Senior vCISO / GRC Consulting Manager Agency Cybersecurity is a fast growing venture backed startup that provides best-in-class cybersecurity and compliance. Our software and services simplify ...
Senior vCISO / GRC Consulting Manager Agency Cybersecurity is a fast growing venture backed startup that provides best-in-class cybersecurity and compliance. Our software and services simplify ...
Senior vCISO / GRC Consulting Manager
Richmond, VA · On-site
$125K/yr
This person will also manage a team of GRC consultants, analysts, and implementation specialists responsible for delivering client work. The ideal candidate has at least 6 years of professional ...
Senior vCISO / GRC Consulting Manager
Richmond, VA · On-site
$125K/yr
This person will also manage a team of GRC consultants, analysts, and implementation specialists responsible for delivering client work. The ideal candidate has at least 6 years of professional ...
This person will also manage a team of GRC consultants, analysts, and implementation specialists responsible for delivering client work. The ideal candidate has at least 6 years of professional ...
This person will also manage a team of GRC consultants, analysts, and implementation specialists responsible for delivering client work. The ideal candidate has at least 6 years of professional ...
About the Role Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC done right ranging from Fortune 1000 companies to high-growth startups.
About the Role Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC done right ranging from Fortune 1000 companies to high-growth startups.
GRC Consultant
Houston, TX · Remote
$38 - $40/hr
NationMind LLC is a technology consulting firm focused on software development and QA testing ... GRC Consultant Location: Remote, USA Duration: 6 Months Experience: 810 Years We are seeking an ...
Quick apply
GRC Consultant
Houston, TX · Remote
$38 - $40/hr
NationMind LLC is a technology consulting firm focused on software development and QA testing ... GRC Consultant Location: Remote, USA Duration: 6 Months Experience: 810 Years We are seeking an ...
Entry Level GRC Analyst
Fort Worth, TX · On-site +1
About the Role Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC done right ranging from Fortune 1000 companies to high-growth startups.
Entry Level GRC Analyst
Fort Worth, TX · On-site +1
About the Role Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC done right ranging from Fortune 1000 companies to high-growth startups.
SAP GRC Consultant
Byhalia, MS · On-site
$105/hr
SAP GRC Consultant REQ INTAKE 9/8/25: Preferred Rate/ Range: $80- $105/hr Is there any flexibility with the rate? yes Please confirm the max rate: $105/hr Please note: While the rate range is ...
SAP GRC Consultant
Byhalia, MS · On-site
$105/hr
SAP GRC Consultant REQ INTAKE 9/8/25: Preferred Rate/ Range: $80- $105/hr Is there any flexibility with the rate? yes Please confirm the max rate: $105/hr Please note: While the rate range is ...
SAP GRC/Security Consultant
Phoenix, AZ · On-site +1
SAP GRC/Security Consultant Company ... Turnkey Consulting Location: United States (Considering candidates in any US location ) About ...
SAP GRC/Security Consultant
Phoenix, AZ · On-site +1
SAP GRC/Security Consultant Company ... Turnkey Consulting Location: United States (Considering candidates in any US location ) About ...
SAP GRC/Security Consultant
Phoenix, AZ · On-site
SAP GRC/Security Consultant Company ... Turnkey Consulting Location: United States (Considering candidates in any US location ) About ...
SAP GRC/Security Consultant
Phoenix, AZ · On-site
SAP GRC/Security Consultant Company ... Turnkey Consulting Location: United States (Considering candidates in any US location ) About ...
About the Role Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC done right ranging from Fortune 1000 companies to high-growth startups.
About the Role Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC done right ranging from Fortune 1000 companies to high-growth startups.
GRC Consultant
Minneapolis, MN · On-site
IT Consultant - GRC Overview: Seeking a process-focused GRC Consultant to align business objectives with security investments, strengthen risk management practices, and enhance governance frameworks.
GRC Consultant
Minneapolis, MN · On-site
IT Consultant - GRC Overview: Seeking a process-focused GRC Consultant to align business objectives with security investments, strengthen risk management practices, and enhance governance frameworks.
About the Role Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC done right ranging from Fortune 1000 companies to high-growth startups.
