Senior Technical Consultant - Security GRC
Quick Summary
scope, SoA, risk assessment and treatment, internal audit liai
This is a senior consulting role, not an internal control-operations seat. You will be sold to clients as a credible authority on security GRC. You diagnose program maturity, design target-state operating models, quantify risk in business terms, and leave behind frameworks, artifacts, and decisions the client can run without you.
You must be highly proficient in English. Client deliverables, findings, board packs, statements of work, and live workshops are held to an executive and audit standard. Fluency is not enough. The bar is precise, concise, defensible professional English under time pressure.
You must be expert in NIST CSF, NIST SP 800-53, NIST SP 800-171, CIS Controls, the Cyber Risk Institute (CRI) Profile, and ISO/IEC 27001, and you must be able to manage and quantify risk—not only score it.
You must also be a consultant: structure ambiguous problems, manage senior stakeholders, run workshops, write commercial-quality deliverables, defend recommendations, and transfer capability to the client team.
Why this role is Senior
You are expected to operate with limited supervision on complex, multi-framework engagements. Typical work includes regulatory or contractual readiness (including CUI / 800-171), CSF or CRI profile builds, ISO 27001 ISMS design or certification support, control rationalization across overlapping frameworks, and quantified risk analysis for boards, CISOs, and risk committees.
You will often be the most senior GRC voice in the room. That means you set the method, hold the quality bar, and say clearly when a control, a score, or a “green” status is not the same thing as acceptable residual risk.
Core Mandate
Own the analytical and advisory quality of assigned GRC workstreams from scoping through readout and knowledge transfer.
Translate overlapping control frameworks into one coherent control and evidence model the client can operate.
Produce risk positions that combine sound qualitative judgment with quantification the business can use.
Run the engagement like a consultant: scope, stakeholders, workshops, issues, deliverables, and next-step decisions.
Risk (required)
End-to-end risk management (identify, analyze, evaluate, treat, accept, monitor) and risk quantification (scenarios, ranges, expected loss or equivalent, explicit assumptions). “High / medium / low” without a method is not qualification.
Experience and education
Roughly 5+ years in security GRC, risk, audit, or control assurance, including substantial time in consulting, professional services, or a comparably senior client-advisory capacity. Bachelor’s degree in a relevant field or equivalent experience. Seniority is judged by judgment, writing, and client impact—not title inflation.
Location & Eligibility
Listing Details
- Posted
- September 28, 2026
- First seen
- September 29, 2026
- Last seen
- September 29, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 76%
- Scored at
- September 29, 2026
Signal breakdown
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.