GRC Solutions Consultant
Remote
YGI Solutions performs compliance readiness assessments for organizations preparing to pursue or maintain federal and commercial security authorizations. We are building a bench of contract consultants who can be assigned to client engagements and carry the assessment work from kickoff through deliverable handoff.
In this role you will evaluate a client's current control environment against a target framework, identify the gaps, and produce the documentation and remediation roadmap that gets them audit-ready. Most engagements center on FedRAMP and CMMC, with additional work across other frameworks depending on the client.
Responsibilities
- Conduct current-state assessments of client security and compliance programs, including control walkthroughs, stakeholder interviews, evidence sampling, and system boundary and scoping analysis.
- Perform gap analyses against target frameworks and translate findings into prioritized, practical remediation roadmaps with realistic effort estimates.
- Draft and tailor policies, standards, procedures, and plans to the client's actual operating environment rather than delivering generic templates.
- Develop and maintain core compliance artifacts, including System Security Plans, control narratives and implementation statements, POA&Ms, inventories, and data flow and boundary diagrams.
- Conduct internal audits and readiness reviews, including evidence collection and validation, control testing against assessment objectives, and findings documentation.
- Run risk assessments, including asset and threat identification, likelihood and impact scoring, risk register development, and treatment plan recommendations.
- Prepare clients for third-party assessment, including evidence package assembly, mock interviews, and coordination support with 3PAOs, C3PAOs, and external auditors.
- Configure and maintain client compliance programs within GRC platforms, including control mapping, evidence automation, and monitoring setup.
- Produce clear written deliverables and present findings to client stakeholders ranging from engineers to executive leadership.
- Track engagement hours and deliverable status, and communicate risks to schedule promptly.
Qualifications
- Three to five years of hands-on experience in security compliance, IT audit, GRC, or a closely related discipline.
- Demonstrated experience with FedRAMP and NIST SP 800-53 (Rev. 5), including authorization boundary definition, FIPS 199 categorization, control tailoring, and SSP development.
- Demonstrated experience with CMMC and NIST SP 800-171, including CUI scoping, assessment objective testing against 800-171A, SPRS scoring, and POA&M development.
- Ability to write clean, audit-defensible documentation with minimal editing, and to explain a control requirement in plain language to a technical owner.
- Working understanding of the technical environments these controls apply to, including cloud infrastructure, identity and access management, logging and monitoring, encryption, and vulnerability management.
- Comfort operating independently in ambiguous client environments, and the professional judgment to know when to escalate.
- U.S. person status, given the nature of federal client work.
- Reliable availability during U.S. business hours for client meetings.
Preferred Qualifications
- Experience with additional frameworks such as ISO 27001, SOC 2, HIPAA, PCI DSS, StateRAMP, or privacy regimes including GDPR and CCPA.
- Hands-on experience administering GRC platforms, particularly Paramify, Vanta, or Drata. Familiarity with Hyperproof, AuditBoard, Onspring, or similar platforms is also valued.
- Prior consulting or client-facing advisory experience, especially with small and mid-sized organizations that lack a dedicated compliance function.
- Experience on the assessor side of the table, whether at a 3PAO, C3PAO, or audit firm.
- Relevant certifications such as CISA, CISSP, CCP or CCA, CRISC, ISO 27001 Lead Implementer or Lead Auditor, or CISM.
- Familiarity with FedRAMP 20x and other evolving program requirements.
- Experience supporting defense industrial base suppliers or federal system integrators.
Engagement Details
- Contract work is assigned per engagement, with typical assessments running four to twelve weeks.
- Utilization varies by client demand. Consultants who deliver consistently are prioritized for repeat and larger assignments.
- Rates are set per engagement based on scope and complexity, and are negotiated at assignment.
- Contractors supply their own equipment and are responsible for their own taxes, insurance, and benefits.
- Execution of a contractor agreement, mutual NDA, and any client-specific confidentiality terms is required prior to assignment.
How to Apply
Submit a resume along with a brief note describing two readiness engagements you have worked, the frameworks involved, and what you personally produced. Redacted writing samples, such as a control narrative, gap assessment summary, or policy excerpt, are welcome and will strengthen your application.