This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Our client, a leading technology integrator, is in need of a Technical GRC Consultant for a 5-month contract opportunity. This individual will be working remotely in support of a GRC effort to move legacy ATO documentation into a modern, machine-readable format. They will be supporting a GRC SaaS implementation and should understand how to manage workspaces, program settings and KSI (Key Security Indicators) mapping. Experience with Python or API based automation is preferred as they will be creating scripts and validators to automate evidence collection from our clients environment. They will also be validating boundary diagrams, data flows and network architecture against actual cloud configurations. Demonstrated ability to develop and deliver training to staff on GRC processes, tools and implementation best practices will help them in driving this project.
Job Responsibility:
Working remotely in support of a GRC effort to move legacy ATO documentation into a modern, machine-readable format
Supporting a GRC SaaS implementation and should understand how to manage workspaces, program settings and KSI (Key Security Indicators) mapping
Creating scripts and validators to automate evidence collection from our clients environment
Validating boundary diagrams, data flows and network architecture against actual cloud configurations
Developing and delivering training to staff on GRC processes, tools and implementation best practices
Requirements:
SME level knowledge of Governance, Risk and Compliance frameworks
FedRAMP Moderate and IL4 knowledge of NIST 800-53 controls as well as a strong understanding of Rev 5
Experience working with GRC SaaS products. Paramify, RegScale or Vanta experience is a huge plus
Experience working with Python or API based automation in order to write “Fetcher” and “Validator” scripts to automate evidence collection
Ability to validate boundary diagrams, data flows, and network architecture against actual cloud configurations
Demonstrated ability to develop and deliver training to staff on GRC processes, tools, and implementation best practices
Nice to have:
Secret or higher clearance is highly preferred as a Tier 5 Public Trust may need to be obtained