Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
AHEAD is seeking a senior GRC consultant to diagnose program maturity, design target-state operating models, and quantify risk in business terms for client engagements. You will deliver frameworks, artifacts, and decisions that clients can operate independently after engagement.
You must be fluent in professional English and capable of producing executive-ready deliverables under time pressure. This role emphasizes leadership across multi-framework programs and client collaboration.
AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digital transformation.
At AHEAD, we prioritize creating a culture of belonging, where all perspectives and voices are represented, valued, respected, and heard. We create spaces to empower everyone to speak up, make change, and drive the culture at AHEAD.
We are an equal opportunity employer, and do not discriminate based on an individual's race, national origin, color, gender, gender identity, gender expression, sexual orientation, religion, age, disability, marital status, or any other protected characteristic under applicable law, whether actual or perceived.
We embrace all candidates that will contribute to the diversification and enrichment of ideas and perspectives at AHEAD.
This is a senior consulting role, not an internal control-operations seat. You will be sold to clients as a credible authority on security GRC. You diagnose program maturity, design target-state operating models, quantify risk in business terms, and leave behind frameworks, artifacts, and decisions the client can run without you.
You must be highly proficient in English. Client deliverables, findings, board packs, statements of work, and live workshops are held to an executive and audit standard. Fluency is not enough. The bar is precise, concise, defensible professional English under time pressure.
You must be expert in NIST CSF, NIST SP 800-53, NIST SP 800-171, CIS Controls, the Cyber Risk Institute (CRI) Profile, and ISO/IEC 27001, and you must be able to manage and quantify risk—not only score it.
You must also be a consultant: structure ambiguous problems, manage senior stakeholders, run workshops, write commercial-quality deliverables, defend recommendations, and transfer capability to the client team.
You are expected to operate with limited supervision on complex, multi-framework engagements. Typical work includes regulatory or contractual readiness (including CUI / 800-171), CSF or CRI profile builds, ISO 27001 ISMS design or certification support, control rationalization across overlapping frameworks, and quantified risk analysis for boards, CISOs, and risk committees.
You will often be the most senior GRC voice in the room. That means you set the method, hold the quality bar, and say clearly when a control, a score, or a “green” status is not the same thing as acceptable residual risk.
Own the analytical and advisory quality of assigned GRC workstreams from scoping through readout and knowledge transfer.
Translate overlapping control frameworks into one coherent control and evidence model the client can operate.
Produce risk positions that combine sound qualitative judgment with quantification the business can use.
Run the engagement like a consultant: scope, stakeholders, workshops, issues, deliverables, and next-step decisions.
Highly proficient written and spoken English at an executive, audit, and client-delivery standard. Grammar, structure, and tone must be consistently professional. You can explain a control failure, a residual-risk position, or a quantified scenario to an engineer, an auditor, and a board member in the register each expects. A writing sample or timed drafting exercise may be required.
Demonstrated senior consulting or equivalent client-advisory experience: scoping ambiguous problems, facilitating senior workshops, managing difficult stakeholders, producing commercial-quality deliverables, defending recommendations under challenge, and transferring methods to the client. Internal GRC operations experience alone is not sufficient unless you can show the same client-facing muscle.
End-to-end risk management (identify, analyze, evaluate, treat, accept, monitor) and risk quantification (scenarios, ranges, expected loss or equivalent, explicit assumptions). “High / medium / low” without a method is not qualification.
Roughly 5+ years in security GRC, risk, audit, or control assurance, including substantial time in consulting, professional services, or a comparably senior client-advisory capacity. Bachelor’s degree in a relevant field or equivalent experience. Seniority is judged by judgment, writing, and client impact—not title inflation.
Through our daily work and internal groups like Moving Women AHEAD and RISE AHEAD, we value and benefit from diversity of people, ideas, experience, and everything in between.
We fuel growth by stacking our office with top-notch technologies in a multi-million-dollar lab, by encouraging cross department training and development, sponsoring certifications and credentials for continued learning.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.