WFH.teamOpen app
Back to remote jobs
Remote job detail

Senior Technical Consultant - Security GRC

AHEAD

LocationIndia
SenioritySenior
CompanyAHEAD
Verified recentlyChecked today
Compensation

Salary not listed

Salary details are shown when available from the source listing. Sign in before applying so the role can be reviewed against your resume, salary goals, seniority, timezone, and location eligibility.

Requirements and working style

Decision details from the source listing

Experience

5+ years stated

Education

Bachelor’s degree in a relevant field or equivalent experience

Schedule

flexible

Benefits stated
Health insurance, with options to extend coverage to dependentsPaid time off and company holidaysAdditional leave benefits as per policyFlexible work arrangementsLearning and development opportunitiesEmployee wellness initiativesRetirement and statutory benefits in line with India regulations

These fields are normalized from the employer's text. Confirm details on the employer site before applying.

WFH.team analysis

What this posting tells you

Senior remote Security GRC consulting role based in Gurugram, India. Requires roughly 5+ years of relevant experience, including substantial consulting or comparable client-advisory work; strong working depth across NIST CSF, NIST SP 800-53, NIST SP 800-171, CIS Controls, CRI Profile, and ISO/IEC 27001; and demonstrated risk management and quantification skills. A relevant bachelor’s degree or equivalent experience is required. Salary is not stated.

Role lane

Accounting, Customer success, Data, Design and creative, DevOps, Education, Legal, Marketing, Operations, Product, Security, Software, Customer support, Writing and content

Where you can work

India

Working hours

Timezone overlap is not stated.

Arrangement

Senior · contract · full_time

Required signals
Security GRC consulting and client advisoryNIST Cybersecurity FrameworkNIST SP 800-53NIST SP 800-171CIS ControlsCRI ProfileISO/IEC 27001ISO/IEC 27002End-to-end risk managementRisk quantificationControl assessment and assuranceExecutive-level writing and presentationStakeholder and workshop facilitation
Confirm before applying
  • Required timezone overlap is not stated
  • Compensation is not listed
Market context

Accounting hiring on WFH.team

1,530active related roles
984new in the latest period
968.4jobs per 100 candidates
$123kmedian of comparable listed ranges

Category counts come from WFH.team's latest published remote job market snapshot.

Explore the remote job market
Skills and signals
Security GRC consulting and client advisoryNIST Cybersecurity FrameworkNIST SP 800-53NIST SP 800-171CIS ControlsCRI ProfileISO/IEC 27001ISO/IEC 27002End-to-end risk managementRisk quantificationControl assessment and assuranceExecutive-level writing and presentationStakeholder and workshop facilitationRemote in Gurugram, Haryana, India
Job description

Senior Technical Consultant - Security GRC at AHEAD

AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digital transformation.

At AHEAD, we prioritize creating a culture of belonging, where all perspectives and voices are represented, valued, respected, and heard. We create spaces to empower everyone to speak up, make change, and drive the culture at AHEAD.

We are an equal opportunity employer, and do not discriminate based on an individual's race, national origin, color, gender, gender identity, gender expression, sexual orientation, religion, age, disability, marital status, or any other protected characteristic under applicable law, whether actual or perceived.

We embrace all candidates that will contribute to the diversification and enrichment of ideas and perspectives at AHEAD.

Responsibilities

Client consulting and engagement leadership

  • Shape problem statements, engagement scope, assumptions, and success criteria with the client sponsor and the account team.
  • Build workplans, RAID logs, and stakeholder maps; keep delivery on quality even when the client’s evidence or ownership is incomplete.
  • Facilitate workshops with CISOs, control owners, internal audit, legal, procurement, and business executives. Drive decisions, not status meetings.
  • Manage resistance, conflicting frameworks, and “we already have a policy” arguments without losing the room or the facts.
  • Write and present deliverables that survive legal, audit, and executive review: current-state assessments, target operating models, control crosswalks, risk registers, quantified scenarios, roadmaps, and board narratives.
  • Coach client staff so the program does not collapse when the engagement ends. Consulting value is transfer, not slide volume.
  • Support pre-sales and scoping when asked: approach, level of effort, risks to delivery, and what “good” looks like for this client.

