GRC Auditor

Silpa Consulting LLC

Houston (TX)

On-site

USD 90,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible work options
Engagement with executive stakeholders
Long-term relationships with clients

Job summary

A national IT consulting firm is seeking a skilled GRC Auditor to conduct assessments and audits across various frameworks including SOC 2, ISO 27001, and NIST. This role requires experience in governance, risk, and compliance, and involves producing structured audit documentation while engaging with executive stakeholders. Candidates located in Houston, Texas, or those with remote capabilities are encouraged to apply. The position emphasizes the importance of clear communication and effective compliance evaluation.

Qualifications

  • Experience conducting GRC assessments and audits.
  • Knowledge of management frameworks like ISO 27001, SOC 2, or NIST.
  • Strong ability to evaluate policies and controls.
  • Strong communication with CISOs and leadership.

Responsibilities

  • Conduct GRC assessments and audits against various frameworks.
  • Review policies, procedures, and control documentation.
  • Identify compliance gaps and document findings.
  • Identify compliance gaps, document findings, assign risk ratings, and develop prioritized remediation roadmaps.
  • Produce high-quality audit reports and executive summaries tailored for CISO, CIO, and Board-level stakeholders.
  • Support clients through pre-audit readiness assessments and third-party audit preparation.
  • Collaborate with Silpa project leads to define engagement scope, timelines, and deliverable formats.
  • Advise clients on risk treatment options and the business impact of identified compliance gaps.

Skills

GRC assessments
Audit documentation
Effective communication
Client engagement
Compliance evaluations

Tools

OneTrust
ServiceNow GRC
Drata
Vanta
Archer

Job description

Submit your application and resume through our online form. We'll review your qualifications and get back to you soon.

Silpa Companies, LLC is a national IT consulting and staffing firm empowering organizations across multiple industries through a blend of AI adoption, Master Data Management, Data & Analytics, Cybersecurity, Cloud Engineering, DevSecOps/GitOps, Fractional C-Suite leadership, Digital Transformation, and M&A advisory for private equity and software ventures.

Role Description

Silpa Secure is seeking a skilled GRC Auditor for project-based contract engagements supporting our clients across governance, risk, and compliance programs. You will assess clients against industry frameworks, evaluate control environments, identify compliance gaps, and produce actionable audit findings and remediation roadmaps. This role is designed for a compliance and risk practitioner who works well independently, communicates clearly with leadership stakeholders, and delivers structured, client-ready documentation. Engagements may span SOC 2, ISO 27001, NIST CSF, HIPAA, CMMC, PCI DSS, and other regulatory or framework-specific assessments.

Key Responsibilities
  • Conduct GRC assessments and audits against frameworks including SOC 2, ISO 27001, NIST CSF/800-53, HIPAA, CMMC, PCI DSS, and/or state/federal regulatory requirements.
  • Review policies, procedures, and control documentation to evaluate design and operational effectiveness.
  • Interview client personnel, collect evidence, and assess control maturity across security, privacy, and operational domains.
  • Identify compliance gaps, document findings, assign risk ratings, and develop prioritized remediation roadmaps.
  • Produce high-quality audit reports and executive summaries tailored for CISO, CIO, and Board-level stakeholders.
  • Support clients through pre-audit readiness assessments and third-party audit preparation.
  • Collaborate with Silpa project leads to define engagement scope, timelines, and deliverable formats.
  • Advise clients on risk treatment options and the business impact of identified compliance gaps.
What We Are Looking For
  • Demonstrated experience conducting GRC assessments, internal audits, or third-party compliance reviews.
  • Deep working knowledge of two or more of the following: SOC 2, ISO 27001, NIST CSF, NIST 800-53, HIPAA, CMMC, PCI DSS, or FedRAMP.
  • Strong ability to review and evaluate policies, controls, and evidence in an auditor capacity.
  • Skilled at producing structured audit documentation including findings registers, gap analyses, and executive reports.
  • Effective communicator capable of engaging directly with client CISOs, compliance officers, and risk leadership.
  • Self-directed with the ability to manage audit workflows, evidence requests, and client coordination independently.
  • Familiarity with GRC tools and platforms (OneTrust, ServiceNow GRC, Drata, Vanta, Archer) is a plus.
Eligibility Requirements
  • Authorized to work in the U.S.
  • Candidates located in the Houston, Texas area will be given preference; however, remote practitioners will also be considered.
  • Reliable internet connection and ability to travel to client sites when required by engagement scope.
  • Available to begin engagements within a standard mobilization window and responsive during project duration.
Why Join Us?

Silpa Secure's GRC practice works with clients across healthcare, financial services, energy, and technology sectors who are navigating real regulatory obligations and security maturity goals. As a contract GRC Auditor in our network, you will engage with executive-level stakeholders whose organizations take compliance seriously. Your recommendations will directly influence security investment decisions and audit outcomes. We prioritize long-term practitioner relationships. Contractors who deliver quality work become our first call for follow-on and expanded engagements.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity GRC Professional
Cybersecurity GRC Professional

duvari group • United States

On-site
USD 120,000 - 190,000
GRC Analyst
GRC Analyst

Recru • Houston (TX)

Hybrid
USD 90,000 - 120,000
IT Security GRC Analyst
IT Security GRC Analyst

The Phoenix Group • Charlotte (NC)

On-site
USD 85,000 - 120,000
Governance, Risk, & Compliance (GRC) Analyst
Governance, Risk, & Compliance (GRC) Analyst

Districttechgroup • Washington

Hybrid
USD 80,000 - 100,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+2
Senior GRC Analyst
Senior GRC Analyst

Jobtailor • New York (NY)

On-site
USD 140,000 - 190,000
GRC Analyst
GRC Analyst

Glocomms • Dallas (TX)

Hybrid
USD 90,000 - 150,000
Competitive base salary
Annual bonus
Comprehensive medical, dental, and eye
+2
Governance, Risk & Compliance Analyst I
Governance, Risk & Compliance Analyst I

Geographic Solutions, Inc. • Dunedin (FL)

On-site
USD 60,000 - 100,000
Sr. Cybersecurity GRC Analyst (Remote)
Sr. Cybersecurity GRC Analyst (Remote)

TPx • United States

On-site
USD 105,000 - 145,000
Principal Security GRC Analyst
Principal Security GRC Analyst

Jobgether • United States

On-site
USD 150,000 - 210,000
High autonomy
Multi-framework exposure
Cloud environment experience
IT GRC Analyst
IT GRC Analyst

Medasource • Town of Texas (WI), Northern (KY)

Hybrid
USD 76,000 - 110,000