> Markdown version of [/jobs/ext/499226-senior-risk-advisory-grc-consultant-full-time-remote-in-the-usa](https://www.wearedevelopers.com/jobs/ext/499226-senior-risk-advisory-grc-consultant-full-time-remote-in-the-usa). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Risk Advisory GRC Consultant - Full Time- Remote in the USA - **Company:** ECHELON RISK, LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Technology Audit, PCI Data Security Standards, IT General Controls (ITGC), RSA Archer Platform - **Published:** June 7, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=80be4c333dbf79ef ## About the Role Do you have a valid CPA license?, Do you have a valid Certified Internal Auditor certification?, Do you have experience in Stakeholder relationship building?, * 5-7 years of hands-on experience in IT audit, compliance, cybersecurity consulting, or GRC advisory services, with significant experience leading SOC 2 Type I/II audits, ISO 27001 assessments, and related attestation engagements * Deep understanding of IT General Controls (ITGCs), Trust Services Criteria, and audit standards such as SSAE 18 and ISAE 3402, with practical experience leading incident response planning and business continuity initiatives * Proven ability to lead risk assessments, compliance reviews, readiness evaluations, and remediation programs across frameworks, including SOC 2, ISO 27001, PCI DSS, HITRUST, HIPAA, and CMMC * Strong analytical and problem-solving skills, with the ability to assess complex risk scenarios and provide strategic, business-aligned recommendations * Experience leveraging leading GRC platforms and technologies to drive compliance, risk management, and governance initiatives * Excellent communication, presentation, and stakeholder management skills, with the ability to engage technical teams, executive leadership, and client stakeholders * Strong project and engagement management skills, including leading multiple client engagements simultaneously while maintaining quality, budget, and client satisfaction objectives * Demonstrated experience mentoring junior team members and contributing to the development of internal methodologies, templates, and best practices * Prior experience at a Big 4 firm, mid-tier CPA/advisory firm, cybersecurity consulting firm, or boutique IT audit/attestation practice is strongly preferred * Applicants must have authorization to work in the United States without current or future visa sponsorship, * Certified in one or more of the following: CISA, CIA, CPA, CISSP, and/or ISO 27001 Lead Auditor * Extensive experience leading the incident response lifecycle, including preparedness, response, recovery, and lessons learned activities * Experience developing project plans, engagement roadmaps, staffing models, and delivery timelines * Proven track record leading high-volume SOC 2 and ISO 27001 engagements in a client-facing consulting, advisory, or attestation environment * Experience with government and regulated-industry compliance frameworks, including FedRAMP, CMMC, NIST 800-53, and related security standards * Experience managing client relationships, expanding advisory opportunities, and contributing to business development initiatives ## Description As a Senior Risk Advisory GRC Consultant, you will lead client engagements focused on information security, compliance, and risk management across frameworks such as SOC 2, ISO 27001, PCI DSS, HITRUST, HIPAA, and CMMC. In this role, you will serve as a trusted advisor to clients, helping them assess security risks, strengthen control environments, achieve compliance objectives, and improve overall cybersecurity maturity. You will manage multiple engagements, provide strategic guidance, mentor junior team members, and deliver high-quality consulting services while building strong client relationships and contributing to the growth of the practice. At Echelon, you will have the opportunity to engage with clients, business partners, and systems that are at the cutting edge of technology. We allow our employees to build from the ground up and make an impact across the organization. We look for driven and proactive people who are eager to contribute to a distinct and thriving Cybersecurity services organization that can adapt to a rapid and changing environment. This is a remote position from anywhere in the USA. What You Will Do: * Lead and execute SOC 2 Type I/II readiness assessments and attestation engagements, including scoping, control evaluation, gap identification, remediation planning, and client advisory services * Lead and develop ISO 27001 gap assessments, internal audits, and certification readiness engagements for clients across a range of industries and organizational sizes * Lead the testing and evaluation of IT General Controls (ITGCs) across client environments, documenting findings and delivering actionable remediation recommendations * Lead and develop PCI DSS, HITRUST, HIPAA, and CMMC Level 2 compliance assessments, providing strategic guidance and oversight throughout the engagement lifecycle * Review and oversee audit workpapers, evidence requests, control narratives, and client-facing deliverables to ensure consistency, quality, and adherence to professional standards * Partner directly with clients to identify and assess information security risks, develop security policies and procedures, and provide practical remediation strategies aligned with business objectives * Lead and develop incident response planning initiatives, tabletop exercises, and business continuity engagements as part of Echelon's broader cybersecurity advisory portfolio * Manage and oversee multiple concurrent client engagements, balancing priorities, mitigating risks, and delivering high-quality results on schedule * Build and strengthen internal and client relationships through exceptional written and verbal communication, effectively translating technical findings for both technical and executive-level stakeholders * Drive continuous improvement by staying current with evolving compliance frameworks, audit standards, and emerging security threats, enhancing both client services and internal methodologies * Demonstrate thought leadership through the creation of cybersecurity content, participation in industry events, mentorship of junior consultants, and active involvement in the cybersecurity community * Mentor and guide junior consultants and associates, providing technical oversight, quality reviews, and professional development support ## Related Videos - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Create DSL (Domain Specific Language) on top of Swift](https://www.wearedevelopers.com/videos/707-create-dsl-domain-specific-language-on-top-of-swift) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Why Your Next Best Talent Might Not Be in Your Neighborhood](https://www.wearedevelopers.com/videos/1861-why-your-next-best-talent-might-not-be-in-your-neighborhood) - [Answering the Million Dollar Question: Why did I Break Production?](https://www.wearedevelopers.com/videos/1171-answering-the-million-dollar-question-why-did-i-break-production) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Job Boards for Remote Work for Developers](https://www.wearedevelopers.com/magazine/290-best-job-boards-for-remote-work-for-developers) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers) - [The Best Job Search Websites of 2025](https://www.wearedevelopers.com/magazine/368-the-best-job-search-websites-of-2025)