Overview
The Governance, Risk & Compliance (GRC) Consultant will support a strategic initiative focused on delivering a NIST Cybersecurity Framework (CSF) 2.0 maturity assessment program. This role will involve collaboration with various stakeholders to produce key documentation and outputs within a defined project timeline. The consultant will leverage their specialized expertise in governance, risk, and compliance to enhance the organization's cybersecurity capabilities and fulfill specific project outcomes.
Responsibilities
- Develop NIST CSF 2.0 profile documentation.
- Assess current capabilities against the NIST CSF 2.0 framework.
- Conduct gap analysis and identify areas for improvement.
- Collect, review, and organize supporting evidence.
- Produce assessment outputs, reports, and associated documentation.
- Provide recommendations to enhance governance, risk, and compliance practices.
- Deliver agreed project artefacts in line with program milestones.
Requirements
- Demonstrable experience applying the NIST Cybersecurity Framework, ideally NIST CSF 2.0.
- Strong governance, risk, and compliance experience within technology and cyber security environments.
- Experience conducting maturity assessments, control assessments, or compliance reviews.
- Ability to produce high quality governance, assurance, and compliance documentation.
- Experience delivering specialist consultancy services within defined project environments.