Назад
Company hidden
9 часов назад

Principal/Senior Consultant, Governance, Risk & Compliance (Cybersecurity)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal/Senior Consultant, Governance, Risk & Compliance (Cybersecurity): Leading cybersecurity and GRC consulting engagements, audits, framework assessments, compliance-readiness programs, cloud-security reviews, and governance initiatives with an accent on control effectiveness, risk analysis, regulatory requirements, and executive-ready reporting. Focus on translating complex cybersecurity and compliance requirements into prioritized remediation roadmaps, strengthening governance programs, and advising stakeholders across technical and executive environments.

Location: Remote, United States; occasional travel to client locations may be required for assessments, workshops, interviews, observations, evidence validation, and executive presentations. Authorization to work in the United States is required.

Company

hirify.global is an enterprise technology partner with more than 3,200 employees, providing digital infrastructure, hybrid cloud, cybersecurity, artificial intelligence, and managed services.

What you will do

  • Lead complex cybersecurity and GRC engagements from discovery and planning through assessment, reporting, and executive presentation.
  • Conduct stakeholder interviews and review policies, system documentation, architecture diagrams, audit reports, control evidence, and technical configurations.
  • Evaluate the design, implementation, and operating effectiveness of cybersecurity, privacy, resiliency, and technology controls.
  • Identify risks, control gaps, exceptions, and dependencies, then develop risk-based recommendations, remediation roadmaps, maturity models, and implementation plans.
  • Deliver audits, readiness assessments, regulatory and framework services across PCI DSS, CMMC, NIST, HIPAA, ISO, CIS, privacy, cloud security, business continuity, and third-party risk management.
  • Support governance strategy, vCISO/vDPO services, executive reporting, pre-sales, methodology development, mentoring, and client presentations.

Requirements

  • 15 or more years of progressively responsible experience in cybersecurity, IT, governance, risk, compliance, audit, privacy, or related disciplines.
  • Experience in consulting, professional services, audit, advisory, or other client-facing environments.
  • Ability to independently lead complex cybersecurity or GRC engagements and assess control design and effectiveness.
  • Strong knowledge of cybersecurity control frameworks, regulatory requirements, risk management, audit evidence, control testing, and remediation lifecycle management.
  • Strong written and verbal communication, interviewing, workshop facilitation, presentation, and executive reporting skills.
  • Authorization to work in the United States and willingness to travel occasionally are required.

Nice to have

  • Experience with Azure, Microsoft 365, AWS, GCP, hybrid cloud, SaaS, on-premises, and multi-cloud environments.
  • Experience with GRC platforms such as ServiceNow GRC/IRM, Archer, OneTrust, Vanta, LogicGate, or OpenPages.
  • Experience with AI governance, AI security, model risk, algorithmic transparency, data privacy, or responsible AI.
  • Certifications such as CISA, CISM, CRISC, CISSP, CGRC, CCSP, PCI QSA, CMMC, ISO 27001, HITRUST, Azure, or AWS security certifications.

Culture & Benefits

  • Remote consulting, analysis, documentation, and project collaboration.
  • Occasional client-site travel coordinated in advance whenever practical.
  • Work across cybersecurity, cloud, artificial intelligence, analytics, digital infrastructure, data protection, and managed services.
  • Varied consulting engagements including CMMC, PCI DSS, healthcare security and privacy, cloud tenant assessments, enterprise GRC operating models, AI risk governance, and cybersecurity roadmaps.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →