Jobs and Careers
WO

Senior Security Solutions Consultant - Cyber Risk and Strategy

World Wide Technology
Remote - Nationwide, United States, United StatesRemotefull_timeVerifiedPosted 30 Jun 2026
💰 $185,000/yr($146,500/yr$185,000/yr)

About the role

Qualifications:

Required

  • 4–8 years of experience in cybersecurity, IT risk, or compliance with a clear focus on GRC; must include hands-on experience with at least two GRC domains (risk management, compliance program management, policy governance, or third-party risk)
  • Hands-on experience across GRC domains and platforms, including one or more of:
    • Risk Management — enterprise and IT risk assessments, risk register development, risk quantification (FAIR or qualitative), risk treatment planning, and KRI design
    • Compliance Program Management — regulatory gap assessments, controls mapping, audit readiness, evidence collection workflows, and remediation tracking against frameworks such as SOC 2, ISO 27001, FedRAMP, HIPAA, PCI DSS, DORA, or SOX ITGC
    • Policy & Control Governance — policy development and review cycles, control framework design (NIST, CIS, ISO), control testing methodology, and policy exception management
    • Third-Party & Vendor Risk — vendor risk tiering, assessment questionnaire management, contractual control review, and ongoing monitoring program design
    • GRC Platforms — ServiceNow GRC, Archer, OneTrust, Vanta, Drata, or equivalent: workflow configuration, risk and compliance module setup, or reporting and dashboard design
  • Working knowledge of GRC and security frameworks: NIST CSF 2.0, NIST SP 800-53, NIST RMF, ISO 27001/27002, CIS Controls v8, SOC 2 Trust Services Criteria, COBIT, PCI DSS v4, HIPAA Security Rule, SOX ITGC, FedRAMP, and DORA
  • Understanding of core GRC concepts: risk appetite and tolerance, control design vs. control effectiveness, separation of duties, three lines of defense, audit lifecycle, regulatory change management, and data privacy principles

Demonstrated consulting delivery competencies, including:

  • Structured discovery: ability to conduct current-state discovery interviews, gather documentation and evidence, manage information collection across workstreams, and synthesize findings into clear, structured outputs
  • Gap analysis: experience assessing GRC program maturity against frameworks, documenting control gaps, and prioritizing findings by risk and business impact
  • Technical communication: ability to translate risk and compliance findings into clear written deliverables and verbal summaries for technical and working-level client audiences
  • Workshop facilitation: participate in and contribute to discovery sessions, risk workshops, and working-group meetings; begin developing the ability to facilitate independently
  • Deliverable quality: consistent track record of producing accurate, well-structured client deliverables, assessment reports, risk registers, gap analyses, and roadmap presentations, on time and to standard
  • Engagement collaboration: work effectively within project teams; communicate status, risks, and issues proactively to the engagement lead; adapt to shifting priorities and client needs

Preferred

  • Bachelor’s degree in Information Security, Risk Management, Business, or a related field
  • Industry certifications demonstrating GRC knowledge: CISSP, CISM, CISA, CRISC, CGEIT, GRCP, Security+, or equivalent; platform certifications from ServiceNow, OneTrust, or Archer are a strong plus
  • Experience in enterprise environments across financial services, healthcare, retail, manufacturing, or public sector, particularly where compliance intersects with regulatory scrutiny (SOX, HIPAA, PCI DSS, DORA, FedRAMP)
  • Prior consulting experience at a professional services firm, systems integrator, or equivalent client-facing advisory role
  • Familiarity with pre-sales processes: SOW development, effort estimation, or proposal support

Key Competencies

  • GRC domain depth and hands-on program execution
  • Delivery quality and individual accountability
  • Clear technical communication, written and verbal
  • Collaborative team contributor with a growth orientation

Success in this role means executing GRC deliverables with high quality and growing independence, building credibility with client teams through consistent performance, expanding domain depth and consulting skills, and contributing to a practice that clients trust and return to while

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

World Wide Technology

View company profile →