Principal/Senior Consultant, Governance, Risk & Compliance
Employment Type: Full-Time | Location: Remote, United States | Occasional travel to client locations for assessments, workshops, interviews, and other project activities
About the Role
Pellera Technologies is seeking an experienced Principal / Senior GRC Consultant to join our growing Cybersecurity Services practice. This role is ideal for a seasoned cybersecurity, audit, risk, and compliance professional who will advise a diverse portfolio of clients, lead complex consulting engagements, and help organizations turn regulatory and security requirements into practical, sustainable improvements.
The Principal/Senior Consultant will lead and contribute to cybersecurity audits, risk and framework assessments, compliance-readiness programs, cloud-security reviews, governance initiatives, and strategic advisory engagements. The role requires moving comfortably between executive conversations, stakeholder interviews, evidence analysis, control testing, technical discussions, and producing high-quality client deliverables. Consultants help clients understand risk, prioritize action, strengthen controls, prepare for high-stakes audits, and build governance programs that support long-term business objectives.
Responsibilities
- Lead Cybersecurity and GRC Consulting Engagements
- Lead complex client engagements from discovery and planning through assessment, reporting, and executive presentation.
- Conduct stakeholder interviews with executives, technology leaders, system owners, control owners, legal and compliance personnel, business leaders, and other subject matter experts.
- Review policies, standards, procedures, system documentation, architecture diagrams, data flows, prior assessments, audit reports, control evidence, technical configurations, and other relevant artifacts.
- Evaluate the design, implementation, and operating effectiveness of cybersecurity, privacy, resiliency, and technology controls.
- Identify control gaps, risks, exceptions, dependencies, and opportunities for improvement.
- Develop pragmatic, risk-based recommendations, remediation roadmaps, plans of action and milestones, maturity models, and prioritized implementation plans.
- Produce polished assessment reports, control workpapers, executive summaries, presentations, dashboards, and other audit-defensible deliverables.
- Present results to technical teams, executives, boards, auditors, assessors, and other client stakeholders.
- Deliver Framework, Regulatory, and Audit Services
- Lead or support advisory, readiness, assessment, audit, and remediation services for frameworks and requirements such as:
- PCI DSS (scoping, readiness assessments, SAQ support, Reports on Compliance, Attestations of Compliance, remediation guidance, and ongoing compliance advisory)
- CMMC and NIST SP 800-171 (readiness assessments, evidence validation, CUI boundary and data-flow analysis, SPRS and POA&M support, remediation roadmaps, mock assessments, and preparation for authorized C3PAO assessments)
- HIPAA Security, Privacy, and Breach Notification Rules (alignment with NIST SP 800-66 and relevant regulatory audit protocols)
- NIST Cybersecurity Framework (NIST CSF)
- NIST SP 800-53 and control-based federal or regulated-industry assessments
- CIS Critical Security Controls
- ISO/IEC 27001 and related information security standards
- ISO 22301 business continuity management
- ISO/IEC 42001 and NIST AI Risk Management Framework (NIST AI RMF)
- Data privacy and governance requirements
- Cloud-security and cloud-governance assessments
- Business continuity, disaster recovery, and business impact analysis
- Third-party and supply-chain risk management
- Cybersecurity program maturity and governance assessments
- Additional frameworks and requirements valued include:
- SOC 1 and SOC 2
- SOX and IT general controls
- COBIT
- HITRUST CSF
- FedRAMP and related federal authorization requirements
- DFARS and FAR cybersecurity clauses
- ISO/IEC 27701
- CSA Cloud Controls Matrix and CSA STAR
- GDPR, CCPA, CPRA, and other national or state privacy regulations
- GLBA, FFIEC, NYDFS Cybersecurity Regulation, NERC CIP, NIS2, TISAX, TX-RAMP, and other industry-specific requirements
- Lead or support advisory, readiness, assessment, audit, and remediation services for frameworks and requirements such as:
- Provide Strategic GRC Advisory
- Help clients establish or mature cybersecurity governance, enterprise risk management, control, compliance, privacy, and assurance programs.
- Develop cybersecurity strategies, target operating models, governance structures, policies, standards, procedures, and multi-year roadmaps.
- Support vCISO, vDPO, GRC-as-a-Service, and strategic program-management engagements.
- Facilitate risk, control, and governance workshops with business and technical stakeholders.
- Support executive and board-level reporting on cybersecurity risk, compliance posture, control effectiveness, and improvement progress.
