Senior GRC Consultant

Scale Up Recruiting Partners

Cancún

Presencial

MXN 1.531.000 - 2.552.000

A tiempo parcial

hace 10 horas
Sé de los primeros/as/es en solicitar esta vacante

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Scale Up Recruiting Partners is assisting a U.S.-based cybersecurity startup to hire a Senior GRC Consultant for a long-term contract. This fully remote role involves leading audit readiness, compliance program development, and risk management across multiple client engagements.

You will own end-to-end GRC activities, including policies, control mappings, evidence collection, and audit support, with direct interaction with executive stakeholders and external auditors. fluency in English required.

Formación

  • 5–7+ years in GRC, compliance, or information security audits.
  • Experience managing multiple client engagements in a consulting setting.
  • Strong expertise with SOC 2 Type I & II and ISO 27001.
  • Experience with GDPR, CCPA/CPRA, or HIPAA.
  • Excellent documentation and technical writing skills.

Responsabilidades

  • Lead audit readiness across SOC 2, ISO 27001, HIPAA, and privacy regulations.
  • Own GRC programs from scoping to evidence collection and remediation guidance.
  • Conduct risk assessments and translate findings into business risks.
  • Design and implement complete GRC programs with policies and controls.
  • Manage vendor security questionnaires and coordinate with SMEs.
  • Build relationships with client leadership and provide status updates.

Conocimientos

GRC
Compliance
Risk management
Client-facing
Documentation

Educación

CISA
CISM
CRISC
ISO 27001 Lead Auditor
ISO 27001 Lead Implementer

Herramientas

Vanta
Drata

Descripción del empleo

Hey! We’re Scale Up, and our client is looking to hire a Senior GRC Consultant.

Type of Employment: Contractor (Long-term)

Work Modality: 100% Remote

Work Schedule: Full-time

Time Zone: U.S. business hours (with flexibility as needed)

Location: LATAM

About Our Client

Our client is a fast-growing U.S.-based cybersecurity and compliance consulting startup that partners with technology companies to build, strengthen, and scale their security and compliance programs. Rather than acting as an external vendor, they work as an extension of their clients' teams, providing embedded security leadership, compliance expertise, and operational support across frameworks such as SOC 2, ISO 27001, HIPAA, GDPR, and more.

This is an opportunity to join a small, highly technical team where you'll have significant ownership, direct client exposure, and the chance to shape security programs for innovative startups.

About The Role

As a Senior GRC Consultant, you will lead audit readiness, compliance program development, and risk management across multiple client engagements. You'll own compliance frameworks end-to-end—from scoping and evidence collection to gap analysis, remediation guidance, and audit support.

This is a senior, client-facing position where you'll independently manage your own engagements while working directly with executive stakeholders and external auditors.

Key Responsibilities
  • Lead compliance readiness engagements including SOC 2 Type I/II, ISO 27001, HIPAA, U.S. state privacy regulations, and UK/EU GDPR.
  • Own GRC platforms such as Vanta, Drata, or similar tools, ensuring compliance monitoring remains fully operational and evidence is continuously maintained.
  • Conduct formal risk assessments using frameworks such as NIST 800-30, translating technical findings into business and compliance risks.
  • Design and implement complete GRC programs, including policies, control frameworks, risk management processes, and evidence collection.
  • Perform internal audits, evaluating both control design and operational effectiveness while preparing audit-ready findings.
  • Manage vendor security questionnaires, coordinating with internal subject matter experts and maintaining reusable knowledge bases.
  • Build strong relationships with client leadership, lead recurring meetings, provide status updates, and manage expectations throughout each engagement.
  • Produce high-quality client deliverables including policies, procedures, risk registers, control matrices, evidence packages, and assessment reports.
What We're Looking For
  • 5–7+ years of hands-on experience in GRC, compliance, or information security audits.
  • Previous consulting or professional services experience managing multiple client engagements.
  • Strong expertise with both:
    • SOC 2 Type I & II
    • ISO 27001 / ISO 27002
  • Experience with one or more additional frameworks such as GDPR, CCPA/CPRA, or HIPAA.
  • Experience building compliance programs from the ground up.
  • Ability to map controls across multiple compliance frameworks.
  • Solid technical understanding of cloud security, IAM, CI/CD pipelines, and security controls.
  • Excellent documentation and technical writing skills.
  • Professional-level English with confidence leading meetings with U.S.-based clients.
Nice to Have
  • Experience working directly with external auditors.
  • Hands-on experience implementing GDPR or U.S. privacy compliance programs.
  • Knowledge of ISO 42001 (AI Management Systems).
  • Certifications such as:
    • CISA
    • CISM
    • CRISC
    • ISO 27001 Lead Auditor
    • ISO 27001 Lead Implementer
    • or equivalent.
Why Join?
  • Join an early-stage, fast-growing cybersecurity startup.
  • Work directly with founders and client leadership.
  • Own high-impact client engagements from start to finish.
  • Help innovative technology companies mature their security and compliance programs.
  • Enjoy long-term remote work with significant autonomy, ownership, and career growth.
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Senior GRC Consultant - Remote Lead, Compliance & Audits
Senior GRC Consultant - Remote Lead, Compliance & Audits

Scale Up Recruiting Partners • Región Centro

Presencial
MXN 1.401.000 - 2.335.000
Senior GRC Consultant
Senior GRC Consultant

Scale Up Recruiting Partners • Región Centro

Presencial
MXN 1.401.000 - 2.335.000
Senior GRC Consultant
Senior GRC Consultant

Scale Up Recruiting Partners • Tijuana

Presencial
MXN 2.034.000 - 3.051.000
Senior GRC Consultant
Senior GRC Consultant

Scale Up Recruiting Partners • Monterrey

Presencial
MXN 1.578.947 - 2.280.701
Senior GRC Consultant - Remote Lead, Compliance Programs
Senior GRC Consultant - Remote Lead, Compliance Programs

Scale Up Recruiting Partners • Tijuana

Presencial
MXN 2.034.000 - 3.051.000
Remote Senior GRC Lead for High-Impact Compliance
Remote Senior GRC Lead for High-Impact Compliance

Scale Up Recruiting Partners • Cancún

Presencial
MXN 1.531.000 - 2.552.000
Senior GRC Consultant - Remote Lead Compliance Programs
Senior GRC Consultant - Remote Lead Compliance Programs

Scale Up Recruiting Partners • Monterrey

Presencial
MXN 1.578.947 - 2.280.701
Senior Security Consultant
Senior Security Consultant

Scale Up Recruiting Partners • Región Centro

Presencial
MXN 2.042.000 - 2.722.000
Senior Security Consultant
Senior Security Consultant

Scale Up Recruiting Partners • Ecatepec de Morelos

Presencial
MXN 2.042.000 - 3.063.000
Information Security Analyst
Information Security Analyst

Scale Up Recruiting Partners • Monterrey

Presencial
MXN 1.201.000 - 1.887.000