NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Management Consultant in India
5 days ago
Apply with autofill
Apply with autofill
Sisainfosec·5 days ago
5 days ago

Cybersecurity GRC Consultant

Mumbai, IndiaFull-timeMid · 5+ yearsManagement Consultant

Sign up free to see how well your resume matches this role.

Boost your chances at sisainfosec

How you compare FREE

?
Your scoreYour score: not yet known
→
64
Top 10%Top 10%: 64 out of 100

Top 10% of NextRaise users matched against Management Consultant roles in India.

Must-have skills for this role

  • cmmc
  • fedramp
  • nist
  • soc 2

PDF or DOCX · no account needed

Apply faster with autofill FREEThe NextRaise extension autofills your application in one click.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Lead end-to-end cybersecurity GRC and compliance engagements, including scoping, planning, assessment, evidence review, gap analysis, remediation support and final reporting.
  • Perform assessments against CMMC 2.0, FedRAMP, NIST SP 800-171, NIST SP 800-53, ISO 27001, SOC 2 and HITRUST CSF, based on client requirements.
  • Develop and maintain control mappings and crosswalks across CMMC, FedRAMP, NIST, ISO 27001, SOC 2 and HITRUST.
  • Conduct detailed control design and operating effectiveness assessments, including review of policies, procedures, configurations, records and other audit evidence.
  • Evaluate control gaps, determine risk and impact, and develop practical remediation recommendations.
  • Support clients in defining and documenting security controls, policies, procedures, control narratives and evidence requirements.
  • Develop and/or review System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), risk assessments, Statements of Applicability, control matrices and audit workpapers.
  • Support SOC 2 readiness and Type I/Type II assessment activities, including Trust Services Criteria mapping, control testing and evidence evaluation.
  • Support ISO 27001 implementation/readiness/certification and surveillance activities, including ISMS controls, risk treatment and Statement of Applicability.
  • Support HITRUST CSF readiness and validated assessment activities, including control mapping, evidence assessment and remediation tracking.
  • Perform NIST-based cybersecurity assessments using NIST CSF and NIST SP 800-series standards where applicable.
  • Validate control mappings and assessment methodologies against applicable regulatory, industry and framework requirements.

What they're looking for

  • 5+ years of hands-on experience in cybersecurity GRC, IT audit, security compliance or risk consulting.
  • Demonstrated experience delivering one or more of the following: CMMC 2.0, FedRAMP, NIST CSF / NIST SP 800-171 / NIST SP 800-53, ISO 27001, SOC 2, HITRUST CSF
  • Strong understanding of security control frameworks, control objectives, control design, operating effectiveness and evidence-based assessment methodologies.
  • Hands-on experience with control mapping/crosswalks across multiple cybersecurity and compliance frameworks.
  • Experience conducting gap assessments, risk assessments, control testing and evidence validation.
  • Experience preparing or reviewing SSPs, POA&Ms, risk registers, control matrices, audit workpapers and assessment reports.
  • Practical understanding of cloud security, IAM, network security, vulnerability management, logging/monitoring, incident response, data protection, business continuity and third-party risk.
  • Ability to translate technical and regulatory requirements into practical security controls and implementation recommendations.
  • Strong written and verbal communication skills with the ability to communicate effectively with both technical teams and senior management.
  • Ability to work independently in a consulting environment and manage multiple client engagements.

Nice to have

  • CMMC-AB Certified CMMC Professional (CCP) / Certified CMMC Assessor (CCA)
  • FedRAMP / 3PAO assessment experience
  • CISSP
  • CISA
  • CISM
  • CRISC
  • ISO 27001 Lead Auditor / Lead Implementer
  • HITRUST Certified CSF Practitioner / related HITRUST credential

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

Cybersecurity GRC Consultant – CMMC, FedRAMP & Security Compliance

Role Overview

We are looking for a hands-on Cybersecurity GRC Consultant with strong experience in CMMC, FedRAMP, NIST, SOC 2, ISO 27001 and/or HITRUST to lead and deliver cybersecurity compliance and advisory engagements.
The role requires practical experience in control assessment, framework mapping, evidence validation, gap assessment, risk analysis, remediation advisory and audit/report delivery. The ideal candidate should be comfortable working directly with clients, understanding their technology and business environment, translating requirements into actionable controls, and managing engagements from scoping through final deliverables.
This is a delivery-focused consulting role requiring both technical understanding and strong client-facing capabilities.

