GRC Consultant You will run SOC 2 and ISO 27001 programs for a diverse client base owning control implementation and audit readiness from kickoff through external audit. Much of the work is hands-on in client cloud environments assessing AWS and Azure against control requirements hardening what falls short and building evidence that holds up under audit. A multi-year SOC 2 program supports a client expanding through M&A with room to grow into GRC engineering and automation as the practice scales.
Compensation
$160000 to $180000
Logistics
Remote Here's
what you'll be doing
Lead SOC 2 scope expansions and stand up ISO 27001 ISMS programs from scratch for clients
- Assess AWS and Azure environments against compliance controls and flag gaps in configuration identity and cloud posture
- Harden client systems and cloud infrastructure run enterprise patch management and drive vulnerability remediation to resolution
- Operate GRC automation platforms such as Drata Vanta and Secureframe to run evidence collection and audit prep
- Write scripts to automate evidence collection control checks and routine security tasks
- Interpret framework and regulatory requirements and build them into client systems platforms and workflows as controls
- Run audit readiness end to end walkthroughs with control owners evidence collection readiness timelines and coordination with external auditors
- Build and maintain control mappings and crosswalks across SOC 2 ISO 27001 CMMC and NIST 800-171
- Author and maintain compliance policies procedures and accreditation documentation including SSPs POA&Ms DR plans and IR plans
- Automate compliance and audit workflows with integrations APIs and AI tooling
- Perform third-party and vendor risk assessments maintain security questionnaires and mature the third-party risk framework
- Report compliance and risk maturity to executives through metrics and crosswalks
- Facilitate incident response tabletop exercises and maintain runbooks and playbooks
- Evaluate new security products and support proof of concept implementations And what you need to have
- Professional auditing experience
- Hands-on experience leading SOC 2 scope expansions and standing up ISO 27001 ISMS programs from scratch
- Hands-on experience assessing and hardening AWS and Azure environments against compliance controls
- Fluency with GRC automation platforms Drata Vanta Secureframe
- Scripting ability to automate evidence collection and security tasks
- A habit of tracking regulatory trends executive orders and framework updates before clients ask Bonus points for
- CMMC implementation experience
- NIST 800-171 experience
- Microsoft GCC High experience No CTC or sponsorship at this time.