Senior Technical Consultant - Security GRC
Gurugram, India · Remote · Full-time
- Posted 1w ago
- From AHEAD’s careers page
- Location
- Gurugram, India
- Work mode
- Remote
- Type
- Full-time
- Level
- Senior
- Experience
- 5+ years
- Department
- Information Technology
Opens the listing on jobs.lever.co
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
Responsibilities
-
Client consulting and engagement leadership
-
Shape problem statements, engagement scope, assumptions, and success criteria with the client sponsor and the account team.
-
Build workplans, RAID logs, and stakeholder maps; keep delivery on quality even when the client’s evidence or ownership is incomplete.
-
Facilitate workshops with CISOs, control owners, internal audit, legal, procurement, and business executives. Drive decisions, not status meetings.
-
Manage resistance, conflicting frameworks, and “we already have a policy” arguments without losing the room or the facts.
-
Write and present deliverables that survive legal, audit, and executive review: current-state assessments, target operating models, control crosswalks, risk registers, quantified scenarios, roadmaps, and board narratives.
-
Coach client staff so the program does not collapse when the engagement ends. Consulting value is transfer, not slide volume.
-
Support pre-sales and scoping when asked: approach, level of effort, risks to delivery, and what “good” looks like for this client.
-
Framework design, assessment, and rationalization
-
Assess and design against NIST CSF (1.1 and/or 2.0): profiles, subcategory outcomes, tiers, and CSF as the executive reporting spine.
-
Assess and tailor NIST SP 800-53 (Rev. 5 preferred): control families, baselines, overlays, common/hybrid/system-specific controls, and assessment procedures.
-
Assess NIST SP 800-171 implementation for CUI: requirement status, 800-171A-style objectives, scoping of CUI flows, POA&Ms, and contractor obligation implications.
-
Apply CIS Controls (v8 preferred) as a prioritized operational control set (IG1–IG3), mapped to CSF and 800-53 rather than run as a second bureaucracy.
-
Interpret and assess the CRI Profile, including diagnostic statements and financial-sector or critical-third-party expectations.
-
Design or uplift an ISO/IEC 27001 ISMS: scope, SoA, risk assessment and treatment, internal audit liaison, management review inputs, and certification or surveillance readiness.
-
Build and maintain crosswalks so one control, one owner, and one evidence package can satisfy multiple frameworks
-
Assurance, evidence, and defensible writing
-
Design test procedures, challenge evidence quality, and write deficiency and residual-risk narratives that are factual and unambiguous.
-
Prepare clients for internal audit, ISO certification bodies, customer assessments, and 800-171 / CRI / CSF inquiries.
-
Produce executive summaries that a non-specialist leader can act on without a decoder.
Skills they ask for
Pick one to see other roles that ask for it.
About AHEAD
Digital platforms for modern enterprisesAHEAD engineers data, developer, and infrastructure platforms for enterprises, and provides consulting and managed services to improve IT operations.
See all 58 roles at AHEADMore roles at AHEAD
See all 58- Senior Manager, Partner Marketing – Security PartnersUnited States · Director · RemoteMarketing · Director · RemoteUnited States1d
- Sr. Engineer - AzureHyderabad · HybridInformation Technology · HybridHyderabad, India1d
- Manager, Web & Marketing PlatformsUnited States · Senior · RemoteInformation Technology · Senior · RemoteUnited States2d
- Services Operations SpecialistsGurugram · HybridBusiness Operations · HybridGurugram, India2d
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.