Jobs · Finance

Principal/Senior Consultant, Governance, Risk & Compliance

Pellera Technologies · United States · 4 days ago
RemoteRemoteFinanceFull-time

Employment Type: Full-Time | Location: Remote, United States | Occasional travel to client locations for assessments, workshops, interviews, and other project activities

About the Role

Pellera Technologies is seeking an experienced Principal / Senior GRC Consultant to join our growing Cybersecurity Services practice. This role is ideal for a seasoned cybersecurity, audit, risk, and compliance professional who will advise a diverse portfolio of clients, lead complex consulting engagements, and help organizations turn regulatory and security requirements into practical, sustainable improvements.

The Principal/Senior Consultant will lead and contribute to cybersecurity audits, risk and framework assessments, compliance-readiness programs, cloud-security reviews, governance initiatives, and strategic advisory engagements. The role requires moving comfortably between executive conversations, stakeholder interviews, evidence analysis, control testing, technical discussions, and producing high-quality client deliverables. Consultants help clients understand risk, prioritize action, strengthen controls, prepare for high-stakes audits, and build governance programs that support long-term business objectives.

Responsibilities

  • Lead Cybersecurity and GRC Consulting Engagements
    • Lead complex client engagements from discovery and planning through assessment, reporting, and executive presentation.
    • Conduct stakeholder interviews with executives, technology leaders, system owners, control owners, legal and compliance personnel, business leaders, and other subject matter experts.
    • Review policies, standards, procedures, system documentation, architecture diagrams, data flows, prior assessments, audit reports, control evidence, technical configurations, and other relevant artifacts.
    • Evaluate the design, implementation, and operating effectiveness of cybersecurity, privacy, resiliency, and technology controls.
    • Identify control gaps, risks, exceptions, dependencies, and opportunities for improvement.
    • Develop pragmatic, risk-based recommendations, remediation roadmaps, plans of action and milestones, maturity models, and prioritized implementation plans.
    • Produce polished assessment reports, control workpapers, executive summaries, presentations, dashboards, and other audit-defensible deliverables.
    • Present results to technical teams, executives, boards, auditors, assessors, and other client stakeholders.
  • Deliver Framework, Regulatory, and Audit Services
    • Lead or support advisory, readiness, assessment, audit, and remediation services for frameworks and requirements such as:
      • PCI DSS (scoping, readiness assessments, SAQ support, Reports on Compliance, Attestations of Compliance, remediation guidance, and ongoing compliance advisory)
      • CMMC and NIST SP 800-171 (readiness assessments, evidence validation, CUI boundary and data-flow analysis, SPRS and POA&M support, remediation roadmaps, mock assessments, and preparation for authorized C3PAO assessments)
      • HIPAA Security, Privacy, and Breach Notification Rules (alignment with NIST SP 800-66 and relevant regulatory audit protocols)
      • NIST Cybersecurity Framework (NIST CSF)
      • NIST SP 800-53 and control-based federal or regulated-industry assessments
      • CIS Critical Security Controls
      • ISO/IEC 27001 and related information security standards
      • ISO 22301 business continuity management
      • ISO/IEC 42001 and NIST AI Risk Management Framework (NIST AI RMF)
      • Data privacy and governance requirements
      • Cloud-security and cloud-governance assessments
      • Business continuity, disaster recovery, and business impact analysis
      • Third-party and supply-chain risk management
      • Cybersecurity program maturity and governance assessments
    • Additional frameworks and requirements valued include:
      • SOC 1 and SOC 2
      • SOX and IT general controls
      • COBIT
      • HITRUST CSF
      • FedRAMP and related federal authorization requirements
      • DFARS and FAR cybersecurity clauses
      • ISO/IEC 27701
      • CSA Cloud Controls Matrix and CSA STAR
      • GDPR, CCPA, CPRA, and other national or state privacy regulations
      • GLBA, FFIEC, NYDFS Cybersecurity Regulation, NERC CIP, NIS2, TISAX, TX-RAMP, and other industry-specific requirements
  • Provide Strategic GRC Advisory
    • Help clients establish or mature cybersecurity governance, enterprise risk management, control, compliance, privacy, and assurance programs.
    • Develop cybersecurity strategies, target operating models, governance structures, policies, standards, procedures, and multi-year roadmaps.
    • Support vCISO, vDPO, GRC-as-a-Service, and strategic program-management engagements.
    • Facilitate risk, control, and governance workshops with business and technical stakeholders.
    • Support executive and board-level reporting on cybersecurity risk, compliance posture, control effectiveness, and improvement progress.
    • Assist clients with audit preparation, regulatory inquiries, customer assurance requests, and third-party assessments.
    • Advise on vendor risk management, mergers and acquisitions, security awareness, vulnerability-management governance, incident-response readiness, and cybersecurity investment priorities.
  • Bridge GRC and Technology
    • Translate regulatory, contractual, risk, and control requirements into actionable language for cloud, infrastructure, security, application, and business teams.
    • Assess control implementation across Microsoft Azure, Microsoft 365, AWS, Google Cloud Platform, SaaS, on-premises, hybrid, and multi-cloud environments.
    • Review technical evidence involving identity and access management, logging and monitoring, vulnerability management, endpoint protection, network security, encryption, data protection, backup and recovery, secure configuration, and incident response.
    • Collaborate with Pellera specialists across cloud, digital workplace, data protection, cybersecurity engineering, artificial intelligence, infrastructure, and managed services.
    • Support cloud migration and modernization initiatives where GRC obligations must be integrated into architecture, implementation, and operational processes.
  • Contribute to Practice Growth
    • Support pre-sales discovery, solution development, project scoping, level-of-effort estimation, proposal development, and client presentations.
    • Partner with account teams and solution architects to identify the right combination of GRC, cybersecurity, cloud, data-protection, and infrastructure services.
    • Contribute to reusable methodologies, templates, accelerators, workpapers, and delivery standards.
    • Mentor other consultants and share knowledge across the practice.
    • Develop thought leadership, client briefings, webinars, white papers, or conference content.
    • Identify follow-on opportunities based on legitimate client risks, needs, and project findings.

