795,742open jobs
50,860companies
125,050added this week
Browse all
Salary
$13k – $19k per year
Location
In office (Mumbai)
Seniority
Senior · 5+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 26, 2026. First seen by Alion on Sep 15, 2026.

Overview
Company
Impact
Profile match
SISA delivers cutting-edge AI-powered cybersecurity solutions for enterprises — from threat detection to compliance, safeguard what matters most.

Cybersecurity GRC Consultant - CMMC, FedRAMP & Security Compliance

Role Overview

We are looking for a hands-on Cybersecurity GRC Consultant with strong experience in CMMC, FedRAMP, NIST, SOC 2, ISO 27001 and/or HITRUST to lead and deliver cybersecurity compliance and advisory engagements.

The role requires practical experience in control assessment, framework mapping, evidence validation, gap assessment, risk analysis, remediation advisory and audit/report delivery. The ideal candidate should be comfortable working directly with clients, understanding their technology and business environment, translating requirements into actionable controls, and managing engagements from scoping through final deliverables.

This is a delivery-focused consulting role requiring both technical understanding and strong client-facing capabilities.

Key Responsibilities

  • Lead end-to-end cybersecurity GRC and compliance engagements, including scoping, planning, assessment, evidence review, gap analysis, remediation support and final reporting.
  • Perform assessments against CMMC 2.0, FedRAMP, NIST SP 800-171, NIST SP 800-53, ISO 27001, SOC 2 and HITRUST CSF, based on client requirements.
  • Develop and maintain control mappings and crosswalks across CMMC, FedRAMP, NIST, ISO 27001, SOC 2 and HITRUST.
  • Conduct detailed control design and operating effectiveness assessments, including review of policies, procedures, configurations, records and other audit evidence.
  • Evaluate control gaps, determine risk and impact, and develop practical remediation recommendations.
  • Support clients in defining and documenting security controls, policies, procedures, control narratives and evidence requirements.
  • Develop and/or review System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), risk assessments, Statements of Applicability, control matrices and audit workpapers.
  • Support SOC 2 readiness and Type I/Type II assessment activities, including Trust Services Criteria mapping, control testing and evidence evaluation.
  • Support ISO 27001 implementation/readiness/certification and surveillance activities, including ISMS controls, risk treatment and Statement of Applicability.
  • Support HITRUST CSF readiness and validated assessment activities, including control mapping, evidence assessment and remediation tracking.
  • Perform NIST-based cybersecurity assessments using NIST CSF and NIST SP 800-series standards where applicable.
  • Validate control mappings and assessment methodologies against applicable regulatory, industry and framework requirements.
  • Lead client discussions with IT, security, engineering, compliance, risk and audit stakeholders to understand the environment and validate controls.
  • Prepare assessment reports, findings, risk ratings, executive summaries and remediation roadmaps for technical and executive audiences.
  • Coordinate with external assessors, auditors, C3PAOs/3PAOs and other assurance stakeholders where applicable.
  • Maintain assessment quality through structured workpapers, evidence traceability, review procedures and quality assurance.
  • Contribute to development and continuous improvement of GRC methodologies, assessment templates, control libraries and reusable delivery assets.
  • Support presales activities, including scope definition, effort estimation, solutioning and technical proposal inputs.

Required Qualifications

  • 5+ years of hands-on experience in cybersecurity GRC, IT audit, security compliance or risk consulting.
  • Demonstrated experience delivering one or more of the following:
    • CMMC 2.0
    • FedRAMP
    • NIST CSF / NIST SP 800-171 / NIST SP 800-53
    • ISO 27001
    • SOC 2
    • HITRUST CSF
  • Strong understanding of security control frameworks, control objectives, control design, operating effectiveness and evidence-based assessment methodologies.
  • Hands-on experience with control mapping/crosswalks across multiple cybersecurity and compliance frameworks.
  • Experience conducting gap assessments, risk assessments, control testing and evidence validation.
  • Experience preparing or reviewing SSPs, POA&Ms, risk registers, control matrices, audit workpapers and assessment reports.
  • Practical understanding of cloud security, IAM, network security, vulnerability management, logging/monitoring, incident response, data protection, business continuity and third-party risk.
  • Ability to translate technical and regulatory requirements into practical security controls and implementation recommendations.
  • Strong written and verbal communication skills with the ability to communicate effectively with both technical teams and senior management.
  • Ability to work independently in a consulting environment and manage multiple client engagements.

