Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Principal Consultant - GRC/Security image - Rise Careers
Job details

Principal Consultant - GRC/Security

Atmosera empowers businesses to Redefine Possible with Modern Technology and Human Expertise. Our exceptional experience across Applications, Data & AI, DevOps, Security, and the Microsoft Azure platform enables organizations to accelerate innovation, enhance security, and optimize operational agility. As a Microsoft Partner with nine specializations, GitHub AI Partner of the Year, a member of the GitHub Advisory Board, and a member of the prestigious Microsoft Intelligent Security Association (MISA), Atmosera expertly delivers cutting-edge, integrated solutions that deliver business value.


As a Principal Consultant on our Professional Services team, you'll be considered a Compliance Advisory subject matter expert (SME) with an ability to evaluate/assess the security and compliance of client firms/services against regulatory and industry requirements and standards, and against security best practice frameworks, etc. You will also need to be able to go hands-on, potentially implementing such recommendations, if needed.


The Principal Consultant (SME) is expected to leverage their technical and business experience across three (3) domains, including:

1. Evaluate and enhance the security of complex systems that may impact both risk and compliance for organizations, large and small.

2. Mentor and develop team members to help grow the team and its capabilities

3. Engage outwardly into the community through blog posts, technical white papers, forum participation, and conference speaking engagements. Engage inwardly to support business and practice growth by developing Sales/Marketing collateral, delivery methodologies, and SOPs, train/mentor colleagues as necessary, and serve as the SME for all topics related to your technical or compliance area of expertise


What You'll Do
  • Work with and mentor team members to drive customer success.
  • Scope and lead engagements with clients. This includes leading pre-sales calls and onsite visits, understanding customer security and compliance requirements and environments, and proposing and delivering packaged offerings or custom solution engagements.
  • Develop technical content, such as security plans, procedures, policies, and white papers that can be used by our clients to assist them in elevating/building out their security and compliance programs.
  • Lead delivery engagements, including potential on-site projects, working with clients to build out compliance roadmaps, architecture guidance, gap assessments, etc.
  • Translate and implement industry-standard GRC requirements into Azure and Microsoft 365 controls.
  • Collaborate with Professional Services team members and sales teams to convey partner and customer feedback.
  • Serve as the practice subject matter expert (SME) for escalations, sales/marketing support, driving practice profitability and revenue.
  • Provide Delivery Team Support, including identifying process improvements, training Delivery personnel on methodologies/tools and quality topics, and mentoring Delivery personnel.
  • Development of industry-wide service line thought leadership through:
  • Authoring: methodologies, templates, white papers, work instructions, guidelines, forms, tools
  • Developing and delivering industry-specific training, including speaking/presenting at conferences, creating webinars
  • Support management of client satisfaction at all phases of the client relationship.
  • Ensure continuous professional development by maintaining industry-specific certifications.
  • Maintain a strong depth of knowledge in the practice area.
  • Collaborate with project managers, quality management, sales and other delivery team members to drive customer satisfaction and meet project deliverables.
  • Establish account relationships and identify upsell and cross-sell opportunities and escalate to sales


