GRC Policy & Standards Specialist

Remote • Posted 4 hours ago • Updated 4 hours ago
Contract W2
Contract Independent
6 Months
No Travel Required
Remote
Depends on Experience
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Artificial Intelligence
  • Attention To Detail
  • Business Operations
  • Business Requirements Gathering
  • Cloud Computing
  • Data Governance
  • ISO 9000
  • NIST SP 800 Series
  • Risk Management Framework
  • Regulatory Compliance
  • Policy Administration
  • Risk Management
  • IT Risk Management
  • RMF
  • System Integration Testing
  • IT Operations
  • Incident Management
  • Legal

Summary

Job Description – GRC Policy & Standards Specialist
Experience: 6–10 years
Level: Mid-Level / Senior Consultant
Role: GRC Policy, Standards & Governance Consultant
Role Overview
• We are looking for a strong GRC Policy & Standards Specialist to develop, enhance, and 
operationalize enterprise governance documentation across security, technology, risk, 
and operational functions.
• The successful candidate will have demonstrated experience developing enterprise 
policies, standards, control requirements, procedures, and supporting governance 
documentation that are clear, structured, actionable, and aligned with recognized 
regulatory and industry frameworks.
• This role requires more than strong writing skills. The individual must understand what 
constitutes effective GRC documentation, including appropriate distinctions between 
policies, standards, procedures, controls, and guidelines, and be able to translate 
complex regulatory, risk, security, technology, and operational requirements into 
documentation that can be practically implemented.
• A critical part of the role will be working across organizational boundaries. The 
individual must be comfortable engaging with technology, cybersecurity, operations, 
risk, compliance, legal, and business stakeholders, reconciling different perspectives, 
challenging unclear requirements, and driving documentation through review, approval, 
and adoption.
Key Responsibilities
• Lead the development, review, and enhancement of enterprise GRC policies, 
standards, procedures, control requirements, and governance documentation.
• Establish consistent documentation structures, terminology, requirements language, 
and governance conventions across policies and standards.
• Translate regulatory, risk, security, technology, and business requirements into clear, 
enforceable, and operationally practical policy and standards requirements.
• Ensure appropriate distinction and traceability between policy statements, standards 
requirements, control objectives, procedures, and supporting guidance.
• Work directly with subject matter experts across technology, cybersecurity, operations, 
risk, compliance, legal, privacy, and business functions to develop and validate 
requirements.
• Facilitate working sessions and stakeholder reviews to identify requirements, resolve 
conflicting requirements, close documentation gaps, and achieve agreement on 
governance expectations.
• Convert complex technical requirements into language that can be understood by 
business and operational stakeholders while maintaining sufficient specificity for 
technology and control owners.
• Ensure policy and standards requirements are written in a manner that is measurable, 
auditable, and capable of being translated into controls and operational processes.
• Support the mapping of policies and standards to regulatory obligations, control 
frameworks, risks, and enterprise requirements.
• Partner with control owners and operational teams to ensure documented 
requirements can be realistically implemented and evidenced.
• Identify gaps between documented requirements and current operational or 
technology practices and help define appropriate remediation actions.
Required Experience
• 6–10 years of experience across policy governance, GRC, cybersecurity governance, 
compliance, technology and enterprise risk.
• Demonstrated experience authoring and substantially revising enterprise policies and 
standards, rather than solely reviewing documentation created by others.
• Strong understanding of what constitutes effective and enforceable GRC and 
governance documentation.
• Ability to write requirements that are clear, concise, enforceable, testable, and 
appropriately prescriptive.
• Strong understanding of GRC concepts including risk management, control design, 
compliance, assurance, issue management, exceptions, and governance oversight.
• Ability to understand technical concepts and work effectively with technology, 
architecture, engineering, cybersecurity, and IT operations teams without needing to be 
a hands-on engineer.
• Ability to work with operational and business stakeholders to understand processes, 
identify practical requirement gaps, and ensure governance requirements are usable 
outside of GRC.
• Experience translating regulatory, framework, security, or risk requirements into 
enterprise policy, standards, and control language.
• Strong stakeholder management skills, including the ability to facilitate discussions 
involving management-level+ stakeholders.
• Excellent written communication, editing, analytical, and information-structuring skills.
• Strong attention to detail and ability to identify ambiguous language, inconsistent 
requirements, documentation gaps, and conflicting governance expectations.
• Confidence working directly with senior leaders, subject matter experts, control 
owners, and second-line risk and compliance functions.
Preferred Experience
Experience with several of the following would be valuable:
• NIST CSF / NIST 800-series
• ISO/IEC 27001 and 27002
• ISO/IEC 42001
• NIST AI RMF
• SOC 2
• Privacy and data governance frameworks
• Third-party risk management
• Secure software development and technology governance
• Cloud and infrastructure security standards
• AI and emerging technology governance
• Regulatory compliance frameworks
• GRC platforms and policy management tools
Most Important Profile
• We are not looking for a technical writer who simply documents information provided 
by subject matter experts, nor are we looking for a purely technical security or 
engineering resource.
• We need someone who understands governance, risk, controls, and enterprise policy 
architecture and can independently determine what strong policy and standards 
documentation should look like.
• The ideal candidate can sit with a cybersecurity architect, technology leader, 
operational process owner, risk professional, or compliance SME; understand their 
requirements; challenge ambiguity or impractical expectations; and translate those 
discussions into clear, defensible, implementable, and auditable enterprise 
requirements.
• Strong candidates should be able to operate as both a governance subject matter 
expert and a skilled policy author, while effectively navigating stakeholders across 
business, operations, risk, security, and technology

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10121769
  • Position Id: 9055463
  • Posted 4 hours ago
Contact the job poster
IK

Imran khan

Recruiter @ Central Business Solutions
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote

Today

Easy Apply

Contract

Depends on Experience

Remote

Today

Contract

$55.00 - $80.00

Remote or Silver Spring, Maryland

Today

Full-time

USD 3,000.00 per month

Remote

2d ago

Easy Apply

Contract, Third Party

Depends on Experience

Search all similar jobs