Principal Cybersecurity GRC Architect - (CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditorv) (Onsite / Contract)

San Francisco, CA, US • Posted 9 hours ago • Updated 1 hour ago
Contract W2
Contract Corp To Corp
Contract Independent
6 Months
On-site
$90 - $100/hr
Company Branding Image
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • NIST CSF 2.0
  • cybersecurity
  • SOC 2
  • CISSP
  • CISM
  • CISA
  • CRISC
  • ISO 27001 Lead Auditor
  • Principal Cybersecurity GRC Architect

Summary

Principal GRC, Cyber Security Data Architect

SAN FRANCISCO, CA

Duration: 06+ months

Lead the delivery of a NIST CSF 2.0 cybersecurity gap and maturity assessment for a global enterprise program, covering assessment planning, stakeholder engagement, evidence review, maturity scoring, risk based gap prioritization, executive reporting, and development of a practical improvement roadmap.

Key Responsibilities

  • Own end to end engagement governance, project planning, milestones, risks, dependencies, status reporting, and stakeholder communications.
  • Conduct NIST CSF 2.0 maturity assessment across functions, categories, subcategories, implementation tiers, and profiles.
  • Review policies, standards, procedures, controls, risk registers, asset inventories, KPIs/KRIs, and supporting evidence.
  • Facilitate interviews and workshops with cybersecurity, risk, compliance, technology, and business stakeholders.
  • Define defensible maturity scoring, identify control gaps, assess business risk, and prioritize remediation actions.
  • Develop executive ready assessment reports, maturity dashboards, prioritized recommendations, and near/mid/long term roadmap.

Required Experience

Area

Requirement

Total Experience

10 to 15 years in cybersecurity, GRC, risk management, audit, security consulting, or cybersecurity program assessment.

NIST CSF Expertise

Strong hands on experience with NIST CSF, preferably NIST CSF 2.0 maturity assessments.

Framework Mapping

Experience mapping controls across NIST CSF, ISO 27001, NIST 800 53, CIS Controls, SOC 2, or similar frameworks.

Assessment Delivery

Proven experience conducting enterprise wide cybersecurity maturity, gap, risk, or control assessments.

Stakeholder Management

Ability to conduct interviews/workshops with senior security, risk, compliance, technology, and business stakeholders.

Executive Reporting

Strong experience creating leadership ready cybersecurity reports, maturity dashboards, and roadmap presentations.

Consulting Delivery

Experience working in consulting/advisory environments with structured methodology, governance, and client facing deliverables.

Risk Prioritization

Ability to convert control gaps into risk ranked remediation recommendations and practical roadmaps.

Required Skills

  • Strong expertise in NIST CSF 2.0, cybersecurity governance, risk management, compliance, control maturity models, and ISO 27001 / ISMS.
  • Ability to map controls across NIST CSF, ISO 27001, NIST 800 53, CIS Controls, SOC 2, and similar frameworks.
  • Experience in evidence based assessment, maturity scoring, risk based gap prioritization, and remediation roadmap development.
  • Excellent consulting delivery, workshop facilitation, stakeholder management, executive reporting, and written/verbal communication skills.

Preferred Certifications

  • CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor / Lead Implementer, NIST CSF training/certification, PMP / Prince2 / Agile certification preferred.

Tools / Platforms Knowledge Preferred

  • GRC and evidence management platforms such as Archer, ServiceNow GRC, OneTrust, MetricStream, SharePoint, Teams, Excel, PowerPoint, Visio, Power BI, and cybersecurity KPI/KRI dashboarding tools.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91163020
  • Position Id: 9063338
  • Posted 9 hours ago

Company Info

About American IT Systems

American IT Systems Staffing Fastest growing Recruitment firm helping clients hire the best quality candidates faster across the globe.

We provide services starting from Temporary Staffing & Permanent Recruitment to management consulting. We specialize in Technology, Product & Design hiring headhunting & sourcing passive resources using cutting edge technology & tools

Our Aim

Hiring and recruiting top talent can be a challenging, time-intensive process. Client organizations recognize the value in saving time, money and preventing unnecessary burden on internal staff by outsourcing certain hiring needs. It can also send a strong message to top professionals they will spare no expense in finding and hiring the best talent possible..

About_Company_OneAbout_Company_Two
Contact the job poster
SS

Steve Smith

Recruiter @ American IT Systems
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs