Senior Compliance / GRC Engineer
Location: Remote
Duration: 6+ Months
Contract role
Phone and Video Call
Requirements:
We are seeking an experienced Senior Compliance / GRC Engineer to design, implement, and operationalize an enterprise-wide, risk-based information security compliance and controls framework.
The ideal candidate will have hands-on experience designing an internal company risk-based controls framework from scratch, using ISO/IEC 27001:2022 and NIST Cybersecurity Framework (CSF) 2.0 as foundational frameworks. The candidate should also have practical implementation experience with Optro InfoSec Risk Management and Cross Comply modules, including configuration, control mapping, risk assessments, evidence management, compliance monitoring, and reporting.
This role requires someone who understands both security/compliance frameworks and how to translate them into practical, measurable controls implemented across an organization.
Key Responsibilities:
- Design and establish an enterprise risk-based security controls framework from the ground up.
- Develop and maintain a comprehensive control library aligned with:
- ISO/IEC 27001:2022
- NIST CSF 2.0
- NIST SP 800-53 / 800-30 where applicable
- SOC 2 and other applicable regulatory/customer requirements.
- Perform control rationalization and cross-framework mapping to eliminate duplicate controls and establish a unified control framework.
- Develop control objectives, control activities, control owners, testing procedures, evidence requirements, and effectiveness criteria.
- Establish a risk-based approach to control prioritization, including inherent risk, residual risk, control maturity, risk acceptance, and remediation.
- Design and implement enterprise Information Security Risk Management processes.
- Configure and implement Optro InfoSec Risk Management capabilities, including:
- Risk identification and assessment
- Risk scoring and prioritization
- Risk treatment plans
- Risk acceptance
- Risk registers
- Risk monitoring and reporting
- Implement and operationalize Optro Cross Comply, including:
- Framework implementation
- Control mapping
- Compliance assessments
- Evidence collection
- Control testing
- Findings/remediation tracking
- Compliance dashboards and reporting.
- Establish processes for continuous control monitoring and compliance validation.
- Develop compliance metrics, KPIs, KRIs, and executive-level dashboards.
- Work with Security, Infrastructure, Cloud, IT, Application Development, HR, Legal, and business teams to establish and validate control ownership.
- Conduct internal control assessments and identify control gaps.
- Develop remediation plans and track corrective actions through closure.
- Support internal and external audits and provide evidence of control effectiveness.
- Establish a repeatable GRC operating model that can scale across business units, applications, cloud environments, and third parties.
- Continuously evaluate the effectiveness and maturity of the organization's control environment.
Required Experience:
Must Have
- 7+ years of experience in Information Security, GRC, Compliance, Risk Management, or Cybersecurity.
- Demonstrated experience building an enterprise security/compliance controls framework from scratch.
- Strong hands-on experience with ISO/IEC 27001:2022.
- Strong hands-on experience with NIST CSF 2.0.
- Proven experience developing risk-based security controls, rather than simply implementing checklist-based compliance.
- Hands-on experience implementing Optro InfoSec Risk Management.
- Hands-on experience implementing Optro Cross Comply.
- Experience creating and maintaining:
- Enterprise control libraries
- Risk registers
- Control matrices
- Risk/control mappings
- Statements of Applicability
- Control testing methodologies
- Evidence requirements
- Corrective action/remediation processes.
- Experience conducting risk assessments and determining inherent vs. residual risk.
- Experience translating security risks into measurable and auditable controls.
- Experience working with control owners across IT, Cloud, Infrastructure, Security, Applications, and business functions.
Preferred Experience:
- ISO 27001 Lead Implementer or Lead Auditor certification.
- CISA, CISM, CRISC, CISSP, or equivalent.
- Experience with SOC 2, PCI DSS, HIPAA, GDPR, or other regulatory frameworks.
- Experience with cloud security compliance across Azure, AWS, or GCP.
- Experience developing third-party/vendor risk management programs.
- Experience with business continuity and disaster recovery controls.
- Experience with security architecture and technical control validation.
- Experience integrating GRC platforms with security and IT management tools.
- Experience developing executive-level risk and compliance dashboards.
Key Competencies:
The candidate should be able to:
- Start with a blank sheet of paper and design a controls framework.
- Translate business and technology risks into specific security controls.
- Map one control across multiple frameworks without creating unnecessary duplicate controls.
- Determine whether a control is actually effective—not merely whether documentation exists.
- Establish risk-based priorities instead of treating every compliance requirement equally.
- Configure and operationalize GRC technology rather than simply being a GRC platform user.
- Communicate technical risk effectively to both engineers and executives.
Interview Focus Areas:
I would make these mandatory interview areas because they will quickly separate experienced candidates from candidates who have primarily done audit/compliance documentation:
1. Framework Design
“Assume you joined our company tomorrow and there is no formal security controls framework. Walk us through exactly how you would design and implement a risk-based controls framework using ISO 27001:2022 and NIST CSF 2.0.”
2. Risk-Based Controls
“How would you determine which controls are mandatory, which are compensating controls, and which controls should receive the highest implementation priority?”
3. Control Rationalization
“Show us how you would take ISO 27001 and NIST CSF requirements and create a single enterprise control library without creating duplicate controls.”
4. Optro Experience
“Describe your hands-on implementation of Optro InfoSec Risk Management and Cross Comply. What did you configure yourself versus what was handled by another team?”
5. Practical Control Example
“Give us an example of a control you designed from scratch. What risk was it addressing, who owned it, what evidence was required, how frequently was it tested, and how did you determine whether the control was effective?”
6. Risk Assessment
“Explain your methodology for calculating inherent risk and residual risk. Give us a real example.”
7. Control Failure
“If a system owner provides evidence showing that a control was performed, but you discover that the control did not actually mitigate the intended risk, how would you handle it?”
8. Executive Reporting
“What metrics would you put on a CISO/Executive GRC dashboard to show whether the company's control environment is actually improving?
Thanks & Regards,
Navneet Singh
Senior Talent Acquisition Specialist
Fast Hire Inc.