← Todas as vagas

Senior Technical Consultant – Security GRC

Sobre a vaga

• Shape problem statements, engagement scope, assumptions, and success criteria with client sponsors and account teams
• Build workplans, RAID logs, and stakeholder maps
• Facilitate workshops with CISOs, control owners, internal audit, legal, procurement, and business executives
• Manage resistance and conflicting frameworks while driving decisions
• Write and present current-state assessments, target operating models, control crosswalks, risk registers, quantified scenarios, roadmaps, and board narratives
• Coach client staff and transfer methods and capability
• Support pre-sales and scoping, including approach, level of effort, delivery risks, and success criteria
• Assess and design against NIST CSF 1.1 and/or 2.0
• Assess and tailor NIST SP 800-53, preferably Revision 5
• Assess NIST SP 800-171 implementation for CUI, including requirement status, 800-171A-style objectives, CUI flow scoping, POA&Ms, and contractor obligations
• Apply CIS Controls v8 as a prioritized operational control set mapped to CSF and 800-53
• Interpret and assess the CRI Profile
• Design or improve ISO/IEC 27001 ISMS, including scope, SoA, risk assessment and treatment, audit liaison, management review inputs, and certification or surveillance readiness
• Build and maintain crosswalks supporting multiple frameworks with one control, owner, and evidence package
• Design test procedures, challenge evidence quality, and write deficiency and residual-risk narratives
• Prepare clients for internal audits, ISO certification bodies, customer assessments, and 800-171, CRI, and CSF inquiries
• Produce executive summaries for non-specialist leaders
• Own analytical and advisory quality from scoping through readout and knowledge transfer
• Translate overlapping control frameworks into a coherent control and evidence model
• Produce business-usable qualitative and quantified risk positions
• Run engagements covering scope, stakeholders, workshops, issues, deliverables, and next-step decisions

• Highly proficient written and spoken English at an executive, audit, and client-delivery standard
• Demonstrated senior consulting or equivalent client-advisory experience
• Experience scoping ambiguous problems, facilitating senior workshops, managing difficult stakeholders, producing commercial-quality deliverables, defending recommendations under challenge, and transferring methods to the client
• Expertise in NIST Cybersecurity Framework
• Expertise in NIST SP 800-53
• Expertise in NIST SP 800-171
• Expertise in CIS Controls
• Expertise in CRI Profile
• Expertise in ISO/IEC 27001, with working command of ISO/IEC 27002
• End-to-end risk management experience
• Risk quantification experience, including scenarios, ranges, expected loss or equivalent, and explicit assumptions
• Roughly 5+ years in security GRC, risk, audit, or control assurance
• Substantial experience in consulting, professional services, or a comparably senior client-advisory capacity
• Bachelor's degree in a relevant field or equivalent experience
• A writing sample or timed drafting exercise may be required

• Comprehensive health insurance coverage for employees, with options to extend coverage to dependents
• Paid time off and company holidays, along with additional leave benefits as per policy
• Flexible work arrangements, supporting work-life balance
• Learning and development opportunities to support continuous growth and upskilling
• Employee wellness initiatives and programs focused on physical and mental well-being
• Retirement and statutory benefits in line with India regulations
• Inclusive and people-first culture, with a strong focus on collaboration and ownership
• Cross-department training and development
• Sponsoring certifications and credentials for continued learning
• Multi-million-dollar technology lab