... consulting firm. Our next team member will be ready to roll up their sleeves and identify ... As a Senior Risk Advisory GRC Consultant , you will lead client engagements focused on information ...
... consulting firm. Our next team member will be ready to roll up their sleeves and identify ... As a Senior Risk Advisory GRC Consultant , you will lead client engagements focused on information ...
SAP GRC Security
Dallas, TX · On-site
Company Description We are looking for a great SAP Security consultant who has hands on experience with GRC 10. Duration: 3m (possible extension) Location: Plano, TX Must have: GRC 10 Start Date: May ...
SAP GRC Security
Dallas, TX · On-site
Company Description We are looking for a great SAP Security consultant who has hands on experience with GRC 10. Duration: 3m (possible extension) Location: Plano, TX Must have: GRC 10 Start Date: May ...
Senior IT GRC Consultant
Jackson, MS · On-site
Role: Senior IT GRC Consultant Location: Jackson, MS 39213 - Hybrid Duration: 4 months with ... consulting or advisory services 10 + years working in an Oversight capacity Required Skills ...
Quick apply
Senior IT GRC Consultant
Jackson, MS · On-site
Role: Senior IT GRC Consultant Location: Jackson, MS 39213 - Hybrid Duration: 4 months with ... consulting or advisory services 10 + years working in an Oversight capacity Required Skills ...
Oracle GRC Consultant
$58 - $73/hr
GRC = Governance, Risk, & Compliance Advanced or Expertise with - Oracle eBusiness Suite --- GRC - Access Controls - Oracle eBusiness Suite --- GRC - Configuration Controls YES/NO - Has this person ...
Oracle GRC Consultant
$58 - $73/hr
GRC = Governance, Risk, & Compliance Advanced or Expertise with - Oracle eBusiness Suite --- GRC - Access Controls - Oracle eBusiness Suite --- GRC - Configuration Controls YES/NO - Has this person ...
SAP GRC Consultant
Rosemead, CA · On-site
We are looking for a seasoned SAP GRC professional who has led end-to-end GRC implementations , optimized SoD and risk frameworks , and worked closely with Security, Audit, Compliance, and Business ...
SAP GRC Consultant
Rosemead, CA · On-site
We are looking for a seasoned SAP GRC professional who has led end-to-end GRC implementations , optimized SoD and risk frameworks , and worked closely with Security, Audit, Compliance, and Business ...
SAP GRC Consultant
Portland, OR · On-site
Represent SAP Security and GRC considerations in department and company-wide projects to ensure security needs are satisfied * Assist with GRC configuration and use GRC tools in the creation and ...
SAP GRC Consultant
Portland, OR · On-site
Represent SAP Security and GRC considerations in department and company-wide projects to ensure security needs are satisfied * Assist with GRC configuration and use GRC tools in the creation and ...
Recruiter
Syosset, NY · Hybrid
$58K - $88K/yr
Gedeon GRC Consulting is looking for a Recruiter to join our firm. This candidate will possess the ability to assess candidates' skills, experience, and relevant knowledge and compare them to job ...
Recruiter
Syosset, NY · Hybrid
$58K - $88K/yr
Gedeon GRC Consulting is looking for a Recruiter to join our firm. This candidate will possess the ability to assess candidates' skills, experience, and relevant knowledge and compare them to job ...
Implement and support SAP GRC Access Control (ARA, ARM, BRM, EAM) * Perform SoD analysis , risk remediation, and access reviews * Manage user provisioning, role changes, and audit support * Work with ...
Quick apply
Implement and support SAP GRC Access Control (ARA, ARM, BRM, EAM) * Perform SoD analysis , risk remediation, and access reviews * Manage user provisioning, role changes, and audit support * Work with ...
GRC Consultant
Downey, CA · On-site
GRC Consultant Downey, CA - Remote 12+ months Description: A Security Engineer serves as the security engineer of complex technology implementations in a product-centric environment; is comfortable ...
GRC Consultant
Downey, CA · On-site
GRC Consultant Downey, CA - Remote 12+ months Description: A Security Engineer serves as the security engineer of complex technology implementations in a product-centric environment; is comfortable ...
