Skip to main content
ResumeKart
← Back to Jobs

SISA Information Security - Cyber Security Consultant - GRC Tools

SISA Information Security•Mumbai, Maharashtra
Full-timeMid Level
👁️ 0 views•📝 0 applications•Posted 9/24/2026•Expires 10/24/2026
Tailor Resume for This JobCheck ATS Score

Get alerts for roles like this

More SISA Information Security - Cyber Security Consultant - GRC Tools roles in Mumbai, Maharashtra — straight to your inbox. No account needed.

Applying to this role? Tailor your résumé to this job description in one click, then download it clean — no watermark, no subscription.

Job Description

Cybersecurity GRC Consultant - CMMC, FedRAMP & Security Compliance. Role Overview : We are looking for a hands-on Cybersecurity GRC Consultant with strong experience in CMMC, FedRAMP, NIST, SOC 2, ISO 27001 and/or HITRUST to lead and deliver cybersecurity compliance and advisory engagements. The role requires practical experience in control assessment, framework mapping, evidence validation, gap assessment, risk analysis, remediation advisory and audit/report delivery. This is a delivery-focused consulting role requiring both technical understanding and strong client-facing capabilities. Key Responsibilities : - Lead end-to-end cybersecurity GRC and compliance engagements, including scoping, planning, assessment, evidence review, gap analysis, remediation support and final reporting. - Perform assessments against CMMC 2.0, FedRAMP, NIST SP 800-171, NIST SP 800-53, ISO 27001, SOC 2 and HITRUST CSF, based on client requirements. - Develop and maintain control mappings and crosswalks across CMMC, FedRAMP, NIST, ISO 27001, SOC 2 and HITRUST. - Conduct detailed control design and operating effectiveness assessments, including review of policies, procedures, configurations, records and other audit evidence. - Evaluate control gaps, determine risk and impact, and develop practical remediation recommendations. - Support clients in defining and documenting security controls, policies, procedures, control narratives and evidence requirements. - Develop and/or review System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), risk assessments, Statements of Applicability, control matrices and audit workpapers. - Support SOC 2 readiness and Type I/Type II assessment activities, including Trust Services Criteria mapping, control testing and evidence evaluation. - Support ISO 27001 implementation/readiness/certification and surveillance activities, including ISMS controls, risk treatment and Statement of Applicability. - Support HITRUST CSF readiness and validated assessment activities, including control mapping, evidence assessment and remediation tracking. - Perform NIST-based cybersecurity assessments using NIST CSF and NIST SP 800-series standards where applicable. - Validate control mappings and assessment methodologies against applicable regulatory, industry and framework requirements. - Lead client discussions with IT, security, engineering, compliance, risk and audit stakeholders to understand the environment and validate controls. - Prepare assessment reports, findings, risk ratings, executive summaries and remediation roadmaps for technical and executive audiences. - Coordinate with external assessors, auditors, C3PAOs/3PAOs and other assurance stakeholders where applicable. - Maintain assessment quality through structured workpapers, evidence traceability, review procedures and quality assurance. - Contribute to development and continuous improvement of GRC methodologies, assessment templates, control libraries and reusable delivery assets. - Support presales activities, including scope definition, effort estimation, solutioning and technical proposal inputs. Required Qualifications : - 5+ years of hands-on experience in cybersecurity GRC, IT audit, security compliance or risk consulting. - Demonstrated experience delivering one or more of the following: CMMC 2.0, FedRAMP, NIST CSF / NIST SP 800-171 / NIST SP 800-53, ISO 27001, SOC 2, HITRUST CSF. - Strong understanding of security control frameworks, control objectives, control design, operating effectiveness and evidence-based assessment methodologies. - Hands-on experience with control mapping/crosswalks across multiple cybersecurity and compliance frameworks. - Experience conducting gap assessments, risk assessments, control testing and evidence validation. - Experience preparing or reviewing SSPs, POA&Ms, risk registers, control matrices, audit workpapers and assessment reports. - Practical understanding of cloud security, IAM, network security, vulnerability management, logging/monitoring, incident response, data protection, business continuity and third-party risk. - Ability to translate technical and regulatory requirements into practical security controls and implementation recommendations. - Strong written and verbal communication skills with the ability to communicate effectively with both technical teams and senior management. - Ability to work independently in a consulting environment and manage multiple client engagements. Preferred Qualifications : - Certifications in one or more of the following are preferred : CMMC-AB Certified CMMC Professional (CCP) / Certified CMMC Assessor (CCA), FedRAMP / 3PAO assessment experience, CISSP, CISA, CISM, CRISC, ISO 27001 Lead Auditor / Lead Implementer, HITRUST Certified CSF Practitioner / related HITRUST credential, SOC 2 / AICPA-related audit or assurance experience.

Required Skills

AuditCommunicationCybersecurityData PrivacyPresalesProject EstimationQuality Assurance

Partner picks for SISA Information Security - Cyber Security Consultant - GRC Tools in Mumbai

Matched to the skills this page calls for and the candidate's location.

Partner
  • Partner course provider

    Certification training in cloud, data, cyber security, project management and digital marketing.

  • Partner course provider

    Online higher-education programmes with university partners in India and abroad.

  • edXVerified partner
    Partner course provider

    Courses and programmes from universities and institutions worldwide.

Partners are ResumeKart affiliates or institutes it works with; ResumeKart may earn a commission when a candidate enrols. Placement is decided by relevance, not payment. How ResumeKart earns

The best-paying roles in your field. Every week. Free.

Join 10,000+ professionals getting job alerts and salary insights in their inbox

We respect your privacy. Unsubscribe anytime with one click.