Security Consultant - GRC

Job Description:
  • Support the implementation, maintenance, and continuous improvement of information security compliance programs, specifically focusing on ISO 27001, SOC 1 and SOC 2.
  • Develop, review, and update security policies, procedures, and guidelines to align with relevant compliance frameworks and regulatory requirements.
  • Conduct risk assessments and gap analyses against ISO 27001 and NIST CSF controls to identify areas for improvement and ensure audit readiness.
  • Prepare and compile documentation, evidence, and responses for customer RFIs and audit requests efficiently and accurately.
  • Contribute in identification, assessment, and mitigation of information security risks in accordance with established risk management frameworks.
  • Maintain comprehensive documentation of security controls, compliance activities, and remediation plans.
  • Prepare regular reports on compliance status, key metrics, and areas of concern for management and stakeholders.
  • Perform comprehensive third-party risk assessments to evaluate vendor compliance with information security policies.
  • Ensure effective communication and documentation of third-party risk assessments.

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available