Cloud Security GRC Consultant
$100K - $140K/yr
This high-impact consulting role requires a deep understanding of Google Cloud services and the ... GRC documentation. The ideal candidate will leverage experience driving systems through the ...
Quick apply
Cloud Security GRC Consultant
$100K - $140K/yr
This high-impact consulting role requires a deep understanding of Google Cloud services and the ... GRC documentation. The ideal candidate will leverage experience driving systems through the ...
GRC Consultant
Bloomington, IL · On-site
GRC Consultant Location: Bloomington, IL Job Type: Contract * Security Compliance * Required to have excellent understanding of the IT Control framework, in particular risk assessment and control ...
GRC Consultant
Bloomington, IL · On-site
GRC Consultant Location: Bloomington, IL Job Type: Contract * Security Compliance * Required to have excellent understanding of the IT Control framework, in particular risk assessment and control ...
SAP Security/GRC Consultant
Plano, TX · On-site
Technical Skills: • 8-10 years of Security Experience in following components ECC, BW/BI, CRM, PO, SRM, SUS, SCM, Portal, HCM, HCM BW, FIORI, CUA, GRC, SOLMAN, BW on HANA, BPC on Hana, S4 HANA • ...
SAP Security/GRC Consultant
Plano, TX · On-site
Technical Skills: • 8-10 years of Security Experience in following components ECC, BW/BI, CRM, PO, SRM, SUS, SCM, Portal, HCM, HCM BW, FIORI, CUA, GRC, SOLMAN, BW on HANA, BPC on Hana, S4 HANA • ...
SAP Security & GRC Consultant (8+ Years Experience) Experience 8+ years of hands-on experience in SAP Security and GRC (Governance, Risk & Compliance) Job Summary The SAP Security & GRC Consultant ...
SAP Security & GRC Consultant (8+ Years Experience) Experience 8+ years of hands-on experience in SAP Security and GRC (Governance, Risk & Compliance) Job Summary The SAP Security & GRC Consultant ...
Having experience in implementing USER ACCESS REVIEW AUTOMATION in SAP GRC. Must-Haves * Someone ... Consulting backgrounds * Candidates with real project experience Job Nice to Haves: * Experience ...
Having experience in implementing USER ACCESS REVIEW AUTOMATION in SAP GRC. Must-Haves * Someone ... Consulting backgrounds * Candidates with real project experience Job Nice to Haves: * Experience ...
ServiceNow GRC / IRM Consultant Location: Raleigh, NC / Charlotte, NC / Hartford, CT (Onsite) Duration: Fulltime Roles and responsibilities: Mandatory - ServiceNow IRM/GRC implementation & Operation ...
ServiceNow GRC / IRM Consultant Location: Raleigh, NC / Charlotte, NC / Hartford, CT (Onsite) Duration: Fulltime Roles and responsibilities: Mandatory - ServiceNow IRM/GRC implementation & Operation ...
About the Role Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC done right across the Defense Industrial Base navigating CMMC, NIST 800 ...
Quick apply
About the Role Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC done right across the Defense Industrial Base navigating CMMC, NIST 800 ...
SAP Security Consultant
Los Angeles, CA · On-site
$80/hr
SAP Security GRC Consultant Los Angeles, CA- Hybrid Rate- $80/HR- Please be flexible * Experienced SAP security consultant with 11+ years in SAP security and SAP GRC Access Control. * Have experience ...
SAP Security Consultant
Los Angeles, CA · On-site
$80/hr
SAP Security GRC Consultant Los Angeles, CA- Hybrid Rate- $80/HR- Please be flexible * Experienced SAP security consultant with 11+ years in SAP security and SAP GRC Access Control. * Have experience ...
GRC Consultant-CyberSecurity, Compliance Job Location: Erlanger, KY Job Type: Contract to Hire * Review Projects and their technical design documents for Information security risks and advise on ...
Quick apply
GRC Consultant-CyberSecurity, Compliance Job Location: Erlanger, KY Job Type: Contract to Hire * Review Projects and their technical design documents for Information security risks and advise on ...
... Process Consulting, problem definition, Architecture/Design /Detailing of Processes At least 3 years of experience in RSA Archer & SNOW Skills At least 2 years of experience in Development ...
