> Markdown version of [/jobs/ext/2621370-cybersecurity-grc-consultant-nist-csf-2-0](https://www.wearedevelopers.com/jobs/ext/2621370-cybersecurity-grc-consultant-nist-csf-2-0). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity GRC Consultant - NIST CSF 2.0 - **Company:** Mergen IT LLC - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Excel, Agile Methodology, Cyber Security, Microsoft Visio, Microsoft PowerPoint, PRINCE2, Power BI, Microsoft SharePoint, Information Security Management System, CIS Benchmarks, Servicenow - **Published:** August 12, 2026 - **Apply:** https://www.dice.com/job-detail/58f07538-0df7-458e-adb5-12f5871a3518 ## About the Role 10 to 15 years in cybersecurity, GRC, risk management, audit, security consulting, or cybersecurity program assessment. NIST CSF Expertise Strong hands on experience with NIST CSF, preferably NIST CSF 2.0 maturity assessments. Framework Mapping Experience mapping controls across NIST CSF, ISO 27001, NIST 800 53, CIS Controls, SOC 2, or similar frameworks. Assessment Delivery Proven experience conducting enterprise wide cybersecurity maturity, gap, risk, or control assessments. Stakeholder Management Ability to conduct interviews/workshops with senior security, risk, compliance, technology, and business stakeholders. Executive Reporting Strong experience creating leadership ready cybersecurity reports, maturity dashboards, and roadmap presentations. Consulting Delivery Experience working in consulting/advisory environments with structured methodology, governance, and client facing deliverables. Risk Prioritization Ability to convert control gaps into risk ranked remediation recommendations and practical roadmaps., * Strong expertise in NIST CSF 2.0, cybersecurity governance, risk management, compliance, control maturity models, and ISO 27001 / ISMS. * Ability to map controls across NIST CSF, ISO 27001, NIST 800 53, CIS Controls, SOC 2, and similar frameworks. * Experience in evidence-based assessment, maturity scoring, risk-based gap prioritization, and remediation roadmap development. * Excellent consulting delivery, workshop facilitation, stakeholder management, executive reporting, and written/verbal communication skills. Preferred Certifications CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor / Lead Implementer, NIST CSF training/certification, PMP / Prince2 / Agile certification preferred. Tools / Platforms Knowledge Preferred * GRC and evidence management platforms such as Archer, ServiceNow GRC, OneTrust, MetricStream, SharePoint, Teams, Excel, PowerPoint, Visio, Power BI, and cybersecurity KPI/KRI dashboarding tools. ## Description Lead the delivery of a NIST CSF 2.0 cybersecurity gap and maturity assessment for a global enterprise program, covering assessment planning, stakeholder engagement, evidence review, maturity scoring, risk-based gap prioritization, executive reporting, and development of a practical improvement roadmap., * Own end to end engagement governance, project planning, milestones, risks, dependencies, status reporting, and stakeholder communications. * Conduct NIST CSF 2.0 maturity assessment across functions, categories, subcategories, implementation tiers, and profiles. * Review policies, standards, procedures, controls, risk registers, asset inventories, KPIs/KRIs, and supporting evidence. * Facilitate interviews and workshops with cybersecurity, risk, compliance, technology, and business stakeholders. * Define defensible maturity scoring, identify control gaps, assess business risk, and prioritize remediation actions. * Develop executive ready assessment reports, maturity dashboards, prioritized recommendations, and near/mid/long term roadmap. ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Beyond Dashboards: Fixing Text-to-SQL with Semantic RAG](https://www.wearedevelopers.com/videos/2036-beyond-dashboards-fixing-text-to-sql-with-semantic-rag) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [REST, GraphQL, gRPC, and more: A comparison of modern API styles](https://www.wearedevelopers.com/videos/100247-rest-graphql-grpc-and-more-a-comparison-of-modern-api-styles) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)