Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Principal, GRC Advisory image - Rise Careers
Job details

Principal, GRC Advisory

About Coalfire


Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Denver, Colorado with offices across the U.S. and U.K., and we support clients around the world.


But that’s not who we are – that’s just what we do.

 

We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.


Position Summary


As a Principal Consultant on our ISO/SOC Advisory team, you'll be considered a Compliance Advisory subject matter expert (SME) in a particular technical area e.g. evaluating/assessing the security and compliance of client firms/services against regulatory and industry requirements and standards, and against security best practice frameworks, etc.


The Principal Consultant (SME) is expected to leverage their technical and business experience across three (3) domains, including:

1. Evaluate and enhance the security of complex systems that may impact both risk and compliance for organizations, large and small.

2. Mentor and develop team members to help grow the team and its capabilities

3. Engage outwardly into the community through blog posts, technical white papers, forum participation and conference speaking engagements. Engage inwardly to support business and practice growth by developing Sales/Marketing collateral, delivery methodologies and SOPs, train/mentor colleagues as necessary and serve as the SME for all topics related to your technical or compliance area of expertise



What You'll Do
  • Work with other teams within Coalfire to drive customer success.
  • Scope and lead on-site engagements with clients. This includes leading pre-sales calls, onsite visits, understanding customer security and compliance requirements and environments, and proposing and delivering packaged offerings or custom solution engagements.
  • Develop technical content, such as security plans, procedures, policies, and white papers that can be used by our clients to assist them in elevating/building out their security and compliance programs.
  • Lead delivery engagements including on-site projects working with clients to build out compliance roadmaps, architecture guidance, gap assessments, etc.
  • Collaborate with Coalfire engineering, support and business teams to convey partner and customer feedback.
  • Serve as the practice subject matter expert (SME) for escalations, sales/marketing support, driving practice profitability and revenue.
  • Provide Delivery Team Support, including: identifying process improvements, training Delivery personnel on methodologies/tools and quality topics, and mentoring Delivery personnel.
  • Development of industry-wide service line thought leadership through:
  • Authoring: methodologies, templates, white papers, work instructions, guidelines, forms, tools
  • Developing and delivering industry specific training, including speaking/presenting at
  • conferences, creating webinars
  • Support management of client satisfaction at all phases of the client relationship.
  • Ensure continuous professional development by maintaining industry specific certifications.
  • Maintain strong depth of knowledge in the practice area.
  • Collaborate with project managers, quality management, sales and other delivery team members to drive customer satisfaction and meet project deliverables.
  • Establish account relationships and identifies upsell and cross sell opportunities and escalates to sales


What You'll Bring
  • 7+ years of experience in an IT security audit, assessment, compliance, risk management, or data privacy role.
  • Knowledge and awareness of the latest information risk, security and compliance innovations, trends, challenges and solutions.
  • Knowledge of strategy, privacy and risk standards/frameworks and professional practices (NIST, ISO, CIS Top 20, ISSA, CSA CMM, Privacy by Design and FAIR, etc.).
  • Knowledge of the typical enterprise risk and security operational practices.
  • Knowledge of information security related solutions, tools and utilities.
  • Experience in strategy development, setting direction for team members, influencing both internally and externally.
  • Experience building common compliance frameworks as well as mapping between different compliance requirements.
  • Demonstrated breadth of security expertise in various sub domains such as encryption, identity, incident response, etc.
  • Hands-on technical expertise is nice to have due to the technical components of the frameworks that are worked with.
  • Experience with risk assessment methodologies and risk reporting for executive leadership.
  • Proven background in clearly writing complex technical documents that can be presented across a varied enterprise corporate audience.
  • 7+ years of experience working with one or more of the following:
  • Payment Card Industry (PCI) Council's Payment Card Industry Data Security Standard (PCI DSS)
  • ISO/IEC 27001:2022
  • ISO 9001:2015
  • System and Organization Controls (SOC) 2
  • National Institute of Standards and Technology (NIST) frameworks (800 series)
  • HITRUST framework
  • Health Insurance Portability and Accountability Act (HIPAA)
  • Health Information Technology for Economic and Clinical Health Act (HITECH)
  • Bachelor's Degree in Computer Science, Information Systems Management, Information Security, Business or equivalent experience required.
  • CISSP
  • CISM or CISA
  • In addition, dependent on the framework(s) you will be supporting you must have one or more of the following:
  • ISO: ISO/IEC 27001 Lead Auditor/Implementer
  • Certified CSF Practitioner (CCSFP)
  • PCI: Qualified Security Assessor (QSA)


Bonus Points
  • AWS, Azure, Google Cloud Platform certification(s).
  • OpenFair, CRISC or related certification
  • CCSK certification
  • Big Four Advisory/Consulting Experience


$104,000 - $179,600 a year
The salary range listed is a reasonable estimate of the compensation range for this role based on national salary averages. The actual salary offer to the successful candidate will be based on job-related education, geographic location, training, licensure and certifications and other factors. You may also be eligible to participate in annual incentive, commission, and/or recognition programs.

