Cybersecurity GRC Consultant - NIST CSF 2.0

Mergen IT LLC
San Francisco, CA, United States
25 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Excel Agile Methodology Cyber Security Microsoft Visio Microsoft PowerPoint PRINCE2 Power BI Microsoft SharePoint Information Security Management System CIS Benchmarks Servicenow

Job description

Lead the delivery of a NIST CSF 2.0 cybersecurity gap and maturity assessment for a global enterprise program, covering assessment planning, stakeholder engagement, evidence review, maturity scoring, risk-based gap prioritization, executive reporting, and development of a practical improvement roadmap., * Own end to end engagement governance, project planning, milestones, risks, dependencies, status reporting, and stakeholder communications.

  • Conduct NIST CSF 2.0 maturity assessment across functions, categories, subcategories, implementation tiers, and profiles.
  • Review policies, standards, procedures, controls, risk registers, asset inventories, KPIs/KRIs, and supporting evidence.
  • Facilitate interviews and workshops with cybersecurity, risk, compliance, technology, and business stakeholders.
  • Define defensible maturity scoring, identify control gaps, assess business risk, and prioritize remediation actions.
  • Develop executive ready assessment reports, maturity dashboards, prioritized recommendations, and near/mid/long term roadmap.

Requirements

10 to 15 years in cybersecurity, GRC, risk management, audit, security consulting, or cybersecurity program assessment.

NIST CSF Expertise

Strong hands on experience with NIST CSF, preferably NIST CSF 2.0 maturity assessments.

Framework Mapping

Experience mapping controls across NIST CSF, ISO 27001, NIST 800 53, CIS Controls, SOC 2, or similar frameworks.

Assessment Delivery

Proven experience conducting enterprise wide cybersecurity maturity, gap, risk, or control assessments.

Stakeholder Management

Ability to conduct interviews/workshops with senior security, risk, compliance, technology, and business stakeholders.

Executive Reporting

Strong experience creating leadership ready cybersecurity reports, maturity dashboards, and roadmap presentations.

Consulting Delivery

Experience working in consulting/advisory environments with structured methodology, governance, and client facing deliverables.

Risk Prioritization

Ability to convert control gaps into risk ranked remediation recommendations and practical roadmaps., * Strong expertise in NIST CSF 2.0, cybersecurity governance, risk management, compliance, control maturity models, and ISO 27001 / ISMS.

  • Ability to map controls across NIST CSF, ISO 27001, NIST 800 53, CIS Controls, SOC 2, and similar frameworks.
  • Experience in evidence-based assessment, maturity scoring, risk-based gap prioritization, and remediation roadmap development.
  • Excellent consulting delivery, workshop facilitation, stakeholder management, executive reporting, and written/verbal communication skills.

Preferred Certifications

CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor / Lead Implementer, NIST CSF training/certification, PMP / Prince2 / Agile certification preferred.

Tools / Platforms Knowledge Preferred

  • GRC and evidence management platforms such as Archer, ServiceNow GRC, OneTrust, MetricStream, SharePoint, Teams, Excel, PowerPoint, Visio, Power BI, and cybersecurity KPI/KRI dashboarding tools.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:46 min

Navigating a career in cloud transformation consulting

Piet Van Dongen · LIVE

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · World Congress 2025

1:24 min

Moving the semantic layer upstream to avoid vendor lock-in

Piotr Menclewicz Piotr Menclewicz · Europe 2026 Virtual

2:27 min

Establishing a simulated technical environment for the workflow demo

Tobias Dunn-Krahn · LIVE

3:48 min

Standardizing data access schemas with OData

Florian Bader Florian Bader · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all