Quick apply
About the Role Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC done right ranging from Fortune 1000 companies to high-growth startups.
SAP GRC/Security Senior Consultant Company ... Turnkey Consulting Location: United States (Considering candidates in any US location that are ...
SAP GRC/Security Senior Consultant Company ... Turnkey Consulting Location: United States (Considering candidates in any US location that are ...
SAP GRC/Security Senior Consultant
Alpharetta, GA · On-site +1
SAP GRC/Security Senior Consultant Company ... Turnkey Consulting Location: United States (Considering candidates in any US location that are ...
SAP GRC/Security Senior Consultant
Alpharetta, GA · On-site +1
SAP GRC/Security Senior Consultant Company ... Turnkey Consulting Location: United States (Considering candidates in any US location that are ...
SAP GRC Consultant
Queens, NY · On-site
SAP GRC Consultant Job Location : Queens borough, NY(Onsite) Job Type: Contract The consultant ... Overall 2-3 years plus industry and/or consulting; 2. Be responsible for all services and ...
SAP GRC Consultant
Queens, NY · On-site
SAP GRC Consultant Job Location : Queens borough, NY(Onsite) Job Type: Contract The consultant ... Overall 2-3 years plus industry and/or consulting; 2. Be responsible for all services and ...
Consulting background * Strong written and verbal communication skills * Integration experience ... Implementation of GRC Access Controls and supporting modules * Work with clients to understand ...
Consulting background * Strong written and verbal communication skills * Integration experience ... Implementation of GRC Access Controls and supporting modules * Work with clients to understand ...
SAP GRC/Security Consultant (US)
Atlanta, GA · On-site +1
Consulting background * Strong written and verbal communication skills * Integration experience ... Implementation of GRC Access Controls and supporting modules * Work with clients to understand ...
SAP GRC/Security Consultant (US)
Atlanta, GA · On-site +1
Consulting background * Strong written and verbal communication skills * Integration experience ... Implementation of GRC Access Controls and supporting modules * Work with clients to understand ...
... GRC consulting, with a focus on SOC 2 Type I/II audits, ISO 27001 assessments, or related ... attestation engagements * Demonstrated understanding of IT General Controls (ITGCs), Trust Services ...
... GRC consulting, with a focus on SOC 2 Type I/II audits, ISO 27001 assessments, or related ... attestation engagements * Demonstrated understanding of IT General Controls (ITGCs), Trust Services ...
SAP GRC Consultant Location:- Rosemead, CA Duration:- Full Time
Rosemead, CA · On-site
$64.25 - $87.50/hr
SAP GRC Consultant Location:- Rosemead, CA Duration:- Full Time Must Have Technical/Functional Skills * End to end management of SAP GRC modules(AC,PC) * SAP GRC 12.0 AC & PC implementation/upgrade ...
Quick apply
SAP GRC Consultant Location:- Rosemead, CA Duration:- Full Time
Rosemead, CA · On-site
$64.25 - $87.50/hr
SAP GRC Consultant Location:- Rosemead, CA Duration:- Full Time Must Have Technical/Functional Skills * End to end management of SAP GRC modules(AC,PC) * SAP GRC 12.0 AC & PC implementation/upgrade ...
This role is for a GRC Consultant with a focus on information security, risk, audit, and compliance. The consultant will be responsible for leveraging expertise in RSA Archer and various security ...
This role is for a GRC Consultant with a focus on information security, risk, audit, and compliance. The consultant will be responsible for leveraging expertise in RSA Archer and various security ...
Grc Consulting information
See salary details
$44.71 - $49.80
3% of jobs
$49.80 - $54.90
2% of jobs
$54.90 - $59.99
5% of jobs
$59.99 - $65.08
4% of jobs
$67.06 is the 25th percentile. Wages below this are outliers.
$65.08 - $70.17
26% of jobs
The median wage is $72.88 / hr.
$70.17 - $75.26
17% of jobs
$75.26 - $80.35
6% of jobs
$80.35 - $85.45
11% of jobs
$85.57 is the 75th percentile. Wages above this are outliers.
$85.45 - $90.54
11% of jobs
$90.54 - $95.63
13% of jobs
$95.63 - $100.72
2% of jobs
$44
$76
$100
How much do grc consulting jobs pay per hour?
