• Skip to primary navigation
  • Skip to main content
  • Skip to footer

Side Hustles

Side Hustles

Side Hustles For All

  • Best Side Hustles
    • Woman sitting on a pile of coins and working on a laptop surrounded by icons representing different side hustle ideas

      31 Best Side Hustles to Earn Extra Money in 2026

    • Bicycle courier delivering food for their side hustle.

      What Is a Side Hustle?

    • Remote worker sitting at his desk making money from home

      18 Ways to Make Money from Home (Online and Offline Jobs)

    • By Category
      • Arts & Crafts
      • Business Services
      • Caregiving
      • Creative Services
      • Digital Freelance Services
      • View All
    • By Lifestyle
      • I’m introverted
      • I’m a man
      • I’m a woman
      • I’m a stay-at-home mom
      • I’m unique
      • View All
    • By Profession
      • Artists & Creatives
      • Musicians
      • Nurses
      • Physicians
      • Teachers
      • View All
    • By Age Group
      • College Students
      • Teens
      • Age 50+
      • Seniors
      • View All
    • By Skills & Interests
      • Get Paid to Lose Weight
      • Get Paid to Play Games
      • Get Paid to Read
      • Get Paid to Sleep
      • Get Paid to Travel
      • View All
  • Best Gig Apps
    • Freelance worker popping out of a phone screen and considering gig apps on the App Store and Google Play

      Top 6 Gig Apps to Make Real Cash in 2026

    • Smartphone surrounded by the icons of different money-making apps

      Top 10 Best Money-Making Apps to Try in 2026

    • two teenagers using job apps on a phone and laptop

      19 Job Apps for Teens to Find Jobs and Make Money

    • By Gig Type
      • Cashback
      • Data Entry
      • Delivery
      • Games
      • Product Testing
      • View All
    • By Payment Method
      • Bingo Games that Pay to Cash App
      • Games that Pay Real Money
      • Games that Pay to Cash App
      • Games that Pay via PayPal
      • Surveys that Pay to Cash App
      • View All
    • By Benefits
      • $20 Signup Bonuses
      • $25 Signup Bonuses
      • $50 Signup Bonuses
      • Best Signup Bonuses
      • Instant Signup Bonuses
      • View All
    • By Skills & Interests
      • Driving
      • Losing Weight
      • Playing Games
      • Product Testing
      • Watching Ads
      • View All
  • Job Hunting
    • Freelance worker browsing a job post on a freelance job board.

      23 Job Boards You Can Use to Find Remote Work

    • Freelance writer sitting at her laptop working on a project

      15 Best Remote Jobs That Require No Paid Work Experience

    • Teenager sitting at laptop working an online job

      14 Online Jobs for Teens (With No Experience)

    • Freelancing
      • Freelance Writing Sites
      • Freelance Writing Job Boards
      • Freelance Writing Platforms
      • View More
    • Gig & Shift Work
      • Gig Work Apps
      • On-Demand Work Apps
      • Shift Work Apps
      • View More
    • GPT (Get Paid To)
      • Microtasking
      • Product Testing
      • Survey Taking
      • View More
    • Remote Working
      • Best Remote Job Boards
      • Top 15 Remote Jobs
      • View More
  • Job Board
    • Work Schedule
      • Part-Time Jobs
      • Per-Diem Jobs
      • Go Search
    • Work Environment
      • Hybrid Jobs
      • Remote Jobs
      • Go Search
    • Employment Type
      • Contractor Jobs
      • Internship Jobs
      • Temporary Jobs
      • Go Search
    • Job Title
      • Accounting Jobs
      • Data Entry Jobs
      • Nursing Jobs
      • Online Teaching Jobs
      • Software Engineer Jobs
      • Go Search
    • State
      • California Jobs
      • Florida Jobs
      • New York Jobs
      • Pennsylvania Jobs
      • Texas Jobs
      • Go Search
    • City
      • Chicago, IL
      • Houston, TX
      • Los Angeles, CA
      • New York City, NY
      • Phoenix, AZ
      • Go Search

Home Flexible Job Board Principal/Senior Consultant, Governance, Risk & Compliance

Salary Unstated 33d ago

Principal/Senior Consultant, Governance, Risk & Compliance

Boost your chances before you apply.

