knowledge of cybersecurity control frameworks, regulatory standards, risk management practices, and audit methodologies.

• Proficient in evaluating control design and effectiveness, documenting evidence, developing findings, and presenting actionable remediation recommendations.

• Strong understanding of IT general controls, control testing, risk assessment, audit evidence, and issue remediation lifecycle management.

• Demonstrated ability to produce polished, accurate, executive-ready reports, presentations, policies, roadmaps, and other client deliverables.

• Excellent verbal communication, interviewing, workshop facilitation, and presentation skills.

• Capable of effectively communicating with executives, auditors, attorneys, compliance leaders, engineers, administrators, and business stakeholders.

• Ability to manage multiple client commitments, deadlines, dependencies, and competing priorities while ensuring high-quality delivery.

• Willingness to travel occasionally for client assessments and workshops.

• Authorization to work in the United States.

• Working knowledge of Azure, Microsoft 365, AWS, GCP, hybrid-cloud, SaaS, or on-premises enterprise environments.

• Experience reviewing technical configurations or evidence related to identity, network security, endpoint security, vulnerability management, logging, monitoring, encryption, data protection, backup, recovery, and cloud security controls.

• Familiarity with Microsoft and AWS Commercial & Government Cloud environments, cloud-native security and governance tools, cloud security posture management, data loss prevention, data classification, and multi-cloud architectures.

• Experience with GRC or integrated risk management platforms such as ServiceNow GRC/IRM, Archer, OneTrust, Vanta, LogicGate, OpenPages, or comparable technologies.

• Experience developing cybersecurity metrics, KRIs, KPIs, dashboards, risk registers, control libraries, and executive or board-level reporting.

• Knowledge of AI governance, AI security, model risk, algorithmic transparency, data privacy, or responsible AI.

• Experience in technical pre-sales, developing SOWs, estimating consulting efforts, or supporting solution design.

• Experience serving clients in highly regulated industries.

• One or more preferred certifications, including CISA, CISM, CRISC, CISSP, CGRC, CCSP, PCI QSA, CMMC credentials, ISO/IEC 27001 Lead Auditor or Lead Implementer, HITRUST credentials, Microsoft Azure or AWS security certifications, or other relevant certifications.


🏝️ Benefits

• Remote work arrangement.

• Occasional travel, coordinated in advance when feasible.

• Opportunity to work across various domains such as artificial intelligence, analytics, cloud, digital infrastructure, application modernization, digital workplace, data protection, offensive security, and managed services.

• Engaging and diverse consulting work.

• Collaboration with specialists in cloud, digital workplace, data protection, cybersecurity engineering, artificial intelligence, infrastructure, and managed services.

People also viewed

LabConnect1 day ago

Head of IT Governance, Risk, Compliance

US flagTennessee OnlyFull-timeCompliance
ApplyView job
Ripple Effect1 day ago

Compliance Analyst

US flagMaryland OnlyFull-timeCompliance$85.3k – $98.1k/year
ApplyView job
Binance1 day ago

Team Lead – Compliance Monitoring, Assurance & Testing

AE flagUnited Arab Emirates (UAE) OnlyFull-timeCompliance
ApplyView job
biBerk Business Insurance1 day ago

Claims Compliance Analyst – Workers' Compensation

US flagUnited States OnlyFull-timeCompliance$77k – $96.5k/year
ApplyView job
Doppel1 day ago

Director, Governance, Risk & Compliance

US flagUnited States OnlyFull-timeCompliance
ApplyView job
PingWind Inc. (SDVOSB)1 day ago

Risk and Compliance Analyst

US flagUnited States OnlyFull-timeCompliance
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers