995,522open jobs
59,374companies
165,411added this week
Browse all
Salary
≈ $22k – $52k per year (Estimated)
Location
Hybrid (Gurgaon, India)
Seniority
Senior · 5+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 1, 2026. First seen by Alion on Sep 28, 2026. AHEAD scores B on the Alion truth index.

Overview
Company
Impact
Profile match
AHEAD helps enterprises build modern, secure, and scalable digital platforms by combining cloud, data, AI, and automation. Their consulting and managed services drive real business impact through smarter IT.

This is a senior consulting role, not an internal control-operations seat. You will be sold to clients as a credible authority on security GRC. You diagnose program maturity, design target-state operating models, quantify risk in business terms, and leave behind frameworks, artifacts, and decisions the client can run without you.

You must be highly proficient in English. Client deliverables, findings, board packs, statements of work, and live workshops are held to an executive and audit standard. Fluency is not enough. The bar is precise, concise, defensible professional English under time pressure.

You must be expert in NIST CSF, NIST SP 800-53, NIST SP 800-171, CIS Controls, the Cyber Risk Institute (CRI) Profile, and ISO/IEC 27001, and you must be able to manage and quantify risk -not only score it.

You must also be a consultant: structure ambiguous problems, manage senior stakeholders, run workshops, write commercial-quality deliverables, defend recommendations, and transfer capability to the client team.

Why this role is Senior

You are expected to operate with limited supervision on complex, multi-framework engagements. Typical work includes regulatory or contractual readiness (including CUI / 800-171), CSF or CRI profile builds, ISO 27001 ISMS design or certification support, control rationalization across overlapping frameworks, and quantified risk analysis for boards, CISOs, and risk committees.

You will often be the most senior GRC voice in the room. That means you set the method, hold the quality bar, and say clearly when a control, a score, or a “green” status is not the same thing as acceptable residual risk.

Core Mandate

Own the analytical and advisory quality of assigned GRC workstreams from scoping through readout and knowledge transfer.

Translate overlapping control frameworks into one coherent control and evidence model the client can operate.

Produce risk positions that combine sound qualitative judgment with quantification the business can use.

Run the engagement like a consultant: scope, stakeholders, workshops, issues, deliverables, and next-step decisions.

Responsibilities

    Client consulting and engagement leadership

  • Shape problem statements, engagement scope, assumptions, and success criteria with the client sponsor and the account team.
  • Build workplans, RAID logs, and stakeholder maps; keep delivery on quality even when the client’s evidence or ownership is incomplete.
  • Facilitate workshops with CISOs, control owners, internal audit, legal, procurement, and business executives. Drive decisions, not status meetings.
  • Manage resistance, conflicting frameworks, and “we already have a policy” arguments without losing the room or the facts.
  • Write and present deliverables that survive legal, audit, and executive review: current-state assessments, target operating models, control crosswalks, risk registers, quantified scenarios, roadmaps, and board narratives.
  • Coach client staff so the program does not collapse when the engagement ends. Consulting value is transfer, not slide volume.
  • Support pre-sales and scoping when asked: approach, level of effort, risks to delivery, and what “good” looks like for this client.
  • Framework design, assessment, and rationalization

  • Assess and design against NIST CSF (1.1 and/or 2.0): profiles, subcategory outcomes, tiers, and CSF as the executive reporting spine.
  • Assess and tailor NIST SP 800-53 (Rev. 5 preferred): control families, baselines, overlays, common/hybrid/system-specific controls, and assessment procedures.
  • Assess NIST SP 800-171 implementation for CUI: requirement status, 800-171A-style objectives, scoping of CUI flows, POA&Ms, and contractor obligation implications.
  • Apply CIS Controls (v8 preferred) as a prioritized operational control set (IG1-IG3), mapped to CSF and 800-53 rather than run as a second bureaucracy.
  • Interpret and assess the CRI Profile, including diagnostic statements and financial-sector or critical-third-party expectations.
  • Design or uplift an ISO/IEC 27001 ISMS: scope, SoA, risk assessment and treatment, internal audit liaison, management review inputs, and certification or surveillance readiness.
  • Build and maintain crosswalks so one control, one owner, and one evidence package can satisfy multiple frameworks
  • Assurance, evidence, and defensible writing

  • Design test procedures, challenge evidence quality, and write deficiency and residual-risk narratives that are factual and unambiguous.
  • Prepare clients for internal audit, ISO certification bodies, customer assessments, and 800-171 / CRI / CSF inquiries.
  • Produce executive summaries that a non-specialist leader can act on without a decoder.

Required qualifications

    Highly proficient written and spoken English at an executive, audit, and client-delivery standard. Grammar, structure, and tone must be consistently professional. You can explain a control failure, a residual-risk position, or a quantified scenario to an engineer, an auditor, and a board member in the register each expects. A writing sample or timed drafting exercise may be required.

    Demonstrated senior consulting or equivalent client-advisory experience: scoping ambiguous problems, facilitating senior workshops, managing difficult stakeholders, producing commercial-quality deliverables, defending recommendations under challenge, and transferring methods to the client. Internal GRC operations experience alone is not sufficient unless you can show the same client-facing muscle.

    Frameworks (all required, with working depth-not acronym familiarity)

  • NIST Cybersecurity Framework
  • NIST SP 800-53
  • NIST SP 800-171
  • CIS Controls
  • CRI Profile
  • ISO/IEC 27001 (working command of 27002 expected)
  • Risk (required)

    End-to-end risk management (identify, analyze, evaluate, treat, accept, monitor) and risk quantification (scenarios, ranges, expected loss or equivalent, explicit assumptions). “High / medium / low” without a method is not qualification.

