GRC Consultant
Core
Design, develop, test, and evaluate information security controls throughout the lifecycle to ensure business systems operate safely and securely based on risk alignment.
Role type
GRC Consultant (Cyber Assurance / Security Operations Manager)
Builds
Information Security Management Systems, documented Security Management Plans, and risk mitigation strategies.
Domain
Cybersecurity, Governance, Risk, and Compliance (GRC)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Security standards and accreditations expertise, Information Security Management System (ISMS) maintenance, regulatory and legal compliance integration, risk identification and quantification, risk mitigation planning, third-party supplier security verification, security KPI monitoring, continuous improvement facilitation, policy and procedure development, information risk assessment, audit and risk assurance coordination, incident response and root cause analysis, security working group leadership.
Preferred skills
Large-scale infrastructure security solution delivery, NIST CSF/NIST 800-53/NCSC CAF framework knowledge, networking (switching/routing/firewalls), modern security concepts (attack vectors/malware/analytics/threat intelligence), security testing and vulnerability management (pen testing/ITHC/CVSS/CVE), ISO 27001/27002/27017/27108 standards experience, Cloud platform security (AWS/Azure), CISSP/CISM/CCSP/CRISC certifications, Active Directory/Cryptography/IAM/PKI/Server hardening/SIEM/SOAR/virtualization, MITRE ATT&CK, ITIL.
Technologies
NIST CSF, NIST 800-53, NCSC CAF, ISO 27001, ISO 27002, ISO 27017, ISO 27108, AWS, Microsoft Azure, Active Directory, SIEM, SOAR, VMware, MITRE ATT&CK, ITIL, CVSS, CVE.
Responsibilities
Provide security expertise across standards and accreditations; derive and deliver Information Security Management Plans; identify risks and lead mitigation plans; verify partner/supplier compliance; lead GRC development aligned to policy; ensure continuous assessment and reporting for risk-based decisions; challenge processes for continuous improvement; review and verify security control documentation; develop ISMS practices for certification; propose and implement policy changes; perform focused information risk assessments; coordinate audit and risk assurance activities; chair Security Working Groups; monitor security incidents and contribute to response.
Seniority
Mid-to-Senior, hands-on IC with strategic oversight.