#LI-AN1

Why You’ll Want to Join Us


At Coalfire, you’ll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office.


Regardless of location, you’ll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You’ll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And you’ll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.


At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, our Human Resources team at HumanResourcesMB@coalfire.com.

Coalfire Glassdoor Company Review
3.8 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Coalfire DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Coalfire
Coalfire CEO photo
Tom McAndrew
Approve of CEO

Average salary estimate

$141800 / YEARLY (est.)
min
max
$104000K
$179600K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Principal, GRC Advisory, Coalfire

Join the incredible team at Coalfire as a Principal Consultant on our ISO/SOC Advisory team! We're on a mission to tackle the toughest cybersecurity challenges for our clients and ensure a safer world. In this dynamic role, you’ll be recognized as a Compliance Advisory subject matter expert (SME), where your experience will shine as you evaluate the security of complex systems for a diverse range of organizations. You’ll not only guide clients through the intricate maze of security and compliance standards but also mentor and develop our talented team members. Here, you will engage with the community by authoring insightful blog posts, technical white papers, and by presenting at conferences. As a Principal Consultant, you'll lead on-site engagements, understanding client requirements, and crafting tailored solutions that elevate their security programs. The best part? You'll have the opportunity to collaborate with cross-functional teams at Coalfire, ensuring that your insights drive customer success and practice growth. Our culture thrives on learning and growth, so you can be sure that both you and your career will flourish while working with us. With a commitment to professional development and a flexible work environment, Coalfire champions work-life balance while pushing the boundaries of cybersecurity expertise. If you're a driven individual passionate about making a difference in the cybersecurity landscape, come grow with us at Coalfire!

Frequently Asked Questions (FAQs) for Principal, GRC Advisory Role at Coalfire
What are the responsibilities of a Principal Consultant at Coalfire?

As a Principal Consultant at Coalfire, you will take charge of evaluating and enhancing the security of complex systems across various organizations. Your role includes leading client engagements, mentoring team members, and developing valuable technical content that assists clients in building their security and compliance programs. Additionally, you will serve as a subject matter expert, engaging in community outreach by writing white papers and participating in industry events.

Join Rise to see the full answer
What qualifications do I need to become a Principal Consultant at Coalfire?

To become a Principal Consultant at Coalfire, you need at least 7 years of experience in IT security, compliance, or risk management, along with a bachelor's degree in Computer Science, Information Security, or a related field. Relevant certifications such as CISSP, CISM, or CISA are essential, and having specific framework expertise, like ISO or PCI, will help you stand out in this role.

Join Rise to see the full answer
What skills are essential for a Principal Consultant in GRC Advisory at Coalfire?

A successful Principal Consultant at Coalfire should possess strong knowledge of compliance frameworks like NIST and ISO. Key skills include excellent communication for drafting complex technical documents, the ability to mentor and develop team members, and a proactive approach to engaging with clients. Your technical expertise in risk assessment and information security solutions will also be crucial in delivering exceptional results.

Join Rise to see the full answer
How does Coalfire support the professional development of Principal Consultants?

Coalfire prioritizes professional development through various initiatives such as certification reimbursements, tailored training programs, and opportunities to speak at industry conferences. You'll be encouraged to stay on top of the latest cybersecurity trends and advancements, ensuring you continually grow your skills and expertise in the field.

Join Rise to see the full answer
What does the work-life balance look like for a Principal Consultant at Coalfire?

At Coalfire, we recognize the importance of work-life balance, offering flexible work arrangements that empower you to choose when and where you work best. Whether you prefer working from home or in an office environment, you'll find that we prioritize connection and well-being, creating a supportive atmosphere for all team members.

Join Rise to see the full answer
Common Interview Questions for Principal, GRC Advisory
Can you explain your experience with compliance frameworks relevant to the Principal Consultant role?

In your response, highlight specific compliance frameworks you have worked with, such as ISO 27001, PCI DSS, or NIST. Describe projects where you helped organizations comply with these standards, including any assessments or audits you conducted, and emphasize your approach to staying current with compliance trends.

Join Rise to see the full answer
How do you approach mentorship and team development in your role?

Discuss your belief in fostering a collaborative learning environment, and provide examples of how you've mentored colleagues. Highlight any initiatives you led to train team members or develop their skills, and explain the positive impact this has had on team performance.

Join Rise to see the full answer
What strategies do you use to ensure client satisfaction during engagements?

