Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Consultant, GRC Advisory image - Rise Careers
Job details

Consultant, GRC Advisory

About Coalfire


Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Denver, Colorado with offices across the U.S. and U.K., and we support clients around the world.


But that’s not who we are – that’s just what we do.

 

We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.


Position Summary


You will perform a variety of ISO/SOC engagements (such as workshops, policy and procedure development) for ISO/SOC compliance. This role will specialize in assessing the readiness for ISO/SOC compliance and providing those advisory services necessary for a successful audit.



What You'll Do
  • You’ll work collaboratively with a team of ISO/SOC advisory assessors as a ISO/SOC advisor and assist with the planning and delivery of those services.
  • Be the team lead on engagements against ISO/SOC compliance to provide information security technical and non-technical expertise.
  • Work with other teams within Coalfire, and collaborate with the ISO/SOC assessment team, to drive customer success.
  • Lead on-site engagements with clients. This includes onsite visits, understanding customer security and compliance requirements and environments, and proposing and delivering packaged offerings or custom solution engagements.
  • Develop technical content, such as procedures and policies, risk management tools, etc., that will be used by our clients to assist them in elevating/build out their security programs for ISO/SOC compliance.
  • Delivery projects to build out compliance roadmaps, architecture guidance, gap remediation, etc.


What You'll Bring
  • 3+ years experience performing and or participating in SOC 2 examinations and ISO/IEC 27001:2013 certifications
  • 3+ years of experience in an IT security audit, assessment, compliance, risk management, or data privacy role
  • 3+ years of experience working with any of the following frameworks: Payment Card Industry (PCI) Council's Payment Card Industry Data Security Standard (PCI DSS) , ISO/IEC 27701:2019 (and/or its mapped references ISO/IEC 29100:2011, ISO/IEC 27018:2019), ISO/IEC ISO/IEC 9001:2015, Health Insurance Portability and Accountability Act (HIPAA), HITRUST, System and Organization Controls (SOC) 2, or National Institute of Standards and Technology (NIST) frameworks
  • ISO/IEC 27001 Lead Auditor Certificate
  • Bachelor's Degree in Computer Science, Information Systems Management, Information Security, Business or equivalent experience required
  • Willing to travel up to 50%


Bonus Points
  • Certified Information Systems Auditor (CISA), Certificate of Cloud Security Knowledge (CCSK)
  • ISO 9001:2015 Lead Auditor
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Privacy Professional (CIPP/US), or Certified Information Security Manager (CISM)


$64,000 - $112,000 a year
The salary range listed is a reasonable estimate of the compensation range for this role based on national salary averages. The actual salary offer to the successful candidate will be based on job-related education, geographic location, training, licensure and certifications and other factors. You may also be eligible to participate in annual incentive, commission, and/or recognition programs.

Why You’ll Want to Join Us


At Coalfire, you’ll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office.


Regardless of location, you’ll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You’ll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And you’ll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.


At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, our Human Resources team at HumanResourcesMB@coalfire.com.

Coalfire Glassdoor Company Review
3.8 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Coalfire DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Coalfire
Coalfire CEO photo
Tom McAndrew
Approve of CEO

Average salary estimate

$88000 / YEARLY (est.)
min
max
$64000K
$112000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Consultant, GRC Advisory, Coalfire

At Coalfire, we're not just another IT company; we're a passionate team dedicated to making the world a safer place by tackling our clients' toughest cybersecurity challenges. As a Consultant in GRC Advisory, you’ll play a vital role in our mission. Located in the United States, you'll find yourself diving deep into the world of ISO/SOC compliance—a field that combines both technical expertise and strategic foresight. You’ll be leading various engagements, from conducting workshops to developing essential policies and procedures aimed at ensuring compliance. Collaborating closely with a dynamic team of ISO/SOC advisory assessors, your insights will be pivotal in enhancing the security and compliance landscape for our clients. Not only will you assess clients’ readiness for ISO/SOC compliance, but you'll also demonstrate your expertise through on-site visits, understanding their unique security requirements, and delivering tailored solutions that elevate their security programs. Your experience matters here—3+ years in roles like IT security audits or compliance, along with certifications, will help you thrive. And, of course, your journey with us will come with competitive benefits and a flexible work model that prioritizes your personal and professional growth. Join us at Coalfire, where you can truly make a difference!