What are the key skills and qualifications needed to thrive as a GRC Consultant, and why are they important?
What is the difference between Grc Consulting vs Risk Analyst?
| Aspect | Grc Consulting | Risk Analyst |
|---|---|---|
| Required Credentials | Certifications like CISA, CISM, or CRISC often preferred | Certifications such as FRM, CRM, or CIA common |
| Work Environment | Advisory roles, client sites, corporate offices | Financial institutions, corporations, or consulting firms |
| Employer & Industry Usage | Consulting firms, large corporations, government agencies | Financial services, insurance, banking, corporate sectors |
Grc Consulting and Risk Analysts both focus on managing and assessing risks, but Grc Consulting typically involves advising organizations on governance, risk, and compliance strategies across multiple areas, while Risk Analysts primarily analyze specific risks within financial or operational contexts. Grc Consultants often work across various industries and provide strategic guidance, whereas Risk Analysts tend to focus on data analysis and risk measurement within specific sectors.
What are some of the most common challenges faced by GRC consultants when working with clients to implement compliance frameworks?
What is GRC consulting?

Job description
Agency Cybersecurity is a fast growing venture backed startup that provides best-in-class cybersecurity and compliance. Our software and services simplify complex compliance frameworks including SOC2, ISO 27001, HIPAA, and others, empowering businesses to scale securely and confidently. We're backed by top tier investors like Y Combinator and have offices in NYC, Boston, Richmond, and London.
Location: Richmond, VA (100% In person)
Employment Type: Salaries, Full-Time
Compensation: $125,000 base salary
About the Role
We are seeking a Senior vCISO / GRC Consulting Manager to lead client-facing cybersecurity, governance, risk, and compliance engagements for organizations pursuing or maintaining security frameworks such as NIST 800-171, 800-53, or CMMC. As well as experience with SOC 2, ISO 27001, and related trust and security standards.
This is an in-person consulting leadership role based in Richmond, VA. The Senior vCISO will work directly with clients, internal delivery teams, and company leadership to provide hands-on advisory support, manage GRC engagements, and lead a team responsible for delivering high-quality cybersecurity and compliance services.
The Senior vCISO will serve as a strategic advisor to clients, helping them understand their security and compliance obligations, prioritize risk, prepare for audits, implement practical controls, and build scalable security programs. This person will also manage a team of GRC consultants, analysts, and implementation specialists responsible for delivering client work.
The ideal candidate has at least 6 years of professional experience in GRC, cybersecurity compliance, audit readiness, or related advisory work, including at least 4 years in a management or team leadership role. This person should be comfortable advising executives, managing client relationships, leading teams, working with auditors, and translating complex security and compliance requirements into clear business actions.
Key Responsibilities
Client Advisory and vCISO Leadership
- Serve as a trusted vCISO advisor to clients across cybersecurity, governance, risk, and compliance matters.
- Provide practical guidance to executive teams, founders, security leaders, IT teams, and business stakeholders.
- Help clients understand what they need to do to improve security, pass audits, reduce risk, and satisfy customer requirements.
- Advise clients on security program design, risk prioritization, compliance strategy, policy development, and control implementation.
- Lead client meetings, executive briefings, audit readiness sessions, and risk review discussions.
- Translate technical and compliance requirements into clear, business-friendly recommendations.
GRC and Compliance Program Delivery
- Lead client engagements related to SOC 2, ISO 27001, and other audited security frameworks.
- Develop and manage compliance roadmaps, audit readiness plans, and remediation timelines for clients.
- Guide clients through the full lifecycle of compliance readiness, including scoping, gap assessments, control implementation, evidence collection, audit support, and ongoing maintenance.
- Help clients determine the right level of security and compliance maturity for their size, industry, customer expectations, and business goals.
- Ensure compliance programs are practical, defensible, and not unnecessarily burdensome.
Audit Readiness and Framework Management
- Lead SOC 2 Type 1 and Type 2 readiness initiatives for clients.
- Support ISO 27001 implementation, certification preparation, surveillance audit readiness, and continuous improvement.
- Coordinate with external auditors, assessors, client stakeholders, and internal delivery teams.
