Post Job Free
Sign in

GRC Consultant

Company:
Galent
Location:
Erlanger, KY, 41018
Posted:
June 28, 2025
Apply

Description:

Job Title: GRC Consultant Location: Erlanger, KY (Onsite) Contract Key Responsibilities:Review Projects and their technical design documents for Information security risks and advise on suitable controls and mitigations at early stages of the programFair understanding of Technology Landscape Applications Infrastructure Cloud and review Client's information security and related threats and vulnerabilities legal and regulatory requirementsGood Understanding on Security Standards like ISO 270012 SOX ITGC SOC1 or SOC2 DevSecOps OWASP top 10 Business Impact analysis ISO 22301 ISO 27005Assess and classify all potential business and infrastructure information risksReview and advise on information security risks of vendor offerings New leveraging existing SAAS PAAS IAAS services including integration with Client environmentConduct risk assessment on Applications Network Systems according to Client policies applicable Standards legal regulatory requirementsIdentify the risks in the Client Projects provide recommendations for remediation of identified risksTranslate Technical legal and Regulatory Compliance obligations into a cohesive collection of Security Controls and provides the respective stakeholders with the IRM requirements and its implementation methodologiesIdentify or design the controls for implementation based on the outcome of Risk Assessment its remediation and residual riskEnsure all the controls outlined for an application Infrastructure are designed effectivelyReview Vulnerability Assessment and Penetration Test scan results and recommend the risks to be remediatedReview and approve the control design of supplier and their organization technical specifications against Client security control requirementsEnsure all the risks are documented classified and tracked with appropriate action as per the IRM standardsWork with Project Managers Business Analysts Architecture and Support Team to ensure Client Information Risk Management standards are being followedTest the control effectiveness post implementation or deployment of controls and technologiesConduct Security governance with Client stakeholders Technology Knowledge:Understanding of Cloud Security SAAS IAAS and PAAS and Onpremise infrastructureUnderstanding of secure application development and supportKnowledge on Network Security Data Security Practices EndPoint Security Identity and Access ManagementKnowledge on Business Continuity Plan and Disaster Recovery Knowledge and Skills:Projects Stake holder Management Governance Management ReportingVery good communication skills Agile Project deliveryCloud Security controls Data Security SeInfo baselines Privacy requirements

Apply