Frequently Asked Questions (FAQs) for Consultant, GRC Advisory Role at Coalfire
What are the main responsibilities of a Consultant, GRC Advisory at Coalfire?

As a Consultant in GRC Advisory at Coalfire, your core responsibilities will include leading ISO/SOC compliance engagements, performing assessments, and developing crucial technical content such as policies and procedures. You'll collaborate with teams to drive customer success and devise compliance roadmaps, ensuring your clients navigate the landscape of cybersecurity challenges effectively.

Join Rise to see the full answer
What qualifications are required for the Consultant, GRC Advisory position at Coalfire?

For the Consultant, GRC Advisory role at Coalfire, you’ll need a Bachelor's Degree in a related field and at least 3 years of experience in roles such as IT security audits or compliance. Key certifications like ISO/IEC 27001 Lead Auditor and knowledge of frameworks like SOC 2 and HIPAA will also help you stand out in the selection process.

Join Rise to see the full answer
How does Coalfire support professional development for its Consultant, GRC Advisory team?

At Coalfire, we are committed to your growth. As a Consultant, GRC Advisory, you benefit from professional development opportunities including certification reimbursements, access to employee resource groups, and participation in various events. We prioritize a supportive environment where you can enhance your knowledge and skills continuously.

Join Rise to see the full answer
What is the salary range for a Consultant, GRC Advisory at Coalfire?

The salary range for a Consultant, GRC Advisory at Coalfire is between $64,000 and $112,000 per year. Actual compensation will be aligned with your experience, education, and other relevant factors, ensuring a fair and equitable offer for your valuable contributions.

Join Rise to see the full answer
What is the company culture like at Coalfire for the Consultant, GRC Advisory position?

Coalfire fosters an inclusive and collaborative culture where every team member is valued. As a Consultant in GRC Advisory, you’ll experience a flexible work model, opportunities for connection, and a commitment to wellbeing that empowers you to perform at your best while contributing positively to our community.

Join Rise to see the full answer
Common Interview Questions for Consultant, GRC Advisory
Can you explain your experience with SOC 2 examinations and ISO/IEC 27001 certifications?

In answering this question, focus on specific projects you've led or participated in, highlighting your role, the challenges faced, and the outcomes. Detail any methodologies you've employed and how your contributions helped enhance compliance for clients, illustrating your experience with these frameworks.

Join Rise to see the full answer
How do you stay updated on the latest developments in cybersecurity compliance?

Highlight your commitment to continuous learning, such as attending workshops, webinars, and industry conferences related to cybersecurity compliance. Mention specific publications or organizations you follow to stay informed, showing your proactive approach to professional development.

Join Rise to see the full answer
Describe a time you successfully managed a compliance roadmap for a client.

Use the STAR method (Situation, Task, Action, Result) to structure your response. Describe the client's initial situation, your tasks in creating a compliance roadmap, the specific actions you took to address challenges, and finally, the successful results of your initiatives in enhancing their compliance status.

Join Rise to see the full answer
What strategies do you employ to work effectively with clients during on-site engagements?

Emphasize your interpersonal skills and strategies for building rapport with clients. Discuss how you gather information about their needs, provide tailored recommendations, and ensure ongoing communication throughout the project to maintain alignment and client satisfaction.

Join Rise to see the full answer
How would you handle a situation where a client is resistant to implementing necessary compliance changes?

Reflect on your communication skills and conflict resolution strategies. Discuss how you would engage the client through understanding their concerns, demonstrating the benefits of compliance, and providing clear, data-backed arguments to help them see the necessity for change.

Join Rise to see the full answer
What tools do you use for risk management in compliance projects?

List specific tools and software you're familiar with for risk management, such as GRC platforms or frameworks. Explain how you've used these tools in your previous roles to effectively assess, monitor, and improve compliance efforts, illustrating their impact on overall project success.

Join Rise to see the full answer
Can you discuss your experience with frameworks like PCI DSS or NIST?

Share specific projects where you’ve applied PCI DSS or NIST frameworks, detailing your role and contributions. Explain how you assessed security measures and ensured compliance, showcasing your proficiency in implementing these important standards in real-world scenarios.