- Review audit evidence, control documentation, risk registers, policies, and remediation plans.
- Help clients understand audit findings and develop clear plans to address gaps.
- Maintain strong working knowledge of SOC 2 Trust Services Criteria, ISO 27001 requirements, and common security control expectations.
Team Management and Delivery Oversight
- Manage a team of GRC consultants, analysts, and implementation resources.
- Assign work, oversee deliverables, manage deadlines, and ensure consistent quality across client engagements.
- Coach and mentor team members on GRC consulting, client communication, audit readiness, and control implementation.
- Review team deliverables, including gap assessments, policies, risk registers, audit evidence, project plans, and client-facing reports.
- Ensure the team delivers work that is accurate, practical, professional, and aligned with client expectations.
- Build repeatable delivery processes, templates, playbooks, and quality standards for the consulting team.
Security Control and Risk Advisory
- Advise clients on the design, implementation, and improvement of security and compliance controls.
- Help clients assess risks across cloud infrastructure, identity and access management, endpoint security, vulnerability management, vendor risk, change management, incident response, and secure development practices.
- Maintain and improve client risk registers and remediation plans.
- Work with client technical teams to prioritize security improvements based on business impact, audit requirements, and real-world risk.
- Provide practical recommendations that balance security, compliance, cost, and operational complexity.
Policy, Governance, and Documentation
- Lead the development and review of client security policies, procedures, standards, and governance documentation.
- Help clients implement policy review cycles, access review processes, vendor review workflows, risk acceptance procedures, and other governance activities.
- Ensure client documentation aligns with actual business practices and audit expectations.
- Help clients avoid "paper compliance" by tying policies and controls to real operational processes.
Customer Trust and Security Questionnaire Support
- Advise clients on customer security reviews, vendor assessments, and trust-related requests.
- Help clients respond to security questionnaires, customer due diligence requests, and enterprise procurement reviews.
- Support the development of reusable security and compliance response libraries.
- Help clients use compliance and security posture to support sales, customer trust, and enterprise readiness.
Client Relationship Management
- Own or support client relationships across multiple GRC and vCISO engagements.
- Set clear expectations with clients regarding scope, timelines, responsibilities, and deliverables.
- Identify client risks, blockers, and expansion opportunities.
- Communicate engagement status, risks, and next steps clearly to both internal leadership and client stakeholders.
- Ensure clients receive strategic advice, not just task completion.
Required Qualifications
- Minimum 6 years of professional experience in GRC, cybersecurity compliance, security advisory, audit readiness, IT risk, internal audit, or a related field.
- Minimum 4 years of management or team leadership experience.
- Direct experience advising organizations on audited frameworks such as SOC 2 and ISO 27001.
- Experience managing client-facing consulting engagements or advisory relationships.
- Strong understanding of security controls, risk management, compliance frameworks, and audit processes.
- Experience leading or supporting external audits, including evidence collection, control testing, auditor communications, and remediation.
- Ability to explain complex security and compliance concepts to executives, founders, technical teams, and non-technical stakeholders.
- Strong written and verbal communication skills.
- Strong project management skills with the ability to manage multiple clients, deadlines, stakeholders, and team members.
- Ability to work in person from Richmond, VA.
- Willingness to attend in-person meetings with internal teams, clients, and leadership as required.
Preferred Qualifications
- Prior experience in a consulting, advisory, MSSP, vCISO, CPA firm, audit firm, cybersecurity firm, or compliance services environment.
- Experience with GRC platforms such as Vanta, Drata, Secureframe, Hyperproof, AuditBoard, OneTrust, or similar tools.
- Experience with additional frameworks such as HIPAA, HITRUST, NIST CSF, NIST 800-53, NIST 800-171, CMMC, PCI DSS, GDPR, CIS Controls, or privacy/security requirements for SaaS companies.
- Experience advising startups, SaaS companies, technology companies, fintech companies, healthcare companies, or mid-market organizations.
- Familiarity with AWS, Azure, Google Cloud, identity
About Agency.com
Sourced by ZipRecruiter
Industry
Marketing
Company size
501 - 1,000 Employees
Headquarters location
New York, NY, US
Year founded
1995