Senior Technical Consultant – Security GRC

Posted 1 day ago

This is a fully remote position, open to applicants in India.

📋 Description

• Define problem statements, engagement scope, assumptions, and success criteria in collaboration with client sponsors and account teams.

• Create work plans, RAID logs, and stakeholder maps.

• Conduct workshops with CISOs, control owners, internal audit, legal, procurement, and business executives.

• Navigate resistance and conflicting frameworks while facilitating decision-making.

• Compose and present current-state assessments, target operating models, control crosswalks, risk registers, quantified scenarios, roadmaps, and board narratives.

• Mentor client personnel and transfer methods and capabilities effectively.

• Assist in pre-sales and scoping activities, including approach, level of effort, delivery risks, and success criteria.

• Evaluate and design strategies in accordance with NIST CSF 1.1 and/or 2.0.

• Evaluate and customize NIST SP 800-53, preferably Revision 5.

• Review NIST SP 800-171 implementation for CUI, including requirement status, 800-171A-style objectives, CUI flow scoping, POA&Ms, and contractor obligations.

• Implement CIS Controls v8 as a prioritized operational control set aligned with CSF and 800-53.

• Analyze and evaluate the CRI Profile.

• Design or enhance ISO/IEC 27001 ISMS, covering scope, SoA, risk assessment and treatment, audit liaison, management review inputs, and certification or surveillance readiness.

• Develop and maintain crosswalks that support multiple frameworks with a single control, owner, and evidence package.

• Create testing procedures, evaluate evidence quality, and draft deficiency and residual-risk narratives.

• Prepare clients for internal audits, ISO certification bodies, customer assessments, and inquiries related to 800-171, CRI, and CSF.

• Generate executive summaries tailored for non-specialist leaders.

• Ensure analytical and advisory quality from scoping through readout and knowledge transfer.

• Convert overlapping control frameworks into a unified control and evidence model.

• Deliver business-relevant qualitative and quantified risk positions.

• Manage engagements addressing scope, stakeholders, workshops, issues, deliverables, and subsequent decision-making.


⛳️ Requirements

• Excellent written and spoken English at an executive, audit, and client-delivery level.

• Proven senior consulting or equivalent client-advisory experience.

• Experience in scoping ambiguous challenges, facilitating senior workshops, managing difficult stakeholders, producing high-quality commercial deliverables, defending recommendations under scrutiny, and transferring methods to clients.

• Proficient knowledge of the NIST Cybersecurity Framework.

• In-depth understanding of NIST SP 800-53.

• Strong expertise in NIST SP 800-171.

• Comprehensive knowledge of CIS Controls.

• Familiarity with the CRI Profile.

• Expertise in ISO/IEC 27001, with a working knowledge of ISO/IEC 27002.

• End-to-end experience in risk management.

• Experience in risk quantification, including scenarios, ranges, expected loss or equivalent, and clear assumptions.

• Approximately 5+ years of experience in security GRC, risk, audit, or control assurance.

• Significant experience in consulting, professional services, or a similarly senior client-advisory role.

• Bachelor's degree in a relevant field or equivalent experience.

• A writing sample or timed drafting exercise may be required.


🏝️ Benefits

• Comprehensive health insurance coverage for employees, with options to extend coverage to dependents.

• Paid time off and company holidays, along with additional leave benefits as per policy.

• Flexible work arrangements to promote work-life balance.

• Opportunities for learning and development to encourage continuous growth and upskilling.

• Employee wellness initiatives and programs focused on physical and mental well-being.

• Retirement and statutory benefits in accordance with Indian regulations.

• An inclusive, people-first culture emphasizing collaboration and ownership.

• Cross-department training and development opportunities.

• Sponsorship for certifications and credentials to support ongoing learning.

• Access to a multi-million-dollar technology lab.

People also viewed

Campbell's12 hours ago

Workday Platform Owner – Integration, Reporting, Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$127.9k – $175.9k/year
ApplyView job
VALCE Talent Solutions12 hours ago

SAP Basis, Security Experience

MX flagMexico OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
The Hello Team13 hours ago

Senior Cybersecurity & Compliance Consultant, HIPAA, NIST, SOC 2

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Anduril Industries14 hours ago

Senior Security Engineer

US flagCalifornia, +1 more stateFull-timeCybersecurity / Security Engineer$1/year
ApplyView job
Anduril Industries14 hours ago

Senior Security Engineer – OT

US flagCalifornia, +1 more stateFull-timeCybersecurity / Security Engineer$1/year
ApplyView job
Optiv15 hours ago

Senior Cybersecurity Advisor – AI

US flagKansas OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers