Back to all roles

Compliance Consultant – GRC Practice

Remote-first Full-time Now hiring

Job Description:

  • Lead and execute compliance assessments across one or more regulatory and standards frameworks, including but not limited to SOC 2 Type I/II, ISO 27001, CMMC 2.0, NIST CSF, HIPAA, PCI-DSS, and FedRAMP
  • Manage multiple concurrent engagements across different clients and frameworks with minimal supervision
  • Map overlapping frameworks and identify where controls satisfy multiple standards simultaneously
  • Conduct qualitative and semi-quantitative risk assessments, evaluate control design effectiveness, and recommend compensating or corrective controls appropriate to client operating environments
  • Draft, review, and revise information security policies, procedures, standards, and control narratives
  • Support clients through external audits and certification processes, serving as the primary liaison between the client and auditors during evidence collection phases
  • Contribute meaningfully to the practice's pipeline

Requirements:

  • Minimum bachelor's degree in information systems, computer science, business, law, or a closely related field, or equivalent demonstrated experience
  • Minimum 5 years of experience in compliance, information security, audit, or a directly related advisory function, including at least two years in a consulting or client-facing delivery role
  • Demonstrated hands-on experience with at least two of the following: SOC 2, ISO 27001, CMMC 2.0, NIST CSF, HIPAA, PCI-DSS, or FedRAMP
  • At least one active professional certification — CISA, CISSP, CISM, CRISC, or CCSFP are most relevant to this role
  • Strong written and verbal communication skills, including the ability to convey technical findings to non-technical audiences with clarity and precision

Benefits:

  • Competitive salary
  • Health insurance
  • Professional development opportunities
  • Flexible working arrangements

Apply tot his job Apply To this Job

More remote roles

Senior Governance, Risk, and Compliance Engineer

Remote-first Full-time

IT GRC Advisor (100% Remote)

Remote-first Full-time

Risk Advisory GRC Consultant - Remote (USA)

Remote-first Full-time

SOC/SOX IT Audit Program Ops Manager

Remote-first Full-time

Sr bus systems analyst - grc (bank it) - remote

Remote-first Full-time

GRC Analyst — FedRAMP & Cloud Compliance (Remote)

Remote-first Full-time

IT Auditor - Mid

Remote-first Full-time

Remote E&M Coding Auditor

Remote-first Full-time

Remote Junior Auditor – Banking Operations

Remote-first Full-time

Risk Advisory GRC Consultant - Remote (USA)

Remote-first Full-time

Vision Sales Engineer - México

Remote-first Full-time

Experienced Data Entry Clerk Remote Work From Home - Part-Time Focus Group Panelist

Remote-first Full-time

Executive Assistant, People & Culture (Temp)

Remote-first Full-time

Remote Quality Control Standards Data Analyst – Data Entry, Process Optimization & Insight Generation – arenaflex

Remote-first Full-time

Medical Record Retrieval Specialist - West Virginia

Remote-first Full-time

Experienced Customer Service Representative – Part-Time Remote Opportunity with arenaflex

Remote-first Full-time

Independent Business Consultant (1099/ +)

Remote-first Full-time

Experienced Full Stack Software Engineer – Web & Cloud Application Development at arenaflex

Remote-first Full-time

# Remote Data Entry Specialist – Flexible Part-Time Position for Teens | Entry Level Home-Based Work

Remote-first Full-time

Experienced Remote Data Entry Specialist – Data Management and Quality Assurance at arenaflex

Remote-first Full-time