    Experience and education

    Roughly 5+ years in security GRC, risk, audit, or control assurance, including substantial time in consulting, professional services, or a comparably senior client-advisory capacity. Bachelor’s degree in a relevant field or equivalent experience. Seniority is judged by judgment, writing, and client impact-not title inflation.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
995,522 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Solutions
Similar stack
Same company
Gurgaon
$19k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Ahmedabad
SQL
Databases
Oracle
DevOps
Git
Analytics
Microsoft Excel
Management
Agile
Apply
≈ $19k – $34k per year (Estimated) • In office • Mumbai
Apply
≈ $28k – $66k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Bengaluru
Apply
≈ $35k – $63k per year (Estimated) • In office • Full-Time • 8+ years exp • Bengaluru
Python
Java
Scala
Databases
Databricks
Delta Lake
AI/ML
Hadoop
Spark
DevOps
Terraform
CloudFormation
Azure
CI/CD
AWS
Kubernetes
Platform Engineering
Amazon EKS
Azure AKS
Amazon S3
IAM
Linux
Analytics
Azure Data Factory
Apply
≈ $27k – $48k per year (Estimated) • In office • Full-Time • 5+ years exp • Hyderabad
Analytics
ETL/ELT
Apply
≈ $106k – $241k per year (Estimated) • Remote (United States) • Contractor
Cybersecurity
NIST CSF
Apply
$51k – $80k per year • In office • Full-Time • Hanover
Cybersecurity
ISO 27001
Apply
Security Engineer 5 hours ago
$78k – $119k per year • Hybrid • 5+ years exp • Bachelor's Degree • Chicago
DevOps
Azure
IAM
Linux
Windows
Cybersecurity
ISO 27001
Cortex XDR
SOC 2
NIST 800-171
Zero Trust
DLP
Management
Outlook
OneDrive
SharePoint
Apply
≈ $20k – $43k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • Bengaluru
DevOps
CI/CD
AWS
IAM
Cybersecurity
ISO 27001
PCI DSS
Least Privilege
SIEM
Apply
≈ $96k – $217k per year (Estimated) • In office • Full-Time • Richmond
DevOps
CI/CD
AWS
Cybersecurity
ISO 27001
PCI DSS
SOC 2
Apply
≈ $22k – $53k per year (Estimated) • Remote (India) • Full-Time
Python
JavaScript
C#
AI/ML
Copilot
Cursor
Windsurf
Claude Code
AI Agents
Continue
DevOps
CI/CD
Management
Agile
Apply
≈ $22k – $58k per year (Estimated) • Remote (India) • Full-Time
Python
JavaScript
C#
AI/ML
Copilot
Cursor
Windsurf
Claude Code
Continue
DevOps
CI/CD
Management
Agile
Apply
≈ $22k – $53k per year (Estimated) • Remote (India) • Full-Time • 8+ years exp • Bachelor's Degree
Python
SQL
Databases
Snowflake
Databricks
Microsoft Fabric
DevOps
GCP
Azure
CI/CD
Git
AWS
Analytics
ETL/ELT
Management
Agile
Apply
≈ $26k – $55k per year (Estimated) • Remote (India) • Full-Time • 5+ years exp • Bachelor's Degree • Gurgaon
Python
AI/ML
LangGraph
Windsurf
LangChain
Claude
Fine-tuning
Scikit-learn
AI Agents
Transfer Learning
DeepEval
Langfuse
LangSmith
Ragas
TensorFlow
PyTorch
LLM
RAG
OpenAI
Anthropic
Amazon SageMaker
AWS Bedrock AgentCore
Devin
LLM Guardrails
Agentic Workflows
Machine Learning
DevOps
Azure
AWS
Apply
≈ $22k – $52k per year (Estimated) • Remote (India) • Full-Time • 4+ years exp • Bachelor's Degree
DevOps
TCP/IP
DNS
DHCP
BGP
OSPF
Apply
≈ $30k – $75k per year (Estimated) • Hybrid • 10+ years exp • Gurgaon
Apex
AI/ML
AI Agents
DevOps
Azure
GitHub
Management
Agile
QA
Selenium
Apply
≈ $20k – $46k per year (Estimated) • In office • 6+ years exp • Gurgaon
Python
JavaScript
Java
TypeScript
SQL
Node JS
AI/ML
AI Agents
LLM
RAG
Frontend
GraphQL
DevOps
Rest API
GCP
Azure
CI/CD
Git
AWS
Docker
Analytics
ETL/ELT
Apply
In office • Full-Time • 5+ years exp • Bengaluru • Pune • Chennai • Mumbai • Hyderabad
Python
SQL
AI/ML
LLM
RAG
DevOps
AWS
Amazon S3
Analytics
ETL/ELT
QA
Selenium
Pytest
Apply
In office • Full-Time • 6+ years exp • Gurgaon
Java
Java
Spring Boot
AI/ML
Anomaly Detection
DevOps
Splunk
Datadog
AWS
Apply
In office • Full-Time • 2+ years exp • Bachelor's Degree • Gurgaon
Java
Kotlin
Java
Spring Boot
Databases
DynamoDB
DevOps
gRPC
AWS
Apply
See all jobs
This is one of many
995,522 more open roles from verified company boards, updated every day.