GRC Solutions Consultant
Remote
Philippines
Contract
1099
Location: Remote
Employment Type: Contract
We are hiring a on behalf of a client that provides security, compliance, and risk advisory services to organizations preparing for federal and commercial security authorizations.
The consultant will support client engagements from initial assessment and scoping through remediation planning, documentation, and audit/readiness preparation. The ideal candidate has hands-on experience with FedRAMP, CMMC, NIST SP 800-53, and NIST SP 800-171, along with strong technical writing and client-facing skills.
Responsibilities
- Conduct current-state assessments of client security and compliance programs, including control walkthroughs, stakeholder interviews, evidence sampling, and system boundary/scoping analysis.
- Perform gap analyses against target frameworks and translate findings into prioritized, practical remediation roadmaps with realistic effort estimates.
- Draft and tailor policies, standards, procedures, and plans based on the client's actual operating environment.
- Develop and maintain compliance documentation, including:
- System Security Plans (SSPs)
- Control narratives and implementation statements
- POA&Ms
- Asset and system inventories
- Data flow and system boundary diagrams
- Conduct internal audits and readiness reviews, including evidence collection and validation, control testing, and findings documentation.
- Perform risk assessments, including asset and threat identification, likelihood and impact scoring, risk register development, and treatment recommendations.
- Prepare clients for third-party assessments through evidence package preparation, mock interviews, and coordination with external assessors and auditors.
- Configure and maintain compliance programs within GRC platforms, including control mapping, evidence automation, and monitoring.
- Produce clear, audit-ready written deliverables and present findings to stakeholders ranging from technical teams to executive leadership.
- Track engagement hours, deliverables, and project progress while proactively communicating risks and potential delays.
- Work independently in client environments and exercise sound professional judgment regarding issues that require escalation.
Qualifications
- 3–5 years of hands-on experience in security compliance, IT audit, GRC, cybersecurity, or a closely related field.
- Demonstrated experience with FedRAMP and NIST SP 800-53 Rev. 5, including:
- Authorization boundary definition
- FIPS 199 categorization
- Control tailoring
- SSP development
- Demonstrated experience with CMMC and NIST SP 800-171, including:
- CUI scoping
- Assessment objective testing against NIST SP 800-171A
- SPRS scoring
- POA&M development
- Strong technical writing skills with the ability to create clear, audit-defensible documentation with minimal editing.
- Ability to explain security and compliance requirements in clear, practical language to technical and non-technical stakeholders.
- Working knowledge of the technical environments to which security controls apply, including:
- Cloud infrastructure
- Identity and access management
- Logging and monitoring
- Encryption
- Vulnerability management
- Ability to work independently in ambiguous or evolving client environments.
- Strong communication, organization, and stakeholder management skills.
- Reliable availability during U.S. business hours for client meetings.
Preferred Qualifications
- Experience with additional frameworks and standards such as:
- ISO 27001
- SOC 2
- HIPAA
- PCI DSS
- StateRAMP
- GDPR
- CCPA
- Hands-on experience administering GRC platforms such as Paramify, Vanta, or Drata.
- Familiarity with Hyperproof, AuditBoard, Onspring, or similar GRC platforms.
- Previous consulting or client-facing advisory experience.
- Experience working with small and mid-sized organizations without a dedicated compliance function.
- Experience on the assessor side through a 3PAO, C3PAO, audit firm, or similar organization.
- Relevant certifications such as:
- CISA
- CISSP
- CCP or CCA
- CRISC
- ISO 27001 Lead Implementer or Lead Auditor
- CISM
- Familiarity with FedRAMP 20x and evolving federal compliance requirements.
- Experience supporting defense industrial base suppliers or federal system integrators.