> Markdown version of [/jobs/ext/241428-risk-advisory-grc-consultant-remote-usa](https://www.wearedevelopers.com/jobs/ext/241428-risk-advisory-grc-consultant-remote-usa). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Risk Advisory GRC Consultant - Remote (USA) - **Company:** ECHELON RISK, LLC - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Technology Audit, PCI Data Security Standards, Smartsuite, IT General Controls (ITGC) - **Published:** May 20, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=47028571d94e7706 ## About the Role Do you have a valid CPA license?, Do you have a valid Certified Internal Auditor certification?, Do you have experience in Security assessment?, * 2-4 years of hands-on experience in IT audit, compliance, or GRC consulting, with a focus on SOC 2 Type I/II audits, ISO 27001 assessments, or related attestation engagements * Demonstrated understanding of IT General Controls (ITGCs), Trust Services Criteria, and audit standards such as SSAE 18 or ISAE 3402, with additional exposure to incident response planning and business continuity concepts. * Ability to conduct risk assessments, compliance reviews, and readiness evaluations across frameworks, including SOC 2, ISO 27001, PCI DSS, HITRUST, and HIPAA * Strong analytical skills with the ability to identify and assess complex risk scenarios and offer practical solutions * Familiarity with leading GRC tools and technologies to support compliance and risk management initiatives * Excellent communication and presentation skills, capable of articulating technical concepts to technical and non-technical audiences * Strong project management skills, including managing multiple engagements and deliverables simultaneously while maintaining high quality and client satisfaction standards * Prior experience at a Big 4 firm, a mid-tier CPA/advisory firm, or a boutique IT audit/attestation firm is strongly preferred, * Already certified in, or currently pursuing, one or more of the following: CISA, CIA, CPA, CISSP, and/or ISO 27001 Lead Auditor * Experience with the incident response lifecycle * Experience developing project plans and timelines * Track record of high-volume SOC 2 or ISO 27001 engagement delivery in a client-facing consulting or attestation role * Exposure to FedRAMP, CMMC, or other government compliance frameworks ## Description About us: At Echelon Risk + Cyber, we believe in defending the basic human right to security and privacy. We are looking for an exceptional Risk Advisory GRC Consultant to support the execution of Risk Advisory client engagements. This includes leading and executing relevant tasks, as well as assisting in developing service deliverables and internal processes that will drive value for the team and clients. Our next team member will be authentic, articulate, and passionate about Cybersecurity, and will be unafraid to roll up their sleeves and dive deep into the unknowns, using their security expertise to identify opportunities to increase Echelon Risk + Cyber's overall capabilities internally and for our clients. At Echelon, you will have the opportunity to engage with systems at the cutting edge of technology. We allow our employees to build from the ground up and make an impact across the organization. We look for driven, proactive people eager to contribute to a distinct and thriving Cybersecurity services organization that can adapt to a rapidly changing environment. This is a remote position from anywhere in the USA. What You Will Do: * Perform SOC 2 Type I/II readiness assessments and support attestation engagements, including scoping, control evaluation, gap identification, and remediation guidance * Conduct ISO 27001 gap assessments, internal audits, and certification support engagements for clients across a range of industries and sizes * Test and evaluate IT General Controls (ITGCs) across client environments, documenting findings and providing actionable remediation recommendations * Support PCI DSS, HITRUST, HIPAA, and CMMC Level 2 compliance assessments as client workload requires * Prepare and review audit workpapers, evidence requests, control narratives, and client-facing deliverables to a consistent standard of quality * Work directly with clients to identify and assess information security risks, develop security policies and procedures, and provide practical remediation guidance * Contribute to incident response planning, tabletop exercises, and business continuity engagements as part of Echelon's broader advisory portfolio * Manage multiple concurrent client engagements, balancing priorities and delivering quality results on schedule * Build strong internal and client relationships through clear written and verbal communication, translating technical findings for both technical and non-technical audiences * Stay current with evolving compliance frameworks, audit standards, and security threats to strengthen client services and internal methodologies * Demonstrate thought leadership by creating content for the organization's website and blog, and through involvement in the cybersecurity community ## Related Videos - [Why Your Next Best Talent Might Not Be in Your Neighborhood](https://www.wearedevelopers.com/videos/1861-why-your-next-best-talent-might-not-be-in-your-neighborhood) - [Create DSL (Domain Specific Language) on top of Swift](https://www.wearedevelopers.com/videos/707-create-dsl-domain-specific-language-on-top-of-swift) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Answering the Million Dollar Question: Why did I Break Production?](https://www.wearedevelopers.com/videos/1171-answering-the-million-dollar-question-why-did-i-break-production) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Job Boards for Remote Work for Developers](https://www.wearedevelopers.com/magazine/290-best-job-boards-for-remote-work-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers)