This is a senior consulting role focused on security Governance, Risk, and Compliance (GRC). The consultant will be a credible authority for clients, diagnosing program maturity, designing target-state operating models, quantifying risk in business terms, and creating frameworks and artifacts that clients can manage independently. The role requires highly proficient English for client deliverables, findings, board packs, statements of work, and workshops, meeting an executive and audit standard. Expertise in NIST CSF, NIST SP 800-53, NIST SP 800-171, CIS Controls, Cyber Risk Institute (CRI) Profile, and ISO/IEC 27001 is essential, along with the ability to manage and quantify risk. The role demands consulting skills such as structuring ambiguous problems, managing senior stakeholders, running workshops, producing high-quality deliverables, defending recommendations, and transferring capabilities to client teams. Seniority is demonstrated by operating with limited supervision on complex, multi-framework engagements, often being the most senior GRC voice, setting methods, and ensuring acceptable residual risk.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior