
Senior GRC Consultant – Federal, Complex Frameworks
Posted Jul 14

Posted Jul 14
This is a fully remote position, open to applicants in India.
• Spearhead the delivery of FedRAMP readiness and authorization support, CMMC Level 1–3 assessments and gap remediation, preparation for HITRUST r2 validated assessments, implementation of NIST 800-53/800-171 controls, and development of System Security Plans (SSP), along with NIST CSF maturity assessments.
• Offer pre-sales technical validation for federal and complex opportunities—these engagements typically require a detailed scoping process prior to contract, unlike standard framework deals.
• Develop and maintain libraries for control mapping, SSP templates, POA&M templates, and evidence-collection playbooks tailored to the requirements of federal frameworks.
• Monitor revisions to frameworks (such as NIST 800-53 Rev 6, the finalization of CMMC rules, and FedRAMP 20x) and promptly update playbooks to reflect these changes—these frameworks operate on regulatory timelines rather than product timelines.
• Establish pricing for federal and complex engagements, accounting for the increased complexity and duration compared to standard framework projects.
• Manage margin and utilization on your portfolio; forecast capacity against specialized skill sets that are more challenging to replace.
• Create AI-assisted control mapping and evidence review playbooks, incorporating more stringent human review processes than standard frameworks due to the consequences of ATO/certification.
• Define QA guardrails specific to federal work, where accuracy is critical due to the potential downstream consequences (including loss of certification or authorization eligibility).
• Clarify the limitations of Sprinto's assessment regarding what it can guarantee in terms of formal certification or authorization outcomes.
• A minimum of 5 years of experience in compliance consulting related to federal or defense sectors, or as an ISSO/ISSM, FedRAMP 3PAO assessor, or CMMC C3PAO assessor.
• Experience in successfully navigating systems through an actual ATO, FedRAMP authorization, or CMMC certification—advisory-only experience is not adequate for this role.
• In-depth knowledge of FedRAMP (Moderate/High baseline), CMMC Level 1–3, HITRUST r2, NIST 800-53, NIST 800-171, and NIST CSF.
• Familiarity with OSCAL/SSP structure is advantageous.
• Proven ability to utilize AI tools to minimize manual tasks and standardize outputs.
• Skilled in translating domain knowledge into reusable templates and guided systems.
• Comfortable managing pricing and margin on a lower-volume, higher-ACV portfolio.
• Exceptional written communication skills for creating SSP/POA&M-level documentation.
• Strong decision-making skills in the face of regulatory uncertainty.
• Preferred qualifications include: CISSP, CISA, CMMC-RP/CMMC-CCA, training as a FedRAMP-recognized assessor, and certification as a NIST 800-171 assessor.
• Work from anywhere: We are fully remote, allowing you the flexibility to choose your workspace, whether it's at home, a café, the mountains, or the beach.
• Co-working covered: If you enjoy co-working, we provide a generous annual allowance to support it.
• We prioritize your growth: We are committed to your development and invest USD 1,000 annually to enhance your skills.
• Unlimited leave: We value your well-being and offer unlimited leave to recharge whenever you need.
• Comprehensive safety net: Health insurance for you and your family with coverage up to INR 10 lakh, accident protection of an additional INR 10 lakh, and life insurance equating to 3 times your annual salary.
• Create your ideal workspace: We contribute INR 35,000 to help you design a setup that suits your needs.
ZoomInfo
Lifelancer
unybrands
Get handpicked remote jobs straight to your inbox weekly.