Governance

Overview

The Governance, Risk & Compliance (GRC) Consultant will support a strategic initiative focused on delivering a NIST Cybersecurity Framework (CSF) 2.0 maturity assessment program. This role will involve collaboration with various stakeholders to produce key documentation and outputs within a defined project timeline. The consultant will leverage their specialized expertise in governance, risk, and compliance to enhance the organization's cybersecurity capabilities and fulfill specific project outcomes.

Responsibilities

  • Develop NIST CSF 2.0 profile documentation.
  • Assess current capabilities against the NIST CSF 2.0 framework.
  • Conduct gap analysis and identify areas for improvement.
  • Collect, review, and organize supporting evidence.
  • Produce assessment outputs, reports, and associated documentation.
  • Provide recommendations to enhance governance, risk, and compliance practices.
  • Deliver agreed project artefacts in line with program milestones.

Requirements

  • Demonstrable experience applying the NIST Cybersecurity Framework, ideally NIST CSF 2.0.
  • Strong governance, risk, and compliance experience within technology and cyber security environments.
  • Experience conducting maturity assessments, control assessments, or compliance reviews.
  • Ability to produce high quality governance, assurance, and compliance documentation.
  • Experience delivering specialist consultancy services within defined project environments.