Risk Management Specialist
Listed on 2026-09-22
-
IT/Tech
Information Security & Data Protection, IT Consultant, Cybersecurity, IT Business Analyst -
Business
We are seeking an experienced Senior Governance Risk Compliance (GRC) Contractor to provide strategic advisory support for Global Security & Risk Management initiatives. This role will assess current governance, risk, and compliance capabilities, develop future-state operating models, define GRC roadmaps, and provide recommendations that enable scalable, efficient, and risk-informed business operations. The consultant will partner with executive stakeholders to design enterprise GRC processes, improve governance effectiveness, and guide strategic transformation initiatives.
Responsibilities:- Conduct current-state assessments of governance, risk, compliance, and third-party risk capabilities.
- Evaluate existing GRC operating models, processes, controls, and governance structures to identify gaps and improvement opportunities.
- Develop enterprise GRC strategy aligned with business objectives and regulatory requirements.
- Define multi-year GRC roadmaps with prioritized initiatives, milestones, and measurable outcomes.
- Design future-state GRC operating models, including governance structures, roles, responsibilities, and decision-making processes.
- Lead GRC process design across risk management, policy management, compliance, third-party risk, and control lifecycle management.
- Develop strategic recommendations for GRC platform capabilities and process automation.
- Facilitate executive workshops and stakeholder interviews to validate business requirements and future-state designs.
- Advise leadership on governance frameworks, risk management practices, and industry best practices.
- Produce executive ready assessments, recommendations, maturity reports, and transformation plans.
- Define KPIs, KRIs, governance metrics, and reporting frameworks to measure program effectiveness.
- Provide strategic oversight during implementation to ensure solutions align with target operating models.
Bachelor's degree in Information Security, Computer Science, Business, or related field preferred; equivalent experience considered.
CertificationsPreferred:
Relevant GRC, risk, audit, or security certifications such as CRISC, CISA, CISM, CGRC, or similar.
8-10+ years of experience in GRC, risk advisory, governance transformation, compliance, or related consulting roles; experience conducting current-state assessments, maturity reviews, or operating model design; experience developing roadmaps and executive recommendations; familiarity with enterprise risk and compliance frameworks such as NIST CSF, ISO 27001, SOC 2, COSO, or similar; experience in regulated or complex enterprise environments preferred.
Technical Skills- Strong understanding of GRC operating models, governance structures, process design, and control frameworks
- Ability to assess process gaps, define target-state designs, and recommend practical improvements.
- Experience with GRC platforms such as One Trust, Service Now GRC, RSA Archer, Metric Stream, Logic Gate, Audit Board, or equivalent from a strategic or solution-advisory perspective.
- Proficiency in translating assessment findings into roadmaps, presentations, and executive-level reporting.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).