Senior GRC Consultant

Scale Up Recruiting Partners

Región Centro

Presencial

MXN 1.401.000 - 2.335.000

Jornada completa

Hace 10 días
Generador de candidaturas

Una candidatura hecha para este puesto de trabajo: un currículum y una carta de presentación adaptados que responden directamente a la oferta.

Supera los filtros ATS

Descripción de la vacante

Scale Up connects with a fast-growing U.S.-based cybersecurity and compliance startup seeking a Senior GRC Consultant. This is a contractor (long-term), 100% remote from LATAM, with U.S. business hours and flexible scheduling.

You’ll lead audits, build compliance programs, and work directly with executive stakeholders and external auditors. You’ll own GRC initiatives across SOC 2, ISO 27001, HIPAA, GDPR, and related frameworks, shaping security programs for innovative startups while enjoying

Formación

  • 5–7+ years in GRC, compliance, or information security audits.
  • Experience in consulting or professional services managing multiple client engagements.
  • Expertise with SOC 2 Type I & II and ISO 27001/27002.
  • Experience with GDPR/CCPA/CPRA or HIPAA is a plus.
  • Ability to map controls across multiple frameworks.

Responsabilidades

  • Lead audit readiness and risk management across client engagements.
  • Own GRC platforms (Vanta, Drata, or similar) and maintain evidence.
  • Conduct risk assessments using frameworks like NIST 800-30.
  • Design and implement complete GRC programs with policies and controls.
  • Prepare audit-ready findings and reports.
  • Manage vendor security questionnaires and knowledge bases.
  • Lead meetings with client leadership and manage expectations.
  • Produce client deliverables including policies and risk registers.

Conocimientos

GRC
Compliance
SOC 2
ISO 27001
Security frameworks
Cloud security
Technical writing
Client management
English fluency

Descripción del empleo

Hey! We’re Scale Up, and our client is looking to hire a Senior GRC Consultant.

Type of Employment: Contractor (Long-term)

Work Modality: 100% Remote

Work Schedule: Full-time

Time Zone: U.S. business hours (with flexibility as needed)

Location: LATAM

About Our Client

Our client is a fast-growing U.S.-based cybersecurity and compliance consulting startup that partners with technology companies to build, strengthen, and scale their security and compliance programs. Rather than acting as an external vendor, they work as an extension of their clients' teams, providing embedded security leadership, compliance expertise, and operational support across frameworks such as SOC 2, ISO 27001, HIPAA, GDPR, and more.

This is an opportunity to join a small, highly technical team where you'll have significant ownership, direct client exposure, and the chance to shape security programs for innovative startups.

About The Role

As a Senior GRC Consultant, you will lead audit readiness, compliance program development, and risk management across multiple client engagements. You'll own compliance frameworks end-to-end—from scoping and evidence collection to gap analysis, remediation guidance, and audit support.

This is a senior, client-facing position where you'll independently manage your own engagements while working directly with executive stakeholders and external auditors.

Key Responsibilities
  • Lead compliance readiness engagements including SOC 2 Type I/II, ISO 27001, HIPAA, U.S. state privacy regulations, and UK/EU GDPR.
  • Own GRC platforms such as Vanta, Drata, or similar tools, ensuring compliance monitoring remains fully operational and evidence is continuously maintained.
  • Conduct formal risk assessments using frameworks such as NIST 800-30, translating technical findings into business and compliance risks.
  • Design and implement complete GRC programs, including policies, control frameworks, risk management processes, and evidence collection.
  • Perform internal audits, evaluating both control design and operational effectiveness while preparing audit-ready findings.
  • Manage vendor security questionnaires, coordinating with internal subject matter experts and maintaining reusable knowledge bases.
  • Build strong relationships with client leadership, lead recurring meetings, provide status updates, and manage expectations throughout each engagement.
  • Produce high-quality client deliverables including policies, procedures, risk registers, control matrices, evidence packages, and assessment reports.
What We're Looking For
  • 5-7+ years of hands-on experience in GRC, compliance, or information security audits.
  • Previous consulting or professional services experience managing multiple client engagements.
  • Strong expertise with both:
    • SOC 2 Type I & II
    • ISO 27001 / ISO 27002
  • Experience with one or more additional frameworks such as GDPR, CCPA/CPRA, or HIPAA.
  • Experience building compliance programs from the ground up.
  • Ability to map controls across multiple compliance frameworks.
  • Solid technical understanding of cloud security, IAM, CI/CD pipelines, and security controls.
  • Excellent documentation and technical writing skills.
  • Professional-level English with confidence leading meetings with U.S.-based clients.
Nice to Have
  • Experience working directly with external auditors.
  • Hands-on experience implementing GDPR or U.S. privacy compliance programs.
  • Knowledge of ISO 42001 (AI Management Systems).
  • Certifications such as:
    • CISA
    • CISM
    • CRISC
    • ISO 27001 Lead Auditor
    • ISO 27001 Lead Implementer
    • or equivalent.
Why Join?
  • Join an early-stage, fast-growing cybersecurity startup.
  • Work directly with founders and client leadership.
  • Own high-impact client engagements from start to finish.
  • Help innovative technology companies mature their security and compliance programs.
  • Enjoy long-term remote work with significant autonomy, ownership, and career growth.
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Senior GRC Consultant - Remote Lead, Compliance & Audits
Senior GRC Consultant - Remote Lead, Compliance & Audits

Scale Up Recruiting Partners • Región Centro

Presencial
MXN 1.401.000 - 2.335.000
Senior Security Consultant
Senior Security Consultant

Scale Up Recruiting Partners • Cancún

Presencial
MXN 2.042.000 - 3.063.000
Senior Security Consultant
Senior Security Consultant

Scale Up Recruiting Partners • Región Centro

Presencial
MXN 2.042.000 - 2.722.000
Senior Security Consultant
Senior Security Consultant

Scale Up Recruiting Partners • Ecatepec de Morelos

Presencial
MXN 2.042.000 - 3.063.000
Senior Security Consultant
Senior Security Consultant

Scale Up Recruiting Partners • Monterrey

Presencial
MXN 600.000 - 900.000
Senior Security Consultant
Senior Security Consultant

Scale Up Recruiting Partners • Tijuana

Presencial
MXN 2.034.000 - 3.051.000
Remote Work
Direct Client Exposure
Autonomy
+1
Information Security Analyst
Information Security Analyst

Scale Up Recruiting Partners • Monterrey

Presencial
MXN 1.201.000 - 1.887.000
Remote Senior Cloud Security Consultant
Remote Senior Cloud Security Consultant

Scale Up Recruiting Partners • Cancún

Presencial
MXN 2.042.000 - 3.063.000
Senior Security Compliance Specialist
Senior Security Compliance Specialist

Illumiti Inc. • Puebla de Zaragoza

Híbrido
MXN 800.000 - 1.200.000
Flexible working time models
Home office
Company pension scheme
+2
Remote Senior Security Consultant: Cloud & Compliance Lead
Remote Senior Security Consultant: Cloud & Compliance Lead

Scale Up Recruiting Partners • Ecatepec de Morelos

Presencial
MXN 2.042.000 - 3.063.000