About The Position

This is a senior consulting role focused on security Governance, Risk, and Compliance (GRC). The consultant will be a credible authority for clients, diagnosing program maturity, designing target-state operating models, quantifying risk in business terms, and creating frameworks and artifacts that clients can manage independently. The role requires highly proficient English for client deliverables, findings, board packs, statements of work, and workshops, meeting an executive and audit standard. Expertise in NIST CSF, NIST SP 800-53, NIST SP 800-171, CIS Controls, Cyber Risk Institute (CRI) Profile, and ISO/IEC 27001 is essential, along with the ability to manage and quantify risk. The role demands consulting skills such as structuring ambiguous problems, managing senior stakeholders, running workshops, producing high-quality deliverables, defending recommendations, and transferring capabilities to client teams. Seniority is demonstrated by operating with limited supervision on complex, multi-framework engagements, often being the most senior GRC voice, setting methods, and ensuring acceptable residual risk.

Requirements

  • Highly proficient written and spoken English at an executive, audit, and client-delivery standard. Grammar, structure, and tone must be consistently professional.
  • Ability to explain a control failure, a residual-risk position, or a quantified scenario to an engineer, an auditor, and a board member in the register each expects.
  • Demonstrated senior consulting or equivalent client-advisory experience: scoping ambiguous problems, facilitating senior workshops, managing difficult stakeholders, producing commercial-quality deliverables, defending recommendations under challenge, and transferring methods to the client.
  • Internal GRC operations experience alone is not sufficient unless you can show the same client-facing muscle.
  • Frameworks (all required, with working depth—not acronym familiarity): NIST Cybersecurity Framework, NIST SP 800-53, NIST SP 800-171, CIS Controls, CRI Profile, ISO/IEC 27001 (working command of 27002 expected).
  • Risk management (required): End-to-end risk management (identify, analyze, evaluate, treat, accept, monitor) and risk quantification (scenarios, ranges, expected loss or equivalent, explicit assumptions). “High / medium / low” without a method is not qualification.
  • Roughly 5+ years in security GRC, risk, audit, or control assurance, including substantial time in consulting, professional services, or a comparably senior client-advisory capacity.
  • Bachelor’s degree in a relevant field or equivalent experience.

Nice To Haves

  • A writing sample or timed drafting exercise may be required.

Responsibilities

  • Client consulting and engagement leadership: Shape problem statements, engagement scope, assumptions, and success criteria with the client sponsor and the account team.
  • Build workplans, RAID logs, and stakeholder maps; keep delivery on quality even when the client’s evidence or ownership is incomplete.
  • Facilitate workshops with CISOs, control owners, internal audit, legal, procurement, and business executives.
  • Drive decisions, not status meetings. Manage resistance, conflicting frameworks, and “we already have a policy” arguments without losing the room or the facts.
  • Write and present deliverables that survive legal, audit, and executive review: current-state assessments, target operating models, control crosswalks, risk registers, quantified scenarios, roadmaps, and board narratives.
  • Coach client staff so the program does not collapse when the engagement ends. Consulting value is transfer, not slide volume.
  • Support pre-sales and scoping when asked: approach, level of effort, risks to delivery, and what “good” looks like for this client.
  • Framework design, assessment, and rationalization: Assess and design against NIST CSF (1.1 and/or 2.0): profiles, subcategory outcomes, tiers, and CSF as the executive reporting spine.
  • Assess and tailor NIST SP 800-53 (Rev. 5 preferred): control families, baselines, overlays, common/hybrid/system-specific controls, and assessment procedures.
  • Assess NIST SP 800-171 implementation for CUI: requirement status, 800-171A-style objectives, scoping of CUI flows, POA&Ms, and contractor obligation implications.
  • Apply CIS Controls (v8 preferred) as a prioritized operational control set (IG1–IG3), mapped to CSF and 800-53 rather than run as a second bureaucracy.
  • Interpret and assess the CRI Profile, including diagnostic statements and financial-sector or critical-third-party expectations.
  • Design or uplift an ISO/IEC 27001 ISMS: scope, SoA, risk assessment and treatment, internal audit liaison, management review inputs, and certification or surveillance readiness.
  • Build and maintain crosswalks so one control, one owner, and one evidence package can satisfy multiple frameworks.
  • Assurance, evidence, and defensible writing: Design test procedures, challenge evidence quality, and write deficiency and residual-risk narratives that are factual and unambiguous.
  • Prepare clients for internal audit, ISO certification bodies, customer assessments, and 800-171 / CRI / CSF inquiries.
  • Produce executive summaries that a non-specialist leader can act on without a decoder.

Benefits

  • Comprehensive health insurance coverage for employees, with options to extend coverage to dependents
  • Paid time off and company holidays, along with additional leave benefits as per policy
  • Flexible work arrangements, supporting work-life balance
  • Learning and development opportunities to support continuous growth and upskilling
  • Employee wellness initiatives and programs focused on physical and mental well-being
  • Retirement and statutory benefits in line with India regulations
  • Inclusive and people-first culture, with a strong focus on collaboration and ownership
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service