Senior GRC Consultant

MAD Security
Huntsville, AL, United States
24 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Shift work
Job source

Tech stack

Microsoft Windows Active Directory Software Applications Collaborative Software Cyber Security Information Systems Azure Active Directory Microsoft InTune Information Technology

Job description

MAD Security is seeking an experienced Senior GRC Consultant to join our Governance, Risk, and Compliance (GRC) team. This role is ideal for a cybersecurity professional who enjoys solving complex compliance challenges, advising executive leadership, and helping organizations build practical, effective cybersecurity programs.

As a Senior GRC Consultant, you will lead cybersecurity compliance consulting engagements for organizations across the Defense Industrial Base and other regulated industries. You’ll serve as a trusted advisor to executives and technical teams, helping clients navigate CMMC, NIST SP 800-171, DFARS, and other cybersecurity compliance requirements while developing practical, risk-informed security programs that support their business objectives. In addition to managing your own client portfolio, you’ll mentor other GRC professionals, contribute to the continuous improvement of our consulting methodologies, and help maintain the high standards that define MAD Security.

Primary Responsibilities

  • Lead cybersecurity compliance consulting engagements for assigned clients from planning through delivery.
  • Serve as the primary advisor for executive and technical client stakeholders regarding cybersecurity risk, compliance, and implementation strategies.
  • Conduct compliance assessments, gap assessments, risk assessments, tabletop exercises, mock assessments, and related consulting engagements.
  • Review security architectures, technical implementations, policies, procedures, and evidence to determine compliance with applicable cybersecurity requirements.
  • Develop practical remediation plans and implementation guidance that help clients achieve and maintain compliance.
  • Prepare and review professional reports, executive presentations, and other client deliverables.
  • Mentor GRC Analysts and GRC Consultants while contributing to the continuous improvement of MAD Security’s consulting methodologies and delivery standards.

What Success Looks Like in the First 12 Months

  • Successfully manages an assigned portfolio of consulting clients while maintaining exceptional client satisfaction.
  • Leads complex compliance engagements with minimal oversight while consistently delivering high-quality work.
  • Establishes trusted advisor relationships with executive and technical stakeholders.
  • Produces professional reports and deliverables that require minimal revision.
  • Provides technical guidance and mentorship that improves the performance and consistency of the GRC team.
  • Contributes meaningful improvements to MAD Security’s consulting methodologies, documentation, or service offerings., * Primarily standard weekday business hours with flexibility to accommodate client schedules when necessary.
  • Work for extended periods at a computer using multiple software applications and virtual collaboration tools.
  • Participate in regular client-facing virtual meetings conducted on camera.
  • Work effectively in a collaborative consulting environment supporting multiple concurrent client engagements.

Requirements

  • Minimum of seven years of experience in an information technology-related position, with three or more years of cybersecurity experience preferred.
  • Previous experience leading cybersecurity compliance consulting or assessment engagements.
  • Experience managing multiple concurrent client engagements, projects, or priorities.
  • Experience leading executive-level client meetings and presenting technical or compliance information to senior leadership.
  • Education

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Business, or a related field preferred. Equivalent professional experience may be considered in lieu of a degree.

Technical Qualifications

  • Strong understanding of enterprise IT infrastructure, cybersecurity technologies, and security architecture.
  • Experience interpreting and applying cybersecurity compliance frameworks, particularly NIST SP 800-171, CMMC, and DFARS.
  • Ability to confidently lead highly technical discussions with executive and technical stakeholders.

Required Certifications

  • One or more of the following:
  • CCA
  • CISSP
  • CISM, * Experience supporting organizations through CMMC assessments or ongoing CMMC compliance programs.
  • Experience with NIST SP 800-171 and DFARS.
  • Experience supporting organizations within the Defense Industrial Base.
  • Experience working for a C3PAO, Registered Provider Organization (RPO), cybersecurity consulting firm, or MSSP.
  • Experience working with Microsoft 365 Commercial, GCC, or GCC High environments.
  • Experience with Microsoft Entra ID, Active Directory, and Microsoft Intune.
  • Experience conducting risk assessments, tabletop exercises, and mock assessments., * Excellent communication skills with the ability to engage executives, technical teams, and business stakeholders.
  • Strong analytical and problem-solving skills with sound professional judgment.
  • Ability to manage multiple client engagements while maintaining exceptional quality and responsiveness.
  • Demonstrated leadership through mentoring, collaboration, knowledge sharing, and technical guidance.
  • Organized, accountable, and capable of working independently in a fast-paced consulting environment.
  • Committed to continuous learning, professional development, and maintaining technical expertise.

About the company

At MAD Security, our mission is Safeguarding Businesses from Evil. We help organizations strengthen their cybersecurity posture through practical consulting, managed security services, and compliance expertise that deliver measurable business value.

Joining our team means working alongside experienced cybersecurity professionals who are passionate about high standards, continuous improvement, and delivering exceptional service. You’ll have the opportunity to solve challenging cybersecurity problems, work directly with executive leadership across a diverse client base, mentor other professionals, and play a meaningful role in helping organizations achieve and maintain cybersecurity compliance.

You must create an Indeed account before continuing to the company website to apply

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:45 min

Evolution from manual setups to automated monolith deployments

Axel Barbier · World Congress 2023

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

5:13 min

Audience Q&A on maturity assessments and external consultants

Mathias Tausig · LIVE

3:18 min

Eliminating passwords using Azure managed identities

Markus Möller · World Congress 2021

Videos

See all

Related articles

See all