Governance, Risk & Compliance (GRC) Consultant
Summary
A 4-month outside-IR35 contract for an experienced GRC consultant to support LCCC's NIST Cybersecurity Framework (CSF) 2.0 maturity assessment programme — developing CSF profile documentation, running capability assessments and gap analysis, and producing evidence and reporting artefacts. Hybrid role based at Canary Wharf, London, with office attendance when needed.
Daily rate: £600-£800 a day
Outside IR35 (subject to final determination and contractual agreement)
Hybrid. Attendance at LCCC offices will be required where necessary to support workshops, stakeholder engagement, evidence gathering and delivery of agreed project outcomes
About the Engagement
- Development of NIST CSF 2.0 profile documentation.
- Assessment of current capabilities against the NIST CSF 2.0 framework.
- Gap analysis and identification of areas for improvement.
- Collection, review and organisation of supporting evidence.
- Production of assessment outputs, reports and associated documentation.
- Recommendations to support improvements in governance, risk and compliance practices.
- Delivery of agreed project artefacts in line with programme milestones.
Deliverables
- NIST CSF 2.0 profile documentation.
- Assessment and gap analysis outputs.
- Evidence repositories and supporting documentation.
- Improvement recommendations and supporting artefacts.
- Documentation required to support the maturity assessment process.
- Demonstrable experience applying the NIST Cybersecurity Framework, ideally NIST CSF 2.0.
- Strong governance, risk and compliance experience within technology and cyber security environments.
- Experience conducting maturity assessments, control assessments or compliance reviews.
- Ability to produce high quality governance, assurance and compliance documentation.
- Experience delivering specialist consultancy services within defined project environments.