What You'll Bring
  • 7+ years of experience in an IT security audit, assessment, compliance, risk management, or data privacy role.
  • Knowledge and awareness of the latest information risk, security, and compliance innovations, trends, challenges, and solutions.
  • Knowledge of strategy, privacy, risk standards/frameworks, and professional practices (NIST, ISO, CIS Top 20, ISSA, CSA CMM, Privacy by Design, FAIR, etc.).
  • Knowledge of the typical enterprise risk and security operational practices.
  • Knowledge of information security-related solutions, tools, and utilities.
  • Experience in strategy development, setting direction for team members, influencing both internally and externally.
  • Experience building common compliance frameworks as well as mapping between different compliance requirements.
  • Experience securing cloud-based infrastructure, including secure operating systems, firewalls, and database lockdowns.
  • Demonstrated breadth of security expertise in various subdomains such as encryption, identity, incident response, etc.
  • Knowledge of Identity Access Management design and implementation patterns.
  • Experience with risk assessment methodologies and risk reporting for executive leadership.
  • Proven background in clearly writing complex technical documents that can be presented across a varied enterprise corporate audience.
  • 7+ years of experience working with one or more of the following:
  • Payment Card Industry (PCI) Council's Payment Card Industry Data Security Standard (PCI DSS)
  • ISO/IEC 27001:2022 and ISO/IEC 2702:2022
  • ISO 9001:2015
  • System and Organization Controls (SOC) 2
  • National Institute of Standards and Technology (NIST) frameworks (800 series)
  • HITRUST framework
  • Health Insurance Portability and Accountability Act (HIPAA)
  • Health Information Technology for Economic and Clinical Health Act (HITECH)
  • Bachelor's Degree in Computer Science, Information Systems Management, Information Security, Business or equivalent experience required.
  • CISSP
  • CISM or CISA
  • In addition, depending on the framework(s) you will be supporting you must have one or more of the following:
  • ISO: ISO/IEC 27001 Lead Auditor/Implementer
  • Certified CSF Practitioner (CCSFP)
  • PCI: Qualified Security Assessor (QSA)


Bonus
  • Azure certification(s).
  •  CRISC or related certification
  • CCSK certification
  • Big Four Advisory/Consulting Experience (Deloitte, EY, PwC, Accenture, etc.)


We value our employees and are committed to providing a comprehensive and competitive benefits package designed to support your well-being and financial security. Here's what you can look forward to:


Financial Security & Growth:

 Competitive Salary: We offer competitive salaries commensurate with experience and skills.

 Generous 401(k) Plan: Secure your financial future with our generous 401(k) plan, featuring a 100% company match on your contributions up to 4% of your salary! This is a fantastic opportunity to build your retirement savings with our support.

 Performance-Based Compensation: Your hard work and dedication will be recognized and rewarded through our performance-based compensation program, which includes bonus potential in addition to your base salary.


Health & Well-being:

 100% Employer-Paid Health, Vision, and Dental Insurance for employees: Say goodbye to expensive premiums! We cover 100% of the cost of your health, vision, and dental insurance premiums, saving you potentially thousands of dollars each year. Focus on your health, not your healthcare costs.

 Company-Paid Life, AD&D, Short and Long-Term Disability Insurance: We provide company-paid life, accidental death & dismemberment, and short- and long-term disability insurance to protect you and your family.


Time Off & Work-Life Balance:

 Generous Paid Time Off (PTO): Enjoy a healthy work-life balance with three weeks of paid time off, allowing you to relax, recharge, and pursue your personal interests. This flexible PTO can be used for vacation, personal time, or sick leave.

 11 Paid Holidays: We observe 11 paid holidays throughout the year, giving you additional time to spend with family and friends.

 Community Service Leave: We believe in giving back to the community and offer paid time off for you to volunteer with organizations that are meaningful to you.


Additional Perks & Recognition:

 Employee Recognition and Reward Program: We celebrate and reward outstanding performance and contributions through our employee recognition program. We value your dedication and are committed to showing our appreciation.


This is a full-time position in the United States with the ability to work from home, or from one of our many US offices if local.

 

Atmosera is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. All employment is decided on the basis of qualifications, merit, and business need.

Atmosera Glassdoor Company Review
3.4 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Atmosera DE&I Review
3.5 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
CEO of Atmosera
Atmosera CEO photo
Jon Thomsen
Approve of CEO

Average salary estimate

$125000 / YEARLY (est.)
min
max
$100000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Principal Consultant - GRC/Security, Atmosera

If you're a seasoned expert looking to make a significant impact, join Atmosera as a Principal Consultant - GRC/Security in beautiful Portland, OR! At Atmosera, we empower businesses to redefine what's possible with a unique blend of modern technology and human expertise. Our expertise spans Applications, Data & AI, DevOps, Security, and the Microsoft Azure platform, allowing us to offer integrated solutions tailored to our clients' needs. As a Principal Consultant, you'll serve as a Compliance Advisory subject matter expert, helping organizations assess their security and compliance against key regulatory requirements and industry standards. Your role will involve evaluating complex systems, mentoring team members, and engaging with the community through thought leadership. You'll scope and lead client engagements, developing essential documents such as security plans and compliance roadmaps while translating industry-standard requirements into actionable controls within Azure and Microsoft 365. The ideal candidate will have over 7 years of experience in security audit, compliance, or risk management roles, coupled with a deep understanding of frameworks like NIST and ISO. If you are passionate about driving customer success, mentoring budding talent, and being at the forefront of security innovation, this could be the perfect opportunity for you!

