Senior GRC Consultant

Scale Up Recruiting Partners

Monterrey

Presencial

MXN 1.578.947 - 2.280.701

A tiempo parcial

hace 10 horas
Sé de los primeros/as/es en solicitar esta vacante

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Scale Up Recruiting Partners is seeking a Senior GRC Consultant for a long-term contract engagement. This 100% remote role serves U.S.-based clients while offering LATAM location flexibility.

You will lead audit readiness, develop compliance programs, and manage risk across multiple client engagements. Expect direct exposure to executive stakeholders and external auditors in a senior, client-facing capacity.

Formación

  • 5–7+ years of hands-on experience in GRC, compliance, or information security audits.

Responsabilidades

  • Lead audit readiness engagements including SOC 2 Type I/II, ISO 27001, HIPAA, GDPR and other regulations.
  • Own GRC platforms such as Vanta or Drata, ensuring continuous evidence collection and monitoring.
  • Conduct risk assessments using frameworks like NIST 800-53/800-30 and translate findings into business risks.
  • Design and implement complete GRC programs with policies, controls, and evidence packages.
  • Prepare audit-ready findings and manage vendor security questionnaires across engagements.

Conocimientos

GRC
Compliance
Information security audits

Herramientas

Vanta
Drata

Descripción del empleo

Hey! We’re Scale Up, and our client is looking to hire a Senior GRC Consultant.

Type of Employment: Contractor (Long-term)

Work Modality: 100% Remote

Work Schedule: Full-time

Time Zone: U.S. business hours (with flexibility as needed)

Location: LATAM

About Our Client

Our client is a fast-growing U.S.-based cybersecurity and compliance consulting startup that partners with technology companies to build, strengthen, and scale their security and compliance programs. Rather than acting as an external vendor, they work as an extension of their clients' teams, providing embedded security leadership, compliance expertise, and operational support across frameworks such as SOC 2, ISO 27001, HIPAA, GDPR, and more.

This is an opportunity to join a small, highly technical team where you'll have significant ownership, direct client exposure, and the chance to shape security programs for innovative startups.

About The Role

As a Senior GRC Consultant, you will lead audit readiness, compliance program development, and risk management across multiple client engagements. You'll own compliance frameworks end-to-end—from scoping and evidence collection to gap analysis, remediation guidance, and audit support.

This is a senior, client-facing position where you'll independently manage your own engagements while working directly with executive stakeholders and external auditors.

Key Responsibilities
  • Lead compliance readiness engagements including SOC 2 Type I/II, ISO 27001, HIPAA, U.S. state privacy regulations, and UK/EU GDPR.
  • Own GRC platforms such as Vanta, Drata, or similar tools, ensuring compliance monitoring remains fully operational and evidence is continuously maintained.
  • Conduct formal risk assessments using frameworks such as NIST 800‑30, translating technical findings into business and compliance risks.
  • Design and implement complete GRC programs, including policies, control frameworks, risk management processes, and evidence collection.
  • Perform internal audits, evaluating both control design and operational effectiveness while preparing audit-ready findings.
  • Manage vendor security questionnaires, coordinating with internal subject matter experts and maintaining reusable knowledge bases.
  • Build strong relationships with client leadership, lead recurring meetings, provide status updates, and manage expectations throughout each engagement.
  • Produce high-quality client deliverables including policies, procedures, risk registers, control matrices, evidence packages, and assessment reports.
What We're Looking For
  • 5–7+ years of hands‑on experience in GRC, compliance, or information security audits.
  • Previous consulting or professional services experience managing multiple client engagements.
  • Strong expertise with both:
    • SOC 2 Type I & II
    • ISO 27001 / ISO 27002
  • Experience with one or more additional frameworks such as GDPR, CCPA/CPRA, or HIPAA.
  • Experience building compliance programs from the ground up.
  • Ability to map controls across multiple compliance frameworks.
  • Solid technical understanding of cloud security, IAM, CI/CD pipelines, and security controls.
  • Excellent documentation and technical writing skills.
  • Professional‑level English with confidence leading meetings with U.S.-based clients.
Nice to Have
  • Experience working directly with external auditors.
  • Hands‑on experience implementing GDPR or U.S. privacy compliance programs.
  • Knowledge of ISO 42001 (AI Management Systems).
  • Certifications such as:
    • CISA
    • CISM
    • CRISC
    • ISO 27001 Lead Auditor
    • ISO 27001 Lead Implementer
    • or equivalent.
Why Join?
  • Join an early‑stage, fast‑growing cybersecurity startup.
  • Work directly with founders and client leadership.
  • Own high‑impact client engagements from start to finish.
  • Help innovative technology companies mature their security and compliance programs.
  • Enjoy long‑term remote work with significant autonomy, ownership, and career growth.
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Senior GRC Consultant — Lead Compliance Programs (Remote)
Senior GRC Consultant — Lead Compliance Programs (Remote)

Scale Up Recruiting Partners • Ecatepec de Morelos

Presencial
MXN 1.525.000 - 2.542.000
Senior GRC Consultant - Remote Lead, Compliance Programs
Senior GRC Consultant - Remote Lead, Compliance Programs

Scale Up Recruiting Partners • Tijuana

Presencial
MXN 2.034.000 - 3.051.000
Remote Senior GRC Lead for High-Impact Compliance
Remote Senior GRC Lead for High-Impact Compliance

Scale Up Recruiting Partners • Cancún

Presencial
MXN 1.531.000 - 2.552.000
Senior GRC Consultant - Remote Lead Compliance Programs
Senior GRC Consultant - Remote Lead Compliance Programs

Scale Up Recruiting Partners • Monterrey

Presencial
MXN 1.578.947 - 2.280.701
Remote Senior Security Consultant: Cloud & Compliance Lead
Remote Senior Security Consultant: Cloud & Compliance Lead

Scale Up Recruiting Partners • Ecatepec de Morelos

Presencial
MXN 2.042.000 - 3.063.000
Senior Security Compliance Specialist
Senior Security Compliance Specialist

Illumiti Inc. • Puebla de Zaragoza

Híbrido
MXN 800.000 - 1.200.000
Flexible working time models
Home office
Company pension scheme
+2
Remote Senior Cloud Security Consultant
Remote Senior Cloud Security Consultant

Scale Up Recruiting Partners • Cancún

Presencial
MXN 2.042.000 - 3.063.000
Senior Cloud Security Consultant - Remote
Senior Cloud Security Consultant - Remote

Scale Up Recruiting Partners • Monterrey

Presencial
MXN 600.000 - 900.000
Senior Cloud Security Consultant — Remote, Client-Facing
Senior Cloud Security Consultant — Remote, Client-Facing

Scale Up Recruiting Partners • Tijuana

Presencial
MXN 2.034.000 - 3.051.000
Remote Work
Direct Client Exposure
Autonomy
+1
Remote GRC & Vendor Security Analyst
Remote GRC & Vendor Security Analyst

Scale Up Recruiting Partners • Monterrey

Presencial
MXN 1.201.000 - 1.887.000