Lead Security Compliance Advisor (GRC)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
As a Senior Compliance Advisor, you will serve as the primary technical compass guiding modern technology companies through complex federal security waters. You are a senior voice, a trusted advisor, and a hands-on strategist who thrives on the true substance of risk management. You will spend your days collaborating with client leadership to turn dense regulatory burdens into clear, achievable security roadmaps, while stepping up to mentor our delivery team and elevate the quality of everything we build. It is a brilliant opportunity to own your expertise, lead high-stakes engagements, and make an undeniable impact on the safety of cloud-regulated environments. Why This Opportunity is Different
- Be the Expert in the Room: This is a delivery-first playground for true compliance practitioners. Your technical voice matters, and you will directly shape how our clients scale safely.
- Influence & Mentorship: You won’t just manage tasks; you will actively champion the growth of junior consultants, passing down your framework mastery to scale our team’s capabilities.
- Escape the Checklist Mentality: We don’t do mindless box-checking. You will solve real architectural puzzles, bridging the gap between heavy federal standards and modern cloud environments.
- Direct Growth Ownership: Your market insights will directly influence our internal product, success, and leadership teams as we continuously evolve our advisory practice.
Your Mission & Impact
- Architect Federal Roadmaps: Lead the end-to-end delivery of complex compliance and risk engagements. You’ll conduct sharp control assessments, gap analyses, and remediation planning across FISMA, FedRAMP, GovRAMP, and DoD RMF environments.
- Translate the Complex: Turn dense NIST guidelines (800-30, 800-37, 800-53, 800-171) into intuitive, execution-ready roadmaps that clients can seamlessly implement.
- Guard Engagement Quality: Take ultimate pride in the work. You’ll lead the QA process for critical deliverables, ensuring our technical reports and assessments are flawless before they reach the customer.
- Drive the Conversation: Direct technical cybersecurity and risk strategy discussions with executive stakeholders, prospects, and internal product teams.
- Amplify Technical Thought Leadership: Help position the company as an industry authority by translating emerging regulatory shifts into clear guidance via technical articles, webinars, or client briefings.
Requirements
- 5+ years of cybersecurity consulting/assessment experience
- 2+ years leading projects or engagements
- U.S. Federal Framework Mastery (FedRAMP, GovRAMP)
- CMMC and NIST Special Publications (800-53, 800-171, 800-37, 800-30)
- 2+ years of experience building out a cybersecurity compliance practice and implementing standard operating procedures (Creating training materials and supporting documentation)
- 2+ years of relevant cloud experience or one of the following certifications: AWS Cloud Practitioner, Microsoft Azure Fundamentals (AZ-900), or GCP Cloud Digital Leader
- Commercial Frameworks experience (SOC 2, ISO 27001)
Preferred Skills:
- Industry Certifications (CISSP, CISA, CISM, CCSP, or CIPP)
- U.S. Federal Framework Mastery (FISMA, DoD RMF), * Consulting DNA: 5+ years of client-facing cybersecurity consulting and assessment experience, with at least 2 years spent successfully steering project timelines and managing delivery milestones.
- Federal Blueprint Mastery: Deep, practical familiarity with U.S. federal compliance frameworks and the underlying NIST Special Publications (800-30, 800-37, 800-53, 800-171).
- Clear Articulation: Exceptional communication skills with a proven ability to distill complex architectural risks into clear, compelling narratives for both developers and executive boards.
- Growth Mindset: An active interest in commercial frameworks (SOC 2, ISO 27001) and cloud ecosystems, backed by a desire to move fast, test new ideas, and continuously elevate your craft.
- Valued Credentials: A Bachelor’s degree or equivalent technical experience. Holding a CISSP, CISA, CISM, or foundational cloud certification is highly preferred.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
9 Ways to Make Money Hacking
Why Upskilling And Reskilling is Important For Developers
What’s the Difference between a Junior, Mid, and Senior Developer?