Skip to content

Open nowPosted 4 days ago

Senior Technical Consultant - Security GRC

thinkahead144 open roles

Where
Gurugram, Haryana
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Technical Consultant - Security GRCthinkahead · Gurugram, Haryana
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on thinkahead's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 4 days ago

The posting

AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digital transformation.

At AHEAD, we prioritize creating a culture of belonging, where all perspectives and voices are represented, valued, respected, and heard. We create spaces to empower everyone to speak up, make change, and drive the culture at AHEAD.

We are an equal opportunity employer, and do not discriminate based on an individual's race, national origin, color, gender, gender identity, gender expression, sexual orientation, religion, age, disability, marital status, or any other protected characteristic under applicable law, whether actual or perceived.

We embrace all candidates that will contribute to the diversification and enrichment of ideas and perspectives at AHEAD.

This is a senior consulting role, not an internal control-operations seat. You will be sold to clients as a credible authority on security GRC. You diagnose program maturity, design target-state operating models, quantify risk in business terms, and leave behind frameworks, artifacts, and decisions the client can run without you.

You must be highly proficient in English. Client deliverables, findings, board packs, statements of work, and live workshops are held to an executive and audit standard. Fluency is not enough. The bar is precise, concise, defensible professional English under time pressure.

You must be expert in NIST CSF, NIST SP 800-53, NIST SP 800-171, CIS Controls, the Cyber Risk Institute (CRI) Profile, and ISO/IEC 27001, and you must be able to manage and quantify risk—not only score it.

You must also be a consultant: structure ambiguous problems, manage senior stakeholders, run workshops, write commercial-quality deliverables, defend recommendations, and transfer capability to the client team.

Why this role is Senior You are expected to operate with limited supervision on complex, multi-framework engagements. Typical work includes regulatory or contractual readiness (including CUI / 800-171), CSF or CRI profile builds, ISO 27001 ISMS design or certification support, control rationalization across overlapping frameworks, and quantified risk analysis for boards, CISOs, and risk committees. You will often be the most senior GRC voice in the room. That means you set the method, hold the quality bar, and say clearly when a control, a score, or a “green” status is not the same thing as acceptable residual risk.

Core Mandate Own the analytical and advisory quality of assigned GRC workstreams from scoping through readout and knowledge transfer. Translate overlapping control frameworks into one coherent control and evidence model the client can operate. Produce risk positions that combine sound qualitative judgment with quantification the business can use. Run the engagement like a consultant: scope, stakeholders, workshops, issues, deliverables, and next-step decisions.

Responsibilities

  • Shape problem statements, engagement scope, assumptions, and success criteria with the client sponsor and the account team.
  • Build workplans, RAID logs, and stakeholder maps; keep delivery on quality even when the client’s evidence or ownership is incomplete.
  • Facilitate workshops with CISOs, control owners, internal audit, legal, procurement, and business executives. Drive decisions, not status meetings.
  • Manage resistance, conflicting frameworks, and “we already have a policy” arguments without losing the room or the facts.
  • Write and present deliverables that survive legal, audit, and executive review: current-state assessments, target operating models, control crosswalks, risk registers, quantified scenarios, roadmaps, and board narratives.
  • Coach client staff so the program does not collapse when the engagement ends. Consulting value is transfer, not slide volume.
  • Support pre-sales and scoping when asked: approach, level of effort, risks to delivery, and what “good” looks like for this client.
  • Assess and design against NIST CSF (1.1 and/or 2.0): profiles, subcategory outcomes, tiers, and CSF as the executive reporting spine.
  • Assess and tailor NIST SP 800-53 (Rev. 5 preferred): control families, baselines, overlays, common/hybrid/system-specific controls, and assessment procedures.
  • Assess NIST SP 800-171 implementation for CUI: requirement status, 800-171A-style objectives, scoping of CUI flows, POA&Ms, and contractor obligation implications.
  • Apply CIS Controls (v8 preferred) as a prioritized operational control set (IG1–IG3), mapped to CSF and 800-53 rather than run as a second bureaucracy.
  • Interpret and assess the CRI Profile, including diagnostic statements and financial-sector or critical-third-party expectations.
  • Design or uplift an ISO/IEC 27001 ISMS: scope, SoA, risk assessment and treatment, internal audit liaison, management review inputs, and certification or surveillance readiness.
  • Build and maintain crosswalks so one control, one owner, and one evidence package can satisfy multiple frameworks
  • Design test procedures, challenge evidence quality, and write deficiency and residual-risk narratives that are factual and unambiguous.
  • Prepare clients for internal audit, ISO certification bodies, customer assessments, and 800-171 / CRI / CSF inquiries.
  • Produce executive summaries that a non-specialist leader can act on without a decoder.

Required qualifications

  • NIST Cybersecurity Framework
  • NIST SP 800-53
  • NIST SP 800-171
  • CIS Controls
  • CRI Profile
  • ISO/IEC 27001 (working command of 27002 expected)

Why AHEAD:

Through our daily work and internal groups like Moving Women AHEAD and RISE AHEAD, we value and benefit from diversity of people, ideas, experience, and everything in between.

We fuel growth by stacking our office with top-notch technologies in a multi-million-dollar lab, by encouraging cross department training and development, sponsoring certifications and credentials for continued learning.

India Employment Benefits include:

Comprehensive health insurance coverage for employees, with options to extend coverage to dependents

Paid time off and company holidays, along with additional leave benefits as per policy

Flexible work arrangements, supporting work-life balance

Learning and development opportunities to support continuous growth and upskilling

Employee wellness initiatives and programs focused on physical and mental well-being

Retirement and statutory benefits in line with India regulations

Inclusive and people-first culture, with a strong focus on collaboration and ownership

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against thinkahead's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on thinkahead's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    thinkahead's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.