Preferred Qualifications

Certifications in one or more of the following are preferred:

  • CMMC-AB Certified CMMC Professional (CCP) / Certified CMMC Assessor (CCA)
  • FedRAMP / 3PAO assessment experience
  • CISSP
  • CISA
  • CISM
  • CRISC
  • ISO 27001 Lead Auditor / Lead Implementer
  • HITRUST Certified CSF Practitioner / related HITRUST credential
  • SOC 2 / AICPA-related audit or assurance experience
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
795,742 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Mumbai
≈ $25k – $59k per year (Estimated) • In office • Full-Time • 4+ years exp • Bachelor's Degree • Bengaluru
DevOps
Splunk
Incident Management
SLI/SLO/SLA
Cybersecurity
SIEM
Analytics
Azure Data Factory
Management
Agile
Apply
≈ $32k – $73k per year (Estimated) • In office • Full-Time • Bengaluru
DevOps
IAM
Cybersecurity
Microsoft Entra ID
Apply
≈ $28k – $63k per year (Estimated) • In office • Full-Time • 5+ years exp • Hyderabad
AI/ML
Red Teaming
DevOps
Splunk
Azure
AWS
Cybersecurity
IBM QRadar
SIEM
Apply
≈ $28k – $62k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Hyderabad
Python
PowerShell
Bash
DevOps
GCP
Azure
AWS
IAM
Linux
Windows
Cybersecurity
MITRE ATT&CK
Zero Trust
SIEM
DLP
Apply
≈ $27k – $61k per year (Estimated) • In office • Full-Time • 6+ years exp • Bachelor's Degree • Hyderabad
Assembly
DevOps
GCP
Azure
AWS
Cybersecurity
ISO 27001
NIST CSF
PCI DSS
GDPR
Apply
≈ $144k – $274k per year (Estimated) • Remote (United States) • Full-Time • Bachelor's Degree
Cybersecurity
Okta
CyberArk
ISO 27001
SOC 2
GDPR
FedRAMP
Ping Identity
Management
ServiceNow
ITSM
Apply
≈ $40k – $105k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Nea Ionia
AI/ML
DPO
DevOps
VMWare
Azure
CI/CD
Cybersecurity
ISO 27001
GDPR
OWASP
Apply
AI Ops Engineer 9 hours ago
≈ $29k – $74k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Chennai
Python
Databases
Google BigQuery
BigQuery
AI/ML
LLM
Hallucination
LLMOps
Machine Learning
DevOps
Terraform
GCP
CI/CD
GitOps
Docker
Kubernetes
Platform Engineering
Self-Healing
Google GKE
Google Cloud Run
AIOps
IAM
Apply
In office
SQL
DevOps
Rest API
Cybersecurity
SOC 2
Management
Slack
Confluence
Jira
ITSM
QA
Swagger
Apply
$140k – $225k per year • Equity 0.1–0.3% • In office • Full-Time • San Francisco
Python
JavaScript
TypeScript
AI/ML
Spark
LLM
OpenRouter
LLM Guardrails
Frontend
Next.js
React.js
DevOps
Vercel
AWS
Kubernetes
Amazon EC2
Amazon CloudWatch
Cybersecurity
SOC 2
Management
Stripe
Apply
$26k – $37k per year • In office • Full-Time • 10+ years exp • Bengaluru
DevOps
IAM
Cybersecurity
ISO 27001
PCI DSS
SOC 2
SIEM
DLP
Apply
SOC Manager 3 months ago
≈ $38k – $90k per year (Estimated) • In office • Full-Time • 10+ years exp • Bengaluru
Python
PowerShell
DevOps
Splunk
GCP
Azure
AWS
Kubernetes
SLI/SLO/SLA
Cybersecurity
ISO 27001
MITRE ATT&CK
PCI DSS
SOC 2
HIPAA
Defense in Depth
IBM QRadar
AlienVault OTX
SIEM
Apply
Digital Forensic Lead 4 months ago
$42k – $47k per year • In office • Full-Time • Bachelor's Degree • Bengaluru
Python
Bash
DevOps
Linux
Windows
Cybersecurity
Autopsy
FTK
EnCase
X-Ways Forensics
Apply
$21k – $26k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • Bengaluru
Python
PowerShell
Cybersecurity
MITRE ATT&CK
IBM QRadar
SIEM
Apply
SOC L2- Qradar 5 months ago
$10k – $19k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • Bengaluru
Python
PowerShell
Cybersecurity
MITRE ATT&CK
STIX
TAXII
IBM QRadar
SIEM
Apply
≈ $21k – $48k per year (Estimated) • In office • Full-Time • 5+ years exp • Mumbai
SQL
Analytics
SAP BusinessObjects
Microsoft Excel
Apply
≈ $22k – $55k per year (Estimated) • Hybrid • Full-Time • 4+ years exp • Bachelor's Degree • Mumbai
Java
DevOps
Docker
Kubernetes
Apply
DevOps Engineer 1 day ago
≈ $25k – $55k per year (Estimated) • Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Mumbai
Python
DevOps
Configuration Management
Incident Management
Apply
≈ $17k – $37k per year (Estimated) • In office • Full-Time • 8+ years exp • Master's Degree • Mumbai
DevOps
SLI/SLO/SLA
Management
Microsoft Office
Apply
≈ $16k – $43k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Bengaluru • Coimbatore • Mumbai
Visual Basic
Analytics
Microsoft Excel
Management
Microsoft Office
Apply
See all jobs
This is one of many
795,742 more open roles from verified company boards, updated every day.