Frequently Asked Questions (FAQs) for Principal Consultant - GRC/Security Role at Atmosera
What are the primary responsibilities of a Principal Consultant - GRC/Security at Atmosera?

The Principal Consultant - GRC/Security at Atmosera is responsible for evaluating and enhancing the security of complex systems within client organizations. This role includes leading client engagements, scoping projects, and ensuring compliance with regulatory standards. You'll also mentor team members, develop technical content, and engage with the community through publications and speaking engagements.

Join Rise to see the full answer
What qualifications do I need to become a Principal Consultant - GRC/Security at Atmosera?

To qualify for the Principal Consultant - GRC/Security role at Atmosera, candidates should have over 7 years of experience in IT security, compliance, or risk management roles. A Bachelor's Degree in Computer Science, Information Systems, or a related field is required. Certifications such as CISSP, CISM, or CISA are essential, along with knowledge of frameworks like NIST and ISO.

Join Rise to see the full answer
How does the Principal Consultant - GRC/Security role contribute to client satisfaction at Atmosera?

The Principal Consultant - GRC/Security directly influences client satisfaction by delivering tailored security and compliance solutions that meet their specific needs. By developing comprehensive compliance roadmaps and providing regular mentorship and support, this role ensures a continued strong relationship between Atmosera and its clients.

Join Rise to see the full answer
What opportunities for professional growth does Atmosera provide for Principal Consultants - GRC/Security?

At Atmosera, Principal Consultants - GRC/Security benefit from a culture that prioritizes continuous learning and professional development. This includes opportunities for certification in current frameworks, mentorship roles, and possibilities to engage in community thought leadership through publications and conference presentations.

Join Rise to see the full answer
What is the office culture like for Principal Consultants - GRC/Security at Atmosera?

Atmosera fosters a positive, inclusive office culture where Principal Consultants - GRC/Security are encouraged to collaborate, innovate, and grow. With flexible work options and a commitment to community involvement, employees are valued for their contributions and have opportunities to actively impact both the company and the industry.

Join Rise to see the full answer
Common Interview Questions for Principal Consultant - GRC/Security
Can you explain your experience with regulatory compliance standards relevant to the Principal Consultant role?

Discuss your familiarity with standards such as NIST, ISO, HIPAA, or PCI DSS. Highlight specific projects where you ensured compliance and the methods used to assess risk and implement necessary controls.

Join Rise to see the full answer
How do you approach mentoring team members in a consulting environment?

Share your strategy for mentoring, emphasizing the importance of knowledge transfer, providing constructive feedback, and fostering an environment where team members feel comfortable asking questions and seeking guidance.

Join Rise to see the full answer
What is your process for conducting a compliance gap assessment?

Explain the steps you take for a gap assessment, including identifying current practices, comparing them to regulatory requirements, and formulating recommendations for compliance improvements.

Join Rise to see the full answer
Can you provide an example of a time you handled a difficult client situation?

Use a specific example to demonstrate your problem-solving skills and ability to maintain professionalism under pressure. Focus on how you resolved the client's concerns while ensuring their satisfaction with your service.

Join Rise to see the full answer
What strategies do you use to stay updated on industry trends related to GRC and security?

Highlight your methods for continuous learning, such as attending webinars, participating in forums, and reading industry publications. Mentioning relevant certifications you're pursuing can also demonstrate your commitment to ongoing education.

Join Rise to see the full answer
How do you ensure that recommendations you provide are implementable for clients?

Discuss your approach to aligning recommendations with clients' specific contexts and capabilities, factoring in their resources and operational constraints to develop realistic implementation plans.

Join Rise to see the full answer
How do you measure the success of a GRC initiative?