Requirements

  • Fifteen or more years of progressively responsible experience across cybersecurity, information technology, governance, risk, compliance, internal audit, external audit, privacy, or related disciplines.
  • Experience working in a consulting, professional services, audit, advisory, or client-facing environment.
  • Demonstrated ability to independently lead complex cybersecurity or GRC engagements.
  • Broad knowledge of cybersecurity control frameworks, regulatory requirements, risk-management practices, and audit methodologies.
  • Experience assessing control design and effectiveness, documenting evidence, developing findings, and presenting practical remediation recommendations.
  • Strong understanding of IT general controls, control testing, risk assessment, audit evidence, and issue-remediation lifecycle management.
  • Proven ability to write polished, accurate, executive-ready reports, presentations, policies, roadmaps, and other client deliverables.
  • Strong verbal communication, interviewing, workshop-facilitation, and presentation skills for diverse audiences including executives, auditors, attorneys, compliance leaders, engineers, administrators, and business stakeholders.
  • Ability to manage multiple client commitments, deadlines, dependencies, and competing priorities while maintaining delivery quality.
  • Willingness to travel occasionally for client assessments and workshops.
  • Authorization to work in the United States.

Preferred Qualifications

  • Working knowledge of Azure, Microsoft 365, AWS, GCP, hybrid-cloud, SaaS, or on-premises enterprise environments.
  • Experience examining technical configurations or evidence related to identity, network security, endpoint security, vulnerability management, logging, monitoring, encryption, data protection, backup, recovery, and cloud-security controls.
  • Experience with Microsoft and AWS Commercial & Government Cloud environments, cloud-native security & governance tools, cloud-security posture management, data loss prevention, data classification, and multi-cloud architectures.
  • Experience with GRC or integrated risk-management platforms such as ServiceNow GRC/IRM, Archer, OneTrust, Vanta, LogicGate, OpenPages, or comparable technologies.
  • Experience developing cybersecurity metrics, KRIs, KPIs, dashboards, risk registers, control libraries, and executive or board reporting.
  • Experience with AI governance, AI security, model risk, algorithmic transparency, data privacy, or responsible AI.
  • Experience performing technical pre-sales, developing SOWs, estimating consulting effort, or supporting solution design.
  • Experience serving clients in healthcare, retail, restaurants, financial services, insurance, manufacturing, aerospace and defense, technology, higher education, government, hospitality, or other highly regulated industries.

Preferred Certifications

  • ISACA CISA, CISM, CRISC
  • ISC2 CISSP, CGRC, CCSP
  • PCI QSA
  • CMMC Certified Professional, Certified CMMC Assessor, or Registered Practitioner
  • ISO/IEC 27001 Lead Auditor or Lead Implementer
  • HITRUST CCSFP or related HITRUST credential
  • Microsoft Certified: Cybersecurity Architect Expert or related Microsoft certifications
  • AWS Certified Security – Specialty or related AWS certifications

Similar jobs

Principal/Senior Consultant

Braun Intertec CorporationKansas City, KS· 2 mo ago
Consulting$108k–$162k/yrapply on braunintertec.wd5.myworkdayjobs.com