... Process Consulting, problem definition, Architecture/Design /Detailing of Processes At least 3 years of experience in RSA Archer & SNOW Skills At least 2 years of experience in Development ...
Sap S/4hana Grc Security Consultant Job Summary: The Sap S/4hana Grc Security Consultant will be responsible for designing, implementing, and supporting SAP S/4HANA security and SAP GRC solutions in ...
Sap S/4hana Grc Security Consultant Job Summary: The Sap S/4hana Grc Security Consultant will be responsible for designing, implementing, and supporting SAP S/4HANA security and SAP GRC solutions in ...
Grc Consulting information
See salary details
$44.71 - $49.80
3% of jobs
$49.80 - $54.90
2% of jobs
$54.90 - $59.99
5% of jobs
$59.99 - $65.08
4% of jobs
$67.06 is the 25th percentile. Wages below this are outliers.
$65.08 - $70.17
26% of jobs
The median wage is $72.88 / hr.
$70.17 - $75.26
17% of jobs
$75.26 - $80.35
6% of jobs
$80.35 - $85.45
11% of jobs
$85.57 is the 75th percentile. Wages above this are outliers.
$85.45 - $90.54
11% of jobs
$90.54 - $95.63
13% of jobs
$95.63 - $100.72
2% of jobs
$44
$76
$100
How much do grc consulting jobs pay per hour?
What are the key skills and qualifications needed to thrive as a GRC Consultant, and why are they important?
What is the difference between Grc Consulting vs Risk Analyst?
| Aspect | Grc Consulting | Risk Analyst |
|---|---|---|
| Required Credentials | Certifications like CISA, CISM, or CRISC often preferred | Certifications such as FRM, CRM, or CIA common |
| Work Environment | Advisory roles, client sites, corporate offices | Financial institutions, corporations, or consulting firms |
| Employer & Industry Usage | Consulting firms, large corporations, government agencies | Financial services, insurance, banking, corporate sectors |
Grc Consulting and Risk Analysts both focus on managing and assessing risks, but Grc Consulting typically involves advising organizations on governance, risk, and compliance strategies across multiple areas, while Risk Analysts primarily analyze specific risks within financial or operational contexts. Grc Consultants often work across various industries and provide strategic guidance, whereas Risk Analysts tend to focus on data analysis and risk measurement within specific sectors.
What are some of the most common challenges faced by GRC consultants when working with clients to implement compliance frameworks?
What is GRC consulting?

Full-time
Medical, Dental, Vision, Life, Retirement
Posted 11 days ago
Job description
As a Senior Risk Advisory GRC Consultant, you will lead client engagements focused on information security, compliance, and risk management across frameworks such as SOC 2, ISO 27001, PCI DSS, HITRUST, HIPAA, and CMMC. In this role, you will serve as a trusted advisor to clients, helping them assess security risks, strengthen control environments, achieve compliance objectives, and improve overall cybersecurity maturity. You will manage multiple engagements, provide strategic guidance, mentor junior team members, and deliver high-quality consulting services while building strong client relationships and contributing to the growth of the practice.
At Echelon, you will have the opportunity to engage with clients, business partners, and systems that are at the cutting edge of technology. We allow our employees to build from the ground up and make an impact across the organization. We look for driven and proactive people who are eager to contribute to a distinct and thriving Cybersecurity services organization that can adapt to a rapid and changing environment.
This is a remote position from anywhere in the USA.
