Principal/Senior Consultant, Governance, Risk & Compliance

🏢 Converge Technology Solutions · all Converge Technology Solutions jobs
📍 United States
💰 USD 170,000 - 190,000 / annual
📅 Posted 2026-08-30 · via Himalayas
🏷 Governance-Risk-And-Compliance,Cybersecurity-Consulting,GRC-Consulting,IT-Audit,Security-Compliance,Senior-Governance-Risk-And-Compliance-Specialist,Senior-Risk-Management-Consultant,Senior-Compliance-Consultant,Senior-Consultant-In-Risk-Management,Senior-GRC-Consultant,Principal-GRC-Consultant,Senior-Principal-Consultant,Governance-Risk-And-Compliance-Manager,Senior-Regulatory-Compliance-Consultant
Apply on original site ↗

Principal/Senior Consultant, Governance, Risk & Compliance

Practice: Cybersecurity, Governance, Risk & Compliance Employment Type: Full-Time Location: Remote, United States Travel: Occasional travel to client locations for assessments, workshops, interviews, and other project activities
Position Summary

Pellera Technologies is seeking an experienced Principal / Senior GRC Consultant, to join our growing Cybersecurity Services practice. This is an opportunity for a seasoned cybersecurity, audit, risk, and compliance professional to advise a diverse portfolio of clients, lead complex consulting engagements, and help organizations turn regulatory and security requirements into practical, sustainable improvements.

The Principal/Senior Consultant will lead and contribute to cybersecurity audits, risk and framework assessments, compliance-readiness programs, cloud-security reviews, governance initiatives, and strategic advisory engagements. The role calls for someone who can move comfortably between executive conversations, stakeholder interviews, evidence analysis, control testing, technical discussions, and the production of high-quality client deliverables.

Our consultants are not limited to producing findings. They help clients understand risk, prioritize action, strengthen controls, prepare for high-stake audits and assessments, and build governance programs that support long-term business objectives. Pellera’s established methodology incorporates interviews, evidence gathering, observations, risk and gap analysis, prioritized recommendations, and executive-ready reporting.
What You Will Do

Lead Cybersecurity and GRC Consulting Engagements

Lead complex client engagements from discovery and planning through assessment, reporting, and executive presentation.

Conduct stakeholder interviews with executives, technology leaders, system owners, control owners, legal and compliance personnel, business leaders, and other subject matter experts.

Review policies, standards, procedures, system documentation, architecture diagrams, data flows, prior assessments, audit reports, control evidence, technical configurations, and other relevant artifacts.

Evaluate the design, implementation, and operating effectiveness of cybersecurity, privacy, resiliency, and technology controls.

Identify control gaps, risks, exceptions, dependencies, and opportunities for improvement.

Develop pragmatic, risk-based recommendations, remediation roadmaps, plans of action and milestones, maturity models, and prioritized implementation plans.

Produce polished assessment reports, control workpapers, executive summaries, presentations, dashboards, and other audit-defensible deliverables.

Present results to technical teams, executives, boards, auditors, assessors, and other client stakeholders.

Pellera GRC engagements commonly include structured interviews, documentation and evidence review, control analysis, risk prioritization, and reporting. Depending on the project, Consultants may also perform technical control observations or configuration reviews.

Deliver Framework, Regulatory, and Audit Services

Lead or support advisory, readiness, assessment, audit, and remediation services involving frameworks and requirements such as:

PCI DSS, including scoping, readiness assessments, SAQ support, Reports on Compliance, Attestations of Compliance, remediation guidance, and ongoing compliance advisory

CMMC and NIST SP 800-171, including readiness assessments, evidence validation, CUI boundary and data-flow analysis, SPRS and POA&M support, remediation roadmaps, mock assessments, and preparation for authorized C3PAO assessments

HIPAA Security, Privacy, and Breach Notification Rules, including alignment with NIST SP 800-66 and relevant regulatory audit protocols
NIST Cybersecurity Framework (NIST CSF)

NIST SP 800-53 and control-based federal or regulated-industry assessments
CIS Critical Security Controls

ISO/IEC 27001 and related information security

← All remote jobs

Similar for you