Join Rise to see the full answer
What role does communication play in your work as a Consultant?

Discuss the importance of clear communication in consulting, particularly in understanding client needs, delivering complex information in an approachable manner, and maintaining ongoing dialogue throughout projects. Your ability to facilitate discussions and share insights is crucial for fostering strong relationships.

Join Rise to see the full answer
Why do you want to work for Coalfire as a Consultant in GRC Advisory?

Articulate your alignment with Coalfire's mission and values. Share what excites you about working in cybersecurity and how Coalfire's commitment to innovation and making a difference resonates with your professional goals. Your passion for the industry and the company will shine through in your answer.

Join Rise to see the full answer
How do you prioritize tasks and manage your time during multiple engagements?

Discuss your time management strategies, such as setting clear goals and deadlines, utilizing project management tools, and regularly reviewing progress against objectives. Emphasize your ability to effectively prioritize tasks based on urgency and importance, ensuring that you meet client expectations.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Esri Remote Redlands, California, United States
Posted yesterday
Posted 6 hours ago
Photo of the Rise User
Abrigo Remote No location specified
Posted 12 days ago
Photo of the Rise User
Humana Remote New York, United States
Posted 2 days ago
Photo of the Rise User
Posted 12 days ago
Mindpath Health Remote US, Los Angeles County, CA; California, Glendale, CA
Posted 8 days ago
Photo of the Rise User
Posted 4 days ago

Coalfire is a cybersecurity and compliance services company that secures the future of businesses by solving complex cybersecurity challenges and is trusted by leading organizations across various sectors.

116 jobs
MATCH
VIEW MATCH
BADGES
Badge ChangemakerBadge Diversity ChampionBadge Flexible CultureBadge Future Maker
FUNDING
DEPARTMENTS
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 1, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Cleveland just viewed Software Engineer I (DevOps) at Mastercard
C
Someone from OH, Warren just viewed Front End Developer (for AI Agent) at CyberCare
I
Someone from OH, Warren just viewed Senior Angular Lead at Integrators services a.s.
Photo of the Rise User
Someone from OH, Warren just viewed SSr. Front End Engineer (Angular.js) at NTD Software
Photo of the Rise User
Someone from OH, Warren just viewed Front-End Developer at Apex Logic
S
Someone from OH, Warren just viewed Angular Developer at Sparkland
Photo of the Rise User
178 people applied to Mindset/Life Coach at Upwork
Photo of the Rise User
Someone from OH, New Albany just viewed Diversity, Equity & Inclusion Manager at Axios
Photo of the Rise User
Someone from OH, Cincinnati just viewed Customer Service Associate at 2K
Photo of the Rise User
Someone from OH, Marion just viewed Casting: '2' at Backstage
Photo of the Rise User
Someone from OH, Westerville just viewed Junior Videographer at HyperionDev
Photo of the Rise User
Someone from OH, Columbus just viewed Part-time driver | Columbus, OH at Uber
Photo of the Rise User
Someone from OH, Columbus just viewed Operations Manager, Overnight at hims & hers
Photo of the Rise User
Someone from OH, North Ridgeville just viewed Court Security Officer, Juneau, AK at Walden Security
Photo of the Rise User
Someone from OH, North Ridgeville just viewed Senior Director GMA Operations Excellence-Oncology at Johnson & Johnson
Photo of the Rise User
Someone from OH, North Ridgeville just viewed Application Developer at Barbaricum
Photo of the Rise User
Someone from OH, North Ridgeville just viewed Outside Sales Account Executive at Pursuit
Photo of the Rise User
Someone from OH, North Ridgeville just viewed Analyst, Demand Planning at Petco
Photo of the Rise User
Someone from OH, North Ridgeville just viewed Associate Director Statistical Programming at Sobi
Photo of the Rise User
Someone from OH, North Ridgeville just viewed PMG is hiring: SEM Lead in Dallas at PMG
Photo of the Rise User
Someone from OH, North Ridgeville just viewed Enterprise Architect (Senior Level) at Platinum Technologies
Photo of the Rise User
Someone from OH, North Ridgeville just viewed Portfolio Execution Lead at Cushman & Wakefield