GRC Consultant
Apply NowGRC Consultant
You will own client compliance programs end to end, taking companies from first scoping through external audit across SOC 2, ISO 27001, and CMMC. This is a consulting role run in a VCISO-style model: you own the client relationship and the roadmap, doing the audit and advisory work up front and the hands-on implementation that follows, from standing up the ISMS to configuring the GRC platform to getting into a client's cloud when they need it. The book is varied, startups and scaling companies, including acquisition targets that need to go from zero to compliant fast, so no two engagements look alike and you wear a lot of hats.
Compensation: $150,000 to $170,000
Logistics: Remote (US). Full time.
Here's what you'll be doing:
- Own client compliance programs end to end: scoping, framework selection, control design, evidence, and coordination with the external auditor through to report
- Take clients from zero to audit-ready across SOC 2, ISO 27001, or CMMC, standing up the ISMS, risk methodology, and control set from scratch
- Run audit readiness end to end: walkthroughs with control owners, evidence collection and schedules, readiness timelines, and gap remediation
- Build and maintain control mappings and crosswalks so one piece of evidence answers across frameworks
- Implement and configure GRC automation platforms, primarily Vanta, along with Drata and Secureframe: integrations, control mapping, evidence workflows, and monitoring tests
- Author policies, procedures, and supporting program documentation with named owners and a real review cadence
- Advise clients through their compliance roadmap as needs change, including M&A due diligence and standing up programs on acquisition targets
- Perform third-party and vendor risk assessments and design the security questionnaires behind them
- Get hands-on in client cloud environments when the engagement calls for it: assess AWS and Azure against control requirements, flag identity and configuration gaps, and guide remediation
- Automate the compliance workflow with integrations, APIs, and AI tooling to cut the manual evidence chase
- Facilitate incident response tabletop exercises and maintain runbooks
- Report compliance and risk maturity to client executives with metrics they can act on
And what you need to have:
- Experience running compliance programs end to end, as a consultant or in-house, from scoping through audit readiness
- Hands-on experience standing up SOC 2, ISO 27001, or CMMC programs from scratch (real strength in any one of these, you don't need all three)
- Professional audit or assessment experience, and the presence to be a client's go-to person
- Working fluency with a GRC automation platform, ideally Vanta, or Drata or Secureframe
- A practical, client-first instinct: matching the fix to what the client actually needs rather than the most expensive option
- Comfort in a small, high-autonomy team where you own your clients and wear many hats
Bonus points for:
- Hands-on cloud experience assessing or configuring AWS and Azure
- Scripting or automation ability (Python, Terraform, PowerShell)
- Privacy depth (ISO 27701, GDPR) or AI governance (ISO 42001, NIST AI RMF)
- CMMC, NIST 800-171, or other federal compliance experience
No CTC or sponsorship at this time.