What You Will Do:
- Lead and execute SOC 2 Type I/II readiness assessments and attestation engagements, including scoping, control evaluation, gap identification, remediation planning, and client advisory services
- Lead and develop ISO 27001 gap assessments, internal audits, and certification readiness engagements for clients across a range of industries and organizational sizes
- Lead the testing and evaluation of IT General Controls (ITGCs) across client environments, documenting findings and delivering actionable remediation recommendations
- Lead and develop PCI DSS, HITRUST, HIPAA, and CMMC Level 2 compliance assessments, providing strategic guidance and oversight throughout the engagement lifecycle
- Review and oversee audit workpapers, evidence requests, control narratives, and client-facing deliverables to ensure consistency, quality, and adherence to professional standards
- Partner directly with clients to identify and assess information security risks, develop security policies and procedures, and provide practical remediation strategies aligned with business objectives
- Lead and develop incident response planning initiatives, tabletop exercises, and business continuity engagements as part of Echelon's broader cybersecurity advisory portfolio
- Manage and oversee multiple concurrent client engagements, balancing priorities, mitigating risks, and delivering high-quality results on schedule
- Build and strengthen internal and client relationships through exceptional written and verbal communication, effectively translating technical findings for both technical and executive-level stakeholders
- Drive continuous improvement by staying current with evolving compliance frameworks, audit standards, and emerging security threats, enhancing both client services and internal methodologies
- Demonstrate thought leadership through the creation of cybersecurity content, participation in industry events, mentorship of junior consultants, and active involvement in the cybersecurity community
- Mentor and guide junior consultants and associates, providing technical oversight, quality reviews, and professional development support
Your Knowledge, Skills, and Abilities:
- 5-7 years of hands-on experience in IT audit, compliance, cybersecurity consulting, or GRC advisory services, with significant experience leading SOC 2 Type I/II audits, ISO 27001 assessments, and related attestation engagements
- Deep understanding of IT General Controls (ITGCs), Trust Services Criteria, and audit standards such as SSAE 18 and ISAE 3402, with practical experience leading incident response planning and business continuity initiatives
- Proven ability to lead risk assessments, compliance reviews, readiness evaluations, and remediation programs across frameworks, including SOC 2, ISO 27001, PCI DSS, HITRUST, HIPAA, and CMMC
- Strong analytical and problem-solving skills, with the ability to assess complex risk scenarios and provide strategic, business-aligned recommendations
- Experience leveraging leading GRC platforms and technologies to drive compliance, risk management, and governance initiatives
- Excellent communication, presentation, and stakeholder management skills, with the ability to engage technical teams, executive leadership, and client stakeholders
- Strong project and engagement management skills, including leading multiple client engagements simultaneously while maintaining quality, budget, and client satisfaction objectives
- Demonstrated experience mentoring junior team members and contributing to the development of internal methodologies, templates, and best practices
- Prior experience at a Big 4 firm, mid-tier CPA/advisory firm, cybersecurity consulting firm, or boutique IT audit/attestation practice is strongly preferred
- Applicants must have authorization to work in the United States without current or future visa sponsorship
Preferred Qualifications:
- Certified in one or more of the following: CISA, CIA, CPA, CISSP, and/or ISO 27001 Lead Auditor
- Extensive experience leading the incident response lifecycle, including preparedness, response, recovery, and lessons learned activities
- Experience developing project plans, engagement roadmaps, staffing models, and delivery timelines
- Proven track record leading high-volume SOC 2 and ISO 27001 engagements in a client-facing consulting, advisory, or attestation environment
- Experience with government and regulated-industry compliance frameworks, including FedRAMP, CMMC, NIST 800-53, and related security standards
- Experience managing client relationships, expanding advisory opportunities, and contributing to business development initiatives
Why Echelon?
We are committed to creating an inclusive environment for our team with unquestioned integrity. If you have a special need that requires accommodation, please let your recruiter know. One of our core values is "People with Personality," and we want to allow you the space to bring your full self to work.
We Currently Offer The Following Benefits:
- Access to medical, dental, and vision insurance through Cigna, with the majority of the employee cost covered by the employer
- Employer funding to HSA accounts and FSA access
- Access to a 401(k) through Vanguard with a guaranteed employer contribution
- Flexible vacation policy that allows you to manage your schedule and rest and recharge when you need to.
- 11 holidays with flexibility based on what is important for you and those you love
- Employer-paid short-term and long-term disability, employer-paid life insurance, and access to additional life insurance, hospital coverage, accidental coverage, discounted mental health support, and more
- Support for individual development through certifications, continued learning, conferences, and more
We value a diverse workforce and a culture of inclusivity and belonging. All employment decisions shall be made without regard to age, race, creed, color, religion, gender, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status, or any other basis as protected by federal, state, or local law. Echelon Risk + Cyber is an Equal Opportunity Employer.