Framework design, assessment, and rationalization

  • Assess and design against NIST CSF (1.1 and/or 2.0): profiles, subcategory outcomes, tiers, and CSF as the executive reporting spine.
  • Assess and tailor NIST SP 800-53 (Rev. 5 preferred): control families, baselines, overlays, common/hybrid/system-specific controls, and assessment procedures.
  • Assess NIST SP 800-171 implementation for CUI: requirement status, 800-171A-style objectives, scoping of CUI flows, POA&Ms, and contractor obligation implications.
  • Apply CIS Controls (v8 preferred) as a prioritized operational control set (IG1–IG3), mapped to CSF and 800-53 rather than run as a second bureaucracy.
  • Interpret and assess the CRI Profile , including diagnostic statements and financial-sector or critical-third-party expectations.
  • Design or uplift an ISO/IEC 27001 ISMS: scope, SoA, risk assessment and treatment, internal audit liaison, management review inputs, and certification or surveillance readiness.
  • Build and maintain crosswalks so one control, one owner, and one evidence package can satisfy multiple frameworks

Assurance, evidence, and defensible writing

  • Design test procedures, challenge evidence quality, and write deficiency and residual-risk narratives that are factual and unambiguous.
  • Prepare clients for internal audit, ISO certification bodies, customer assessments, and 800-171 / CRI / CSF inquiries.
  • Produce executive summaries that a non-specialist leader can act on without a decoder.

Required qualifications

Highly proficient written and spoken English at an executive, audit, and client-delivery standard. Grammar, structure, and tone must be consistently professional. You can explain a control failure, a residual-risk position, or a quantified scenario to an engineer, an auditor, and a board member in the register each expects. A writing sample or timed drafting exercise may be required.

Demonstrated senior consulting or equivalent client-advisory experience: scoping ambiguous problems, facilitating senior workshops, managing difficult stakeholders, producing commercial-quality deliverables, defending recommendations under challenge, and transferring methods to the client. Internal GRC operations experience alone is not sufficient unless you can show the same client-facing muscle.

Frameworks (all required, with working depth—not acronym familiarity)

  • NIST Cybersecurity Framework
  • NIST SP 800-53
  • NIST SP 800-171
  • CIS Controls
  • CRI Profile
  • ISO/IEC 27001 (working command of 27002 expected)

Risk (required)

End-to-end risk management (identify, analyze, evaluate, treat, accept, monitor) and risk quantification (scenarios, ranges, expected loss or equivalent, explicit assumptions). “High / medium / low” without a method is not qualification.

Experience and education

Roughly 5+ years in security GRC, risk, audit, or control assurance, including substantial time in consulting, professional services, or a comparably senior client-advisory capacity. Bachelor’s degree in a relevant field or equivalent experience. Seniority is judged by judgment, writing, and client impact—not title inflation.

Why AHEAD

Through our daily work and internal groups like Moving Women AHEAD and RISE AHEAD, we value and benefit from diversity of people, ideas, experience, and everything in between.

We fuel growth by stacking our office with top-notch technologies in a multi-million-dollar lab, by encouraging cross department training and development, sponsoring certifications and credentials for continued learning.

India Employment Benefits include

Comprehensive health insurance coverage for employees, with options to extend coverage to dependents

Paid time off and company holidays, along with additional leave benefits as per policy

Flexible work arrangements, supporting work-life balance

Learning and development opportunities to support continuous growth and upskilling

Employee wellness initiatives and programs focused on physical and mental well-being

Retirement and statutory benefits in line with India regulations

Inclusive and people-first culture, with a strong focus on collaboration and ownership

Company context

Working remotely at AHEAD

AHEAD is hiring for 78 active remote roles, with remote-friendly openings, application links, and job details refreshed from the public remote job inventory.

Remote policy

Remote hiring signal is inferred from active confirmed-remote job listings.

Research AHEAD