Principal/Senior Consultant, Governance, Risk & Compliance
Listed on 2026-10-02
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant, IT Business Analyst
Principal/Senior Consultant, Governance, Risk & Compliance
Practice:
Cybersecurity, Governance, Risk & Compliance
Employment Type:
Full-Time
Location:
Remote, United States Travel:
Occasional travel to client locations for assessments, workshops, interviews, and other project activities
Pellera Technologies is seeking an experienced Principal / Senior GRC Consultant, to join our growing Cybersecurity Services practice. This is an opportunity for a seasoned cybersecurity, audit, risk, and compliance professional to advise a diverse portfolio of clients, lead complex consulting engagements, and help organizations turn regulatory and security requirements into practical, sustainable improvements.
The Principal/Senior Consultant will lead and contribute to cybersecurity audits, risk and framework assessments, compliance-readiness programs, cloud-security reviews, governance initiatives, and strategic advisory engagements. The role calls for someone who can move comfortably between executive conversations, stakeholder interviews, evidence analysis, control testing, technical discussions, and the production of high-quality client deliverables.
Our consultants are not limited to producing findings. They help clients understand risk, prioritize action, strengthen controls, prepare for high-stake audits and assessments, and build governance programs that support long-term business objectives. Pellera’s established methodology incorporates interviews, evidence gathering, observations, risk and gap analysis, prioritized recommendations, and executive-ready reporting.
What You Will DoLead Cybersecurity and GRC Consulting Engagements- Lead complex client engagements from discovery and planning through assessment, reporting, and executive presentation.
- Conduct stakeholder interviews with executives, technology leaders, system owners, control owners, legal and compliance personnel, business leaders, and other subject matter experts.
- Review policies, standards, procedures, system documentation, architecture diagrams, data flows, prior assessments, audit reports, control evidence, technical configurations, and other relevant artifacts.
- Evaluate the design, implementation, and operating effectiveness of cybersecurity, privacy, resiliency, and technology controls.
- Identify control gaps, risks, exceptions, dependencies, and opportunities for improvement.
- Develop pragmatic, risk-based recommendations, remediation roadmaps, plans of action and milestones, maturity models, and prioritized implementation plans.
- Produce polished assessment reports, control work papers, executive summaries, presentations, dashboards, and other audit-defensible deliverables.
- Present results to technical teams, executives, boards, auditors, assessors, and other client stakeholders.
- PCI DSS, including scoping, readiness assessments, SAQ support, Reports on Compliance, Attestations of Compliance, remediation guidance, and ongoing compliance advisory
- CMMC and NIST SP 800-171, including readiness assessments, evidence validation, CUI boundary and data-flow analysis, SPRS and POA&M support, remediation roadmaps, mock assessments, and preparation for authorized C3
PAO assessments - HIPAA Security, Privacy, and Breach Notification Rules, including alignment with NIST SP 800-66 and relevant regulatory audit protocols
- NIST Cybersecurity Framework (NIST CSF)
- NIST SP 800-53 and control-based federal or regulated-industry assessments
- CIS Critical Security Controls
- ISO/IEC 27001 and related information security standards
- ISO 22301 business continuity management
- ISO/IEC 42001 and NIST AI Risk Management Framework (NIST AI RMF)
- Data privacy and governance requirements
- Cloud-security and cloud-governance assessments
- Business continuity, disaster recovery, and business impact analysis
- Third-party and supply-chain risk management
- Cybersecurity program maturity and governance assessments
- Pellera GRC Consultants may perform NIST-aligned GRC programs; PCI DSS ROC assessments & attestations; CMMC readiness, remediation, evidence-validation, and audit-preparation services; cloud-security reviews; data-governance engagements;
Cyber Executive Advisory or vCISO services; and resiliency-focused assessments.
- SOC 1 and SOC 2
- SOX and IT general controls
- COBIT
- HITRUST CSF
- FedRAMP and related federal authorization requirements
- DFARS and FAR cybersecurity clauses
- ISO/IEC 27701
- CSA Cloud…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).