Key Responsibilities

  • Lead end-to-end cybersecurity GRC and compliance engagements, including scoping, planning, assessment, evidence review, gap analysis, remediation support and final reporting.
  • Perform assessments against CMMC 2.0, FedRAMP, NIST SP 800-171, NIST SP 800-53, ISO 27001, SOC 2 and HITRUST CSF, based on client requirements.
  • Develop and maintain control mappings and crosswalks across CMMC, FedRAMP, NIST, ISO 27001, SOC 2 and HITRUST.
  • Conduct detailed control design and operating effectiveness assessments, including review of policies, procedures, configurations, records and other audit evidence.
  • Evaluate control gaps, determine risk and impact, and develop practical remediation recommendations.
  • Support clients in defining and documenting security controls, policies, procedures, control narratives and evidence requirements.
  • Develop and/or review System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), risk assessments, Statements of Applicability, control matrices and audit workpapers.
  • Support SOC 2 readiness and Type I/Type II assessment activities, including Trust Services Criteria mapping, control testing and evidence evaluation.
  • Support ISO 27001 implementation/readiness/certification and surveillance activities, including ISMS controls, risk treatment and Statement of Applicability.
  • Support HITRUST CSF readiness and validated assessment activities, including control mapping, evidence assessment and remediation tracking.
  • Perform NIST-based cybersecurity assessments using NIST CSF and NIST SP 800-series standards where applicable.
  • Validate control mappings and assessment methodologies against applicable regulatory, industry and framework requirements.
  • Lead client discussions with IT, security, engineering, compliance, risk and audit stakeholders to understand the environment and validate controls.
  • Prepare assessment reports, findings, risk ratings, executive summaries and remediation roadmaps for technical and executive audiences.
  • Coordinate with external assessors, auditors, C3PAOs/3PAOs and other assurance stakeholders where applicable.
  • Maintain assessment quality through structured workpapers, evidence traceability, review procedures and quality assurance.
  • Contribute to development and continuous improvement of GRC methodologies, assessment templates, control libraries and reusable delivery assets.
  • Support presales activities, including scope definition, effort estimation, solutioning and technical proposal inputs.

Required Qualifications

  • 5+ years of hands-on experience in cybersecurity GRC, IT audit, security compliance or risk consulting.
  • Demonstrated experience delivering one or more of the following:
    • CMMC 2.0
    • FedRAMP
    • NIST CSF / NIST SP 800-171 / NIST SP 800-53
    • ISO 27001
    • SOC 2
    • HITRUST CSF
  • Strong understanding of security control frameworks, control objectives, control design, operating effectiveness and evidence-based assessment methodologies.
  • Hands-on experience with control mapping/crosswalks across multiple cybersecurity and compliance frameworks.
  • Experience conducting gap assessments, risk assessments, control testing and evidence validation.
  • Experience preparing or reviewing SSPs, POA&Ms, risk registers, control matrices, audit workpapers and assessment reports.
  • Practical understanding of cloud security, IAM, network security, vulnerability management, logging/monitoring, incident response, data protection, business continuity and third-party risk.
  • Ability to translate technical and regulatory requirements into practical security controls and implementation recommendations.
  • Strong written and verbal communication skills with the ability to communicate effectively with both technical teams and senior management.
  • Ability to work independently in a consulting environment and manage multiple client engagements.

Preferred Qualifications

Certifications in one or more of the following are preferred:
  • CMMC-AB Certified CMMC Professional (CCP) / Certified CMMC Assessor (CCA)
  • FedRAMP / 3PAO assessment experience
  • CISSP
  • CISA
  • CISM
  • CRISC
  • ISO 27001 Lead Auditor / Lead Implementer
  • HITRUST Certified CSF Practitioner / related HITRUST credential
  • SOC 2 / AICPA-related audit or assurance experience

Company

Sisainfosec
Mumbai, India

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Sisainfosec's careers site·first seen 15 Sept 2026·last verified 15 Sept 2026·How we source jobs

Similar jobs

  • IBM WebSphere Liberty SME / Senior Middleware Consultant at Zensar TechnologiesPune, India–match not yet calculated
  • Consultant - TB Diagnostics Expert, Infectious Disease – Tuberculosis at pathDelhi NCR, India–match not yet calculated
  • Associate Consultant at zeissgroupBengaluru, India–match not yet calculated
  • AVP - Know Your Customer Advisory at mufgubMumbai, India–match not yet calculated
  • Credit Portfolio Consultant at Wells FargoHyderabad, India–match not yet calculated

Browse more jobs

  • Management Consultant jobs in India
  • Operations Consultant jobs in India
  • Strategy Consultant jobs in India
  • Business Strategy Analyst jobs in India
  • Management Consultant jobs in United States
  • Management Consultant jobs in Germany