Consultant, GRC Services

InfoHedge Technologies LLC

Tampa (FL)

On-site

USD 75,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

InfoHedge Technologies LLC is seeking a Governance, Risk, and Compliance (GRC) Consultant to manage cybersecurity compliance programs for clients, primarily in the government sector. This role involves operation engagement, compliance assessments, and risk analysis, ensuring adherence to frameworks like NIST and SOC.

The ideal candidate will possess a Bachelor’s Degree, 2-4 years of relevant experience, and strong communication skills. Join a dynamic team focused on delivering top-notch compliance solutions!

Qualifications

  • 2-4 years of experience conducting security and compliance risk assessments.
  • Experience managing multiple clients/projects in parallel.
  • Good understanding of NIST 800-171 and SOC-2 frameworks.

Responsibilities

  • Participates in day-to-day operations and client engagement activities across various projects.
  • Supports the GRC Service Delivery team with assessments of controls and processes.
  • Conducts cybersecurity Risk Assessments and audit liaison activities.

Skills

Client-facing consulting
Security assessments
Project management
Communication skills
Problem identification

Education

Bachelor’s Degree in related field

Job description

About Us

Thrive is a rapidly growing technology solutions provider focusing upon Cloud, Cyber Security, Networking, Disaster Recovery and Managed Services, including Managed GRC Services. Our corporate culture, engineering talent, customer‑centric approach, and focus upon “next generation” services help us stand out amongst our peers. Thrive is on the look‑out for individuals who don’t view their weekdays spent at “a job” but rather look to develop valuable skills that ignite their passion and lead to a CAREER. If you’re attracted to a “work hard, play hard” environment, seeking the guidance, training and experience necessary to build a lucrative career, then welcome to THRIVE!!

Position Overview

The Governance, Risk, and Compliance (GRC) Consultant is a client‑facing role that helps build, manage, and maintain cybersecurity compliance programs for clients across various industries, primarily within the government sector where most clients will be government contractors or sub‑contractor providers that need to comply with government regulations.

The GRC Consultant supports the Assessment, Program Establishment, and Support work required for Abacode’s clients to become and remain compliant with their respective cybersecurity and privacy frameworks. The GRC Consultant develops client reporting and metrics, updates dashboards, and collects and validates evidence/artifacts.

Responsibilities
  • Participates in day‑to‑day operations and client engagement activities across various client projects involving compliance readiness and security assessments.
  • Supports the Abacode GRC Service Delivery team with conducting on‑going and new assessments of controls, processes, and procedures across multiple clients and compliance standards: NIST 800‑171 (CMMC), SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF and CIS.
  • Supports clients with maintaining compliance with such frameworks by guiding them through control execution and evidence collection and review.
  • Supports compliance, policy, procedural, and technical review of client information security and/or compliance program(s), providing maturity and improvement recommendations based on experience and industry best practices.
  • Performs security controls gap analysis and identification based on compliance mandates, standards, and security benchmarks.
  • Documents security controls inventory of client systems within the GRC portals.
  • Conducts general cybersecurity Risk Assessments.
  • Provides tactical guidance aimed at helping clients meet compliance requirements across applicable security standards and frameworks.
  • Performs audit liaison activities, guiding and assisting clients with audit preparation, evidence identification and gathering, and responding to audit questions.
  • Manages compliance requirements across multiple clients in parallel. Works with clients to identify opportunities for improvement for client’s security controls.
  • Builds internal company partnerships and collaborates with team leaders to determine the company’s services, delivery criteria, and solutions for issues that may arise.
  • Supports evidence collection for internal Abacode/Thrive audits.
  • Identifies and makes suggestions for improvements when problems and/or opportunities arise.
  • Keeps up to date with developments in the cybersecurity, privacy, and GRC areas of specialization.
  • Performs other duties as assigned.
Qualifications

Minimum

  • Bachelor’s Degree in related field or relevant work experience.
  • 2‑4 years of experience conducting and documenting security and compliance risk assessments.
  • Experience working in a client‑facing consulting or service delivery capacity.
  • Experience managing multiple clients/projects in parallel.
  • Experience with general project management and customer success/service is strongly desired.
  • Demonstrated understanding of control frameworks and regulatory requirements for NIST 800‑171, NIST‑CSF, SOC‑2, and ISO 27001.
  • Preferred experience with: HIPAA, PCI‑DSS.
  • Good understanding of the Department of Defense CMMC ruling and implications for the Defense Industrial Base.
  • Proven ability to assess risks and controls and identify opportunities for improvement.
  • Excellent written and verbal communication skills along with excellent interpersonal skills. Able to communicate confidently in a clear, concise, and articulate manner - verbally and written in the documentation produced.
  • Ability to work independently and with minimal supervision.
  • Self‑motivated, positive attitude, and a team player.

Preferred

  • Broad knowledge of information technology (basic networking principles), information security (such as identity and access management), and critical data protection practices (basic principles of encryption and sensitive data protection) is highly desirable.
  • Preferred prior experience working with GRC systems/tools.
  • Preferred prior experience with general IT and Security auditing.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Consultant
GRC Consultant

NetCov • United States

On-site
USD 80,000 - 100,000
Principal Security GRC Analyst
Principal Security GRC Analyst

Jobgether • United States

On-site
USD 150,000 - 210,000
High autonomy
Multi-framework exposure
Cloud environment experience
Cybersecurity GRC Professional
Cybersecurity GRC Professional

duvari group • United States

On-site
USD 120,000 - 190,000
GRC analyst
GRC analyst

Frontier Cybersecurity Consulting • Miami (FL)

Hybrid
USD 70,000 - 100,000
Senior GRC Analyst
Senior GRC Analyst

Jobtailor • New York (NY)

On-site
USD 140,000 - 190,000
Practice Lead, GRC Advisory for Shellproof Security
Practice Lead, GRC Advisory for Shellproof Security

The ProActive Technology Group • New York (NY)

On-site
USD 100,000 - 150,000
Competitive salary
Health, vision, and dental benefits
Performance-based incentives
+3
IT Security GRC Analyst
IT Security GRC Analyst

The Phoenix Group • Charlotte (NC)

On-site
USD 85,000 - 120,000
Lead GRC Analyst (IT/Security)
Lead GRC Analyst (IT/Security)

Ultra Clean Technology • Manor (TX)

On-site
USD 90,000 - 120,000
IT GRC Lead Analyst
IT GRC Lead Analyst

Ohio Farmers Insurance Company • Westfield Center (OH)

Hybrid
USD 90,000 - 120,000
GRC Specialist (Governance, Risk & Compliance)
GRC Specialist (Governance, Risk & Compliance)

360CyberX • United States

On-site
USD 70,000 - 90,000