Principal/Senior Consultant, Governance, Risk & Compliance
Principal/Senior Consultant, Governance, Risk & Compliance
Practice: Cybersecurity, Governance, Risk & Compliance Employment Type: Full-Time Location: Remote, United States Travel: Occasional travel to client locations for assessments, workshops, interviews, and other project activities
Position Summary
Pellera Technologies is seeking an experienced Principal / Senior GRC Consultant, to join our growing Cybersecurity Services practice. This is an opportunity for a seasoned cybersecurity, audit, risk, and compliance professional to advise a diverse portfolio of clients, lead complex consulting engagements, and help organizations turn regulatory and security requirements into practical, sustainable improvements.
The Principal/Senior Consultant will lead and contribute to cybersecurity audits, risk and framework assessments, compliance-readiness programs, cloud-security reviews, governance initiatives, and strategic advisory engagements. The role calls for someone who can move comfortably between executive conversations, stakeholder interviews, evidence analysis, control testing, technical discussions, and the production of high-quality client deliverables.
Our consultants are not limited to producing findings. They help clients understand risk, prioritize action, strengthen controls, prepare for high-stake audits and assessments, and build governance programs that support long-term business objectives. Pellera’s established methodology incorporates interviews, evidence gathering, observations, risk and gap analysis, prioritized recommendations, and executive-ready reporting.
What You Will Do
Lead Cybersecurity and GRC Consulting Engagements
Lead complex client engagements from discovery and planning through assessment, reporting, and executive presentation.
Conduct stakeholder interviews with executives, technology leaders, system owners, control owners, legal and compliance personnel, business leaders, and other subject matter experts.
Review policies, standards, procedures, system documentation, architecture diagrams, data flows, prior assessments, audit reports, control evidence, technical configurations, and other relevant artifacts.
Evaluate the design, implementation, and operating effectiveness of cybersecurity, privacy, resiliency, and technology controls.
Identify control gaps, risks, exceptions, dependencies, and opportunities for improvement.
Develop pragmatic, risk-based recommendations, remediation roadmaps, plans of action and milestones, maturity models, and prioritized implementation plans.
Produce polished assessment reports, control workpapers, executive summaries, presentations, dashboards, and other audit-defensible deliverables.
Present results to technical teams, executives, boards, auditors, assessors, and other client stakeholders.
Pellera GRC engagements commonly include structured interviews, documentation and evidence review, control analysis, risk prioritization, and reporting. Depending on the project, Consultants may also perform technical control observations or configuration reviews.
Deliver Framework, Regulatory, and Audit Services
Lead or support advisory, readiness, assessment, audit, and remediation services involving frameworks and requirements such as:
PCI DSS, including scoping, readiness assessments, SAQ support, Reports on Compliance, Attestations of Compliance, remediation guidance, and ongoing compliance advisory
CMMC and NIST SP 800-171, including readiness assessments, evidence validation, CUI boundary and data-flow analysis, SPRS and POA&M support, remediation roadmaps, mock assessments, and preparation for authorized C3PAO assessments
HIPAA Security, Privacy, and Breach Notification Rules, including alignment with NIST SP 800-66 and relevant regulatory audit protocols
NIST Cybersecurity Framework (NIST CSF)
NIST SP 800-53 and control-based federal or regulated-industry assessments
CIS Critical Security Controls
ISO/IEC 27001 and related information security