Talk about metrics you employ to assess effectiveness, such as improvement in audit ratings, reduction in security incidents, or increased compliance with identified standards or frameworks.

Join Rise to see the full answer
How would you describe your collaboration style with sales teams?

Illustrate your collaborative approach, emphasizing your belief in open communication, shared goals, and mutual respect, which helps in effectively addressing client needs and creating winning proposals.

Join Rise to see the full answer
How do you balance multiple client projects at once while ensuring high-quality delivery?

Share your techniques for prioritization, time management, and resource allocation. Mention the importance of setting clear expectations upfront and maintaining close communication with clients to keep them informed of progress.

Join Rise to see the full answer
What technical writing experience do you have, especially related to security documentation?

Detail your background in creating security plans, procedures, and white papers. Discuss your ability to communicate complex information clearly, catering to various audiences across organizations.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User

Join Capco Poland as a Business Analyst, where you'll play a pivotal role in driving data-related initiatives within the financial services sector.

Photo of the Rise User

Become an integral part of Infosys Consulting as a Senior ERP EAM Functional Consultant, utilizing your SAP expertise to drive impactful solutions for clients.

Photo of the Rise User

Drive impactful project outcomes as a Senior Consultant in KPMG's vibrant team, specializing in project delivery across diverse sectors.

Photo of the Rise User
Posted 11 days ago

Join Nationwide as a Digital Learning Experience Consultant and help revolutionize the learner experience using modern technologies and creative strategies.

Photo of the Rise User

Palo Alto Networks is searching for a Senior Principal Consultant in Cloud Security to lead proactive services and enhance client cybersecurity.

Photo of the Rise User
Posted 7 days ago

Become a key player in Visa's Client Success transformation as a Consultant, driving operational excellence and product adoption for key clients.

Photo of the Rise User
Posted 8 days ago

NICE seeks an experienced Lead Business Consultant to elevate Workforce Management solutions for clients through strategic engagement and expert guidance.

Photo of the Rise User

Become a vital part of AECOM's award-winning team as a Geo-Environmental Consultant, shaping solutions for some of the UK's most pressing environmental challenges.

Empower our customers with a seamless infrastructure experience

14 jobs
MATCH
VIEW MATCH
FUNDING
DEPARTMENTS
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 9, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Lewis Center just viewed Third Party Risk Analyst at Experian
Photo of the Rise User
Someone from OH, Columbus just viewed Lead Preschool Teacher at Guidepost Montessori
A
Someone from OH, Cincinnati just viewed Global Supply Manager - Taiwan at Also
Photo of the Rise User
Someone from OH, Cincinnati just viewed Global Supply Manager (Raptor Machining) at SpaceX
Photo of the Rise User
Someone from OH, Reynoldsburg just viewed Summer 2025 Financial Services Internship at Nationwide
Photo of the Rise User
Someone from OH, Brunswick just viewed Staff Software Engineer C++ / Computer Vision at ABBYY
Photo of the Rise User
Someone from OH, Columbus just viewed Label Machine Operator I - 2nd Shift at Avery Dennison
Photo of the Rise User
Someone from OH, North Ridgeville just viewed Java, Javascript, Python, NodeJS Software Engineer at Walmart
R
Someone from OH, Dublin just viewed Supply Chain Lead (Clinical Supply) at Resultance
Photo of the Rise User
Someone from OH, Columbus just viewed Scrum Master at Sysco Costa Rica
Photo of the Rise User
193 people applied to Mindset/Life Coach at Upwork
X
Someone from OH, Cincinnati just viewed Senior Java Engineer (Remote) at Xenon7
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior, Software Engineer- Java at Walmart
Photo of the Rise User
Someone from OH, Pickerington just viewed Senior Business Analyst (Salesforce) at Protolabs
H
Someone from OH, Akron just viewed Brand Marketing Manager at Huntington
R
Someone from OH, Hamilton just viewed Forklift Operator Warehouse at Ryder
Photo of the Rise User
Someone from OH, Cincinnati just viewed Ad Ops Specialist, Display at System1
Photo of the Rise User
6 people applied to Scrum Master at IE