- Assist clients with audit preparation, regulatory inquiries, customer assurance requests, and third-party assessments.
- Advise on vendor risk management, mergers and acquisitions, security awareness, vulnerability-management governance, incident-response readiness, and cybersecurity investment priorities.
- Bridge GRC and Technology
- Translate regulatory, contractual, risk, and control requirements into actionable language for cloud, infrastructure, security, application, and business teams.
- Assess control implementation across Microsoft Azure, Microsoft 365, AWS, Google Cloud Platform, SaaS, on-premises, hybrid, and multi-cloud environments.
- Review technical evidence involving identity and access management, logging and monitoring, vulnerability management, endpoint protection, network security, encryption, data protection, backup and recovery, secure configuration, and incident response.
- Collaborate with Pellera specialists across cloud, digital workplace, data protection, cybersecurity engineering, artificial intelligence, infrastructure, and managed services.
- Support cloud migration and modernization initiatives where GRC obligations must be integrated into architecture, implementation, and operational processes.
- Contribute to Practice Growth
- Support pre-sales discovery, solution development, project scoping, level-of-effort estimation, proposal development, and client presentations.
- Partner with account teams and solution architects to identify the right combination of GRC, cybersecurity, cloud, data-protection, and infrastructure services.
- Contribute to reusable methodologies, templates, accelerators, workpapers, and delivery standards.
- Mentor other consultants and share knowledge across the practice.
- Develop thought leadership, client briefings, webinars, white papers, or conference content.
- Identify follow-on opportunities based on legitimate client risks, needs, and project findings.
Requirements
- Fifteen or more years of progressively responsible experience across cybersecurity, information technology, governance, risk, compliance, internal audit, external audit, privacy, or related disciplines.
- Experience working in a consulting, professional services, audit, advisory, or client-facing environment.
- Demonstrated ability to independently lead complex cybersecurity or GRC engagements.
- Broad knowledge of cybersecurity control frameworks, regulatory requirements, risk-management practices, and audit methodologies.
- Experience assessing control design and effectiveness, documenting evidence, developing findings, and presenting practical remediation recommendations.
- Strong understanding of IT general controls, control testing, risk assessment, audit evidence, and issue-remediation lifecycle management.
- Proven ability to write polished, accurate, executive-ready reports, presentations, policies, roadmaps, and other client deliverables.
- Strong verbal communication, interviewing, workshop-facilitation, and presentation skills for diverse audiences including executives, auditors, attorneys, compliance leaders, engineers, administrators, and business stakeholders.
- Ability to manage multiple client commitments, deadlines, dependencies, and competing priorities while maintaining delivery quality.
- Willingness to travel occasionally for client assessments and workshops.
- Authorization to work in the United States.
Preferred Qualifications
- Working knowledge of Azure, Microsoft 365, AWS, GCP, hybrid-cloud, SaaS, or on-premises enterprise environments.
- Experience examining technical configurations or evidence related to identity, network security, endpoint security, vulnerability management, logging, monitoring, encryption, data protection, backup, recovery, and cloud-security controls.
- Experience with Microsoft and AWS Commercial & Government Cloud environments, cloud-native security & governance tools, cloud-security posture management, data loss prevention, data classification, and multi-cloud architectures.
- Experience with GRC or integrated risk-management platforms such as ServiceNow GRC/IRM, Archer, OneTrust, Vanta, LogicGate, OpenPages, or comparable technologies.
- Experience developing cybersecurity metrics, KRIs, KPIs, dashboards, risk registers, control libraries, and executive or board reporting.
- Experience with AI governance, AI security, model risk, algorithmic transparency, data privacy, or responsible AI.
- Experience performing technical pre-sales, developing SOWs, estimating consulting effort, or supporting solution design.
- Experience serving clients in healthcare, retail, restaurants, financial services, insurance, manufacturing, aerospace and defense, technology, higher education, government, hospitality, or other highly regulated industries.
Preferred Certifications
- ISACA CISA, CISM, CRISC
- ISC2 CISSP, CGRC, CCSP
- PCI QSA
- CMMC Certified Professional, Certified CMMC Assessor, or Registered Practitioner
- ISO/IEC 27001 Lead Auditor or Lead Implementer
- HITRUST CCSFP or related HITRUST credential
- Microsoft Certified: Cybersecurity Architect Expert or related Microsoft certifications
- AWS Certified Security – Specialty or related AWS certifications