Skip to Content

GRC Solutions Consultant

Remote

YGI Solutions performs compliance readiness assessments for organizations preparing to pursue or maintain federal and commercial security authorizations. We are building a bench of contract consultants who can be assigned to client engagements and carry the assessment work from kickoff through deliverable handoff.

In this role you will evaluate a client's current control environment against a target framework, identify the gaps, and produce the documentation and remediation roadmap that gets them audit-ready. Most engagements center on FedRAMP and CMMC, with additional work across other frameworks depending on the client.

Responsibilities

  • Conduct current-state assessments of client security and compliance programs, including control walkthroughs, stakeholder interviews, evidence sampling, and system boundary and scoping analysis.
  • Perform gap analyses against target frameworks and translate findings into prioritized, practical remediation roadmaps with realistic effort estimates.
  • Draft and tailor policies, standards, procedures, and plans to the client's actual operating environment rather than delivering generic templates.
  • Develop and maintain core compliance artifacts, including System Security Plans, control narratives and implementation statements, POA&Ms, inventories, and data flow and boundary diagrams.
  • Conduct internal audits and readiness reviews, including evidence collection and validation, control testing against assessment objectives, and findings documentation.
  • Run risk assessments, including asset and threat identification, likelihood and impact scoring, risk register development, and treatment plan recommendations.
  • Prepare clients for third-party assessment, including evidence package assembly, mock interviews, and coordination support with 3PAOs, C3PAOs, and external auditors.
  • Configure and maintain client compliance programs within GRC platforms, including control mapping, evidence automation, and monitoring setup.
  • Produce clear written deliverables and present findings to client stakeholders ranging from engineers to executive leadership.
  • Track engagement hours and deliverable status, and communicate risks to schedule promptly.

Qualifications

  • Three to five years of hands-on experience in security compliance, IT audit, GRC, or a closely related discipline.
  • Demonstrated experience with FedRAMP and NIST SP 800-53 (Rev. 5), including authorization boundary definition, FIPS 199 categorization, control tailoring, and SSP development.
  • Demonstrated experience with CMMC and NIST SP 800-171, including CUI scoping, assessment objective testing against 800-171A, SPRS scoring, and POA&M development.
  • Ability to write clean, audit-defensible documentation with minimal editing, and to explain a control requirement in plain language to a technical owner.
  • Working understanding of the technical environments these controls apply to, including cloud infrastructure, identity and access management, logging and monitoring, encryption, and vulnerability management.
  • Comfort operating independently in ambiguous client environments, and the professional judgment to know when to escalate.
  • U.S. person status, given the nature of federal client work.
  • Reliable availability during U.S. business hours for client meetings.

Preferred Qualifications

  • Experience with additional frameworks such as ISO 27001, SOC 2, HIPAA, PCI DSS, StateRAMP, or privacy regimes including GDPR and CCPA.
  • Hands-on experience administering GRC platforms, particularly Paramify, Vanta, or Drata. Familiarity with Hyperproof, AuditBoard, Onspring, or similar platforms is also valued.
  • Prior consulting or client-facing advisory experience, especially with small and mid-sized organizations that lack a dedicated compliance function.
  • Experience on the assessor side of the table, whether at a 3PAO, C3PAO, or audit firm.
  • Relevant certifications such as CISA, CISSP, CCP or CCA, CRISC, ISO 27001 Lead Implementer or Lead Auditor, or CISM.
  • Familiarity with FedRAMP 20x and other evolving program requirements.
  • Experience supporting defense industrial base suppliers or federal system integrators.

Engagement Details

  • Contract work is assigned per engagement, with typical assessments running four to twelve weeks.
  • Utilization varies by client demand. Consultants who deliver consistently are prioritized for repeat and larger assignments.
  • Rates are set per engagement based on scope and complexity, and are negotiated at assignment.
  • Contractors supply their own equipment and are responsible for their own taxes, insurance, and benefits.
  • Execution of a contractor agreement, mutual NDA, and any client-specific confidentiality terms is required prior to assignment.

How to Apply

Submit a resume along with a brief note describing two readiness engagements you have worked, the frameworks involved, and what you personally produced. Redacted writing samples, such as a control narrative, gap assessment summary, or policy excerpt, are welcome and will strengthen your application. 

Consulting
Technical Expertise