Senior Consultant, GRC Advisory

United States

Coalfire

Coalfire is a cybersecurity and compliance services company that works with enterprises and tech businesses in FedRAMP, cloud migration, AI Risk, pen


View all jobs at Coalfire

Apply now Apply later

About Coalfire
Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Denver, Colorado with offices across the U.S. and U.K., and we support clients around the world.
But that’s not who we are – that’s just what we do. We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.
Position Summary
You will lead a variety of GRC framework engagements (such as environment scoping, gap analysis, training workshops, policy and procedure development) for framework compliance. Assessing the security and compliance of client firms against regulatory and industry requirements and standards, and against security best practice frameworks, Sr. Consultants play a key role in advising clients in cybersecurity program transformation activities. This role will have a strong understanding of cybersecurity frameworks (program, risk, and controls) and advisory services necessary for a successful audit against those frameworks.  The Senior Consultant will conduct and/or lead interviews with client staff, analyze documents, and develop reports for clients. They will also provide quality control and peer review to other members of the delivery staff. They will work closely with Project Managers, Directors and other Delivery team members to effectively manage project timelines and deliverables.  

What You'll Do

  • You’ll work collaboratively with a team of GRC advisory assessors as a GRC advisor and assist with the planning and delivery of those services.
  • Lead cybersecurity program diagnostic and advisory efforts including plan preparation, review of technical plans, documentation evidence. Be the team lead on engagements against GRC compliance to provide information security technical and non-technical expertise. This includes onsite visits, understanding customer security and compliance requirements and environments, and proposing and delivering packaged offerings or custom solution engagements.
  • Develop technical content, such as procedures and policies, risk management tools, etc., that will be used by our clients to assist them in elevating/build out their security programs for GRC compliance.
  • Manage priorities, tasks and hours on projects in conjunction with the project manager and/or Director to deliver on time and within allocated budgets.  
  • Ensures quality products and services are delivered on time.  
  • Escalates client and project issues to management in a timely manner to inform and engage the necessary resources to address the issue.  
  • Provide mentorship to team members in areas including, but not limited to: risk and controls assessments, technical control implementation, maturity assessments, and a wide range of remediation activities management programs.  
  • Interfaces with clients through entire engagement, interacting will all levels of client organizations. Establish and maintain positive collaborative relationships with clients and stakeholders.  
  • Continuous professional development in maintaining industry specific certifications. Maintains strong depth of knowledge in the practice area.  
  • Collaborates with project managers, quality management, sales and other delivery team members to drive customer satisfaction and meet project deliverables
  • Travel: up to 20%
  • Ability to be successful working remotely
  • Meet project deliverable quality expectations and deadlines

What You'll Bring

  • 3+ years experience performing and or participating in SOC 2 examinations and ISO/IEC 27001:2022 certifications
  • 3+ years of experience in an IT security audit, assessment, compliance, risk management, or data privacy role
  • 3+ years of experience working with any of the following frameworks: ISO/IEC 27701:2019 (and/or its mapped references ISO/IEC 29100:2011, ISO/IEC 27018:2019), ISO/IEC ISO/IEC 9001:2015, Health Insurance Portability and Accountability Act (HIPAA), HITRUST, System and Organization Controls (SOC) 2, or National Institute of Standards and Technology (NIST) frameworks
  • ISO/IEC 27001 Lead Auditor Certificate
  • Bachelor's Degree in Computer Science, Information Systems Management, Information Security, Business or equivalent experience required
  • Knowledge and awareness of the latest information risk, security and compliance innovations, trends, challenges and solutions.
  • Knowledge in one or more of the following standards of information governance, risk and security standards/frameworks and professional practices (ISO/IEC 27001:2022, ISO/IEC 27701:2019 (and/or its mapped references ISO/IEC 29100:2011, ISO/IEC 27018:2019), SO/IEC ISO/IEC 9001:2015, ISO/IEC 42001:2022, Health Insurance Portability and Accountability Act (HIPAA), HITRUST, System and Organization Controls (SOC) 2, or National Institute of Standards and Technology (NIST) frameworks such as NIST SP 800-53 or SP 800-171).Bonus points for knowledge in 2 or more of those listed.
  • Knowledge of the typical enterprise risk and security operational practices.
  • Knowledge of information security related solutions, tools and utilities.
  • Strong initiative and sense of entrepreneurship.  
  • Strong analytical skills, demonstrated problem solving abilities.
  • Strong oral and written communication skills. 
  • Willing to travel up to 20%

Bonus Points

  • CISM, CISSP, CISA, or CCSP certification(s). 
  • ISO 9001:2015 Lead Auditor
  • Certified Information Privacy Professional (CIPP/US)
  • Big Four Advisory/Consulting Experience
  • DevSec Ops Experience
  • AWS, Azure, Google Cloud Platform certification(s)
Why You’ll Want to Join Us
At Coalfire, you’ll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office.
Regardless of location, you’ll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You’ll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And you’ll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.
At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, our Human Resources team at HumanResourcesMB@coalfire.com.
Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  4  1  0

Tags: AWS Azure CCSP CIPP CISA CISM CISSP Cloud Compliance Computer Science GCP Governance HIPAA HITRUST NIST NIST 800-53 Privacy Risk management SOC SOC 2

Perks/benefits: Career development Competitive pay Flex hours Flex vacation Health care Insurance Parental leave Salary bonus Team events

Regions: Remote/Anywhere North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.