Outline your process for understanding client needs, setting clear expectations, and maintaining open lines of communication. Describe specific instances where your proactive approach led to increased client satisfaction and retention.

Join Rise to see the full answer
What steps do you take to stay updated on the latest cybersecurity trends and threats?

Share your commitment to continuous learning through resources such as industry journals, conferences, webinars, and professional networks. Highlight specific examples where your knowledge of emerging threats helped you provide better consulting services.

Join Rise to see the full answer
Can you provide an example of a challenging compliance issue you've faced and how you resolved it?

Pick a real-world challenge that required you to analyze complex compliance requirements. Describe the steps you took to navigate the issue, how you collaborated with others, and the successful outcomes achieved through your efforts.

Join Rise to see the full answer
How do you prioritize tasks and manage multiple client engagements?

Explain your organizational strategies such as using project management tools, setting SMART goals, and assessing client needs to prioritize work effectively. Share an example of how you managed competing deadlines successfully.

Join Rise to see the full answer
What is your process for developing technical content for clients?

Discuss the importance of clear communication and how you tailor content based on client needs. Provide examples of types of documents you've created, like policies or procedure manuals, and how they added value to your clients' compliance programs.

Join Rise to see the full answer
How do you handle disagreements or conflicts within your project teams?

Mention your approach of focusing on open communication and understanding different perspectives. Share an example of a time you positively resolved a conflict and how it contributed to team unity.

Join Rise to see the full answer
What role does thought leadership play in the Principal Consultant position at Coalfire?

Discuss the importance of sharing insights through writing articles, giving talks, or engaging in forums and how it reflects on your expertise and the company's reputation. Highlight any contributions you've already made in this area.

Join Rise to see the full answer
How would you develop a compliance roadmap for a new client?

Explain your approach, which should include conducting a thorough assessment of the client's current security posture, identifying compliance gaps, and then creating a step-by-step roadmap that aligns with industry standards and the client's business objectives.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 7 days ago
Photo of the Rise User
Penumbra Remote Your Remote Malaysia Home Office
Posted 7 days ago
Photo of the Rise User
Posted 7 days ago
Photo of the Rise User
Procurify Remote No location specified
Posted 13 days ago
Posted 7 days ago

Coalfire is a cybersecurity and compliance services company that secures the future of businesses by solving complex cybersecurity challenges and is trusted by leading organizations across various sectors.

111 jobs
MATCH
VIEW MATCH
BADGES
Badge ChangemakerBadge Diversity ChampionBadge Flexible CultureBadge Future Maker
FUNDING
DEPARTMENTS
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
March 19, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
157 people applied to Mindset/Life Coach at Upwork
Photo of the Rise User
Someone from OH, Cincinnati just viewed Product Owner, AI at Modernizing Medicine, Inc.
Photo of the Rise User
Someone from OH, Strongsville just viewed Used Car Buyer - Concord Toyota at Sonic Automotive
Photo of the Rise User
Someone from OH, Canton just viewed UI Designer - Website & Brand at Atlan
Photo of the Rise User
Someone from OH, Dayton just viewed Data Engineer - User Platform at Spotify
Photo of the Rise User
Someone from OH, Dayton just viewed Data Engineer - #1696 at MeridianLink
Photo of the Rise User
Someone from OH, Columbus just viewed Enterprise Sales Project Associate at Array
Photo of the Rise User
Someone from OH, Akron just viewed Medical Receptionist at LifeStance Health
Photo of the Rise User
Someone from OH, Thornville just viewed Finance Rotation Analyst at Huntington National Bank
Photo of the Rise User
Someone from OH, Columbus just viewed Cashier - Sawmill Road Market District at Giant Eagle
Photo of the Rise User
Someone from OH, Cincinnati just viewed Data Scientist at Apex Systems
Photo of the Rise User
Someone from OH, Mansfield just viewed POS Install Tech at TEKsystems
Photo of the Rise User
Someone from OH, Dublin just viewed Sr. Manager UX Design Research at Visa
Photo of the Rise User
Someone from OH, Columbus just viewed Case Manager at Release Recovery
Photo of the Rise User
Someone from OH, Cincinnati just viewed Recruiting Coordinator (Contractor) at Anduril Industries
Photo of the Rise User
Someone from OH, Dublin just viewed Field Support Technicians - (Phoenix) at Nordstrom
Photo of the Rise User
Someone from OH, Stow just viewed IT Asset administrator at Ergomed
Photo of the Rise User
Someone from OH, Loveland just viewed Senior Buyer (wholesale) (m/f/d) at ABOUT YOU SE & Co. KG
Photo of the Rise User
Someone from OH, Cincinnati just viewed Summer 2025 Internship: Talent at Hylant