> Markdown version of [/jobs/ext/3034657-grc-consultant](https://www.wearedevelopers.com/jobs/ext/3034657-grc-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Consultant - **Company:** Hey, Inc. - **Location:** San Francisco, CA, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cloud Computing Security, Cyber Security, Continuous Integration, Identity and Access Management, RSA Archer Platform, ISO/IEC 27002 - **Published:** September 23, 2026 - **Apply:** https://www.thejobnetwork.com/job/3cfd6bd9-67b8-4e04-8239-160128a4281b/senior-grc-consultant ## About the Role * 5-7+ years of hands-on experience in GRC, compliance, or information security audits. * Previous consulting or professional services experience managing multiple client engagements. * Strong expertise with both: + SOC 2 Type I & II + ISO 27001 / ISO 27002 * Experience with one or more additional frameworks such as GDPR, CCPA/CPRA, or HIPAA. * Experience building compliance programs from the ground up. * Ability to map controls across multiple compliance frameworks. * Solid technical understanding of cloud security, IAM, CI/CD pipelines, and security controls. * Excellent documentation and technical writing skills. * Professional-level English with confidence leading meetings with U.S.-based clients. Nice to Have * Experience working directly with external auditors. * Hands-on experience implementing GDPR or U.S. privacy compliance programs. * Knowledge of ISO 42001 (AI Management Systems). * Certifications such as: + CISA + CISM + CRISC + ISO 27001 Lead Auditor + ISO 27001 Lead Implementer + or equivalent. ## Description As a Senior GRC Consultant, you will lead audit readiness, compliance program development, and risk management across multiple client engagements. You'll own compliance frameworks end-to-end-from scoping and evidence collection to gap analysis, remediation guidance, and audit support. This is a senior, client-facing position where you'll independently manage your own engagements while working directly with executive stakeholders and external auditors., * Lead compliance readiness engagements including SOC 2 Type I/II, ISO 27001, HIPAA, U.S. state privacy regulations, and UK/EU GDPR. * Own GRC platforms such as Vanta, Drata, or similar tools, ensuring compliance monitoring remains fully operational and evidence is continuously maintained. * Conduct formal risk assessments using frameworks such as NIST 800-30, translating technical findings into business and compliance risks. * Design and implement complete GRC programs, including policies, control frameworks, risk management processes, and evidence collection. * Perform internal audits, evaluating both control design and operational effectiveness while preparing audit-ready findings. * Manage vendor security questionnaires, coordinating with internal subject matter experts and maintaining reusable knowledge bases. * Build strong relationships with client leadership, lead recurring meetings, provide status updates, and manage expectations throughout each engagement. * Produce high-quality client deliverables including policies, procedures, risk registers, control matrices, evidence packages, and assessment reports., * Join an early-stage, fast-growing cybersecurity startup. * Work directly with founders and client leadership. * Own high-impact client engagements from start to finish. * Help innovative technology companies mature their security and compliance programs. * Enjoy long-term remote work with significant autonomy, ownership, and career growth. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Your Enterprise RAG Has No Legal Basis](https://www.wearedevelopers.com/videos/100344-your-enterprise-rag-has-no-legal-basis) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) - [Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)