Enterprise Controls Consultant – GRC (2 openings)
Summary
Designs and documents cybersecurity controls aligned with frameworks like NIST and ISO for a large GRC modernization program, working with stakeholders to implement measurable, auditable security measures.
Senior Cybersecurity GRC Consultant - Controls Design & Transformation
Greater Philadelphia area
Hybrid ( three days a week onsite)
$75-$95/hour
The Planet Group has partnered with a Greater Philadelphia area company to locate an Senior Cybersecurity GRC Consultant to support a large-scale enterprise Governance, Risk & Compliance (GRC) modernization initiative.
Candidates must have direct, hands-on experience designing and developing cybersecurity controls. This should include translating cybersecurity risks, policies, standards, and framework requirements into technically meaningful controls that can be implemented by security and technology teams.
We are specifically seeking experience designing controls across cybersecurity domains such as Identity & Access Management (IAM), privileged access, vulnerability management, network security, endpoint security, cloud security, data protection, security logging/monitoring, encryption, secure configuration, or incident response.
Experience primarily focused on control testing, audit execution, evidence collection, compliance assessments, risk assessments, or general GRC activities without direct cybersecurity control design experience will not meet the requirements of this role.
Responsibilities:
- Assess existing cybersecurity and technology controls against policies, standards, risk requirements, audit findings, and regulatory expectations.
- Design and document new and enhanced security controls aligned with frameworks such as NIST 800-53, NIST CSF, CIS Controls, ISO 27001/27002, and COBIT.
- Translate security policies, standards, regulatory requirements, and identified risks into practical, technically sound controls.
- Define clear control objectives, ownership, implementation guidance, testing criteria, monitoring requirements, and evidence requirements.
- Identify redundant, outdated, inconsistent, or overly complex controls and recommend opportunities for consolidation and standardization.
- Partner directly with cybersecurity and technology control owners to validate control design and support implementation.
- Develop and enhance enterprise control libraries, control taxonomies, and mappings across multiple security and regulatory frameworks.
- Facilitate working sessions with Security, Technology, Risk, Compliance, Internal Audit, and business stakeholders to gather requirements and drive agreement on future-state controls.
- Design controls with scalability, automation, and Continuous Controls Monitoring (CCM) in mind.
- Identify opportunities to use automation, analytics, and emerging AI capabilities to improve control monitoring and governance.
- Support broader GRC modernization efforts focused on improving control maturity, governance, regulatory readiness, and operational efficiency.
- 8+ years of experience in cybersecurity governance, GRC, technology risk, controls engineering/design, compliance, internal audit, or a closely related discipline.
- Demonstrated experience designing, developing, modernizing, or transforming cybersecurity or technology controls.
- Strong understanding of the complete control lifecycle, including control design, implementation, testing, evidence collection, monitoring, remediation, and continuous improvement.
- Hands-on experience working with recognized cybersecurity and governance frameworks such as NIST 800-53, NIST CSF, CIS Controls, ISO 27001/27002, and/or COBIT.
- Experience translating policies, technical standards, risk assessments, regulatory requirements, and audit findings into clearly defined and implementable controls.
- Sufficient technical cybersecurity knowledge to collaborate effectively with security engineers, architects, and technology control owners and understand how controls are implemented within enterprise environments.
- Experience working within a large, complex, highly regulated organization; financial services experience is strongly preferred.
- Strong experience facilitating workshops and working across Security, Technology, Risk, Compliance, Audit, and business organizations.
- Excellent written communication and documentation skills, with the ability to turn complex security and regulatory requirements into clear, measurable control language.
- Experience with enterprise-wide GRC modernization, control transformation, or control rationalization initiatives.
- Experience developing enterprise control libraries, taxonomies, and cross-framework mappings.
- Experience designing controls to support Continuous Controls Monitoring (CCM) or automated control testing.
- Financial services, banking, insurance, or other highly regulated industry experience.
- Consulting or advisory experience within a Big Four or other large consulting organization.
- Experience incorporating automation, analytics, or AI into governance, risk, and compliance processes.
- Familiarity with AI governance, AI risk management, or emerging AI regulatory requirements.
- Relevant professional certifications such as CISSP, CISM, CISA, CRISC, CIA, or CPA.
#LI-SC1
#TECH
#Hybrid