GRC Consultant - Cyber Lead
Core
Drive governance and maturity of non-OS vulnerability management across enterprise application and platform environments, focusing on cyber risk oversight, exception management, and vulnerability treatment strategy.
Role type
Senior GRC Consultant – Cyber Lead
Builds
Enterprise security standards, risk-based treatment plans, and secure-by-design SDLC practices for application and platform environments.
Domain
Cybersecurity, Governance, Risk, and Compliance (GRC)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
GRC and cyber risk expertise, non-OS vulnerability management, risk assessment, exception management, compliance frameworks (ISO 27001, NIST, CIS), stakeholder engagement, DevSecOps/SDLC security practices
Preferred skills
Tooling strategy and automation, training and adoption leadership, secure-by-design practices
Technologies
Qualys, Tenable, Snyk
Responsibilities
Define and implement non-OS vulnerability management frameworks, policies, and standards; Manage remediation exceptions and risk acceptance lifecycle; Perform risk assessments for unremediated vulnerabilities; Lead tooling strategy, evaluation, and automation initiatives; Oversee remediation outcomes from pen tests, audits, and assessments; Provide risk insights to senior leadership and governance forums
Seniority
Senior, hands-on IC