  • ✨ Apply 10x Faster Free

    It takes 30+ tailored applications to land jobs like this one. We'll help you get that done in 1 hour.

    No Credit Card Required

  • Proceed to Application Go directly to the company's job page to apply.
Logo

Converge Technology Solutions

US

Full-time Permanent Remote

✨ Apply 10x Faster

Analyze your resume for missing keywords, then one-click optimize it. Don't be anything less than a 100% match candidate.

Free

No Credit Card Required

Summary

Lead complex cybersecurity and GRC consulting engagements, including assessments, audits, and strategic advisory services for a diverse client portfolio. Facilitate stakeholder interviews, evaluate control effectiveness, and develop risk-based remediation roadmaps and executive-ready reports.

Job Description

Principal/Senior Consultant, Governance, Risk & Compliance 

Practice: Cybersecurity, Governance, Risk & Compliance 
Employment Type: Full-Time 
Location: Remote, United States 
Travel: Occasional travel to client locations for assessments, workshops, interviews, and other project activities 

Position Summary 

Pellera Technologies is seeking an experienced Principal / Senior GRC Consultant, to join our growing Cybersecurity Services practice. This is an opportunity for a seasoned cybersecurity, audit, risk, and compliance professional to advise a diverse portfolio of clients, lead complex consulting engagements, and help organizations turn regulatory and security requirements into practical, sustainable improvements. 

The Principal/Senior Consultant will lead and contribute to cybersecurity audits, risk and framework assessments, compliance-readiness programs, cloud-security reviews, governance initiatives, and strategic advisory engagements. The role calls for someone who can move comfortably between executive conversations, stakeholder interviews, evidence analysis, control testing, technical discussions, and the production of high-quality client deliverables. 

Our consultants are not limited to producing findings. They help clients understand risk, prioritize action, strengthen controls, prepare for high-stake audits and assessments, and build governance programs that support long-term business objectives. Pellera’s established methodology incorporates interviews, evidence gathering, observations, risk and gap analysis, prioritized recommendations, and executive-ready reporting.  

What You Will Do 

Lead Cybersecurity and GRC Consulting Engagements 

  • Lead complex client engagements from discovery and planning through assessment, reporting, and executive presentation. 

  • Conduct stakeholder interviews with executives, technology leaders, system owners, control owners, legal and compliance personnel, business leaders, and other subject matter experts. 

  • Review policies, standards, procedures, system documentation, architecture diagrams, data flows, prior assessments, audit reports, control evidence, technical configurations, and other relevant artifacts. 

  • Evaluate the design, implementation, and operating effectiveness of cybersecurity, privacy, resiliency, and technology controls. 

  • Identify control gaps, risks, exceptions, dependencies, and opportunities for improvement. 

  • Develop pragmatic, risk-based recommendations, remediation roadmaps, plans of action and milestones, maturity models, and prioritized implementation plans. 

  • Produce polished assessment reports, control workpapers, executive summaries, presentations, dashboards, and other audit-defensible deliverables. 

  • Present results to technical teams, executives, boards, auditors, assessors, and other client stakeholders. 

Pellera GRC engagements commonly include structured interviews, documentation and evidence review, control analysis, risk prioritization, and reporting. Depending on the project, Consultants may also perform technical control observations or configuration reviews.  

Deliver Framework, Regulatory, and Audit Services 

Lead or support advisory, readiness, assessment, audit, and remediation services involving frameworks and requirements such as: 

  • PCI DSS, including scoping, readiness assessments, SAQ support, Reports on Compliance, Attestations of Compliance, remediation guidance, and ongoing compliance advisory 

  • CMMC and NIST SP 800-171, including readiness assessments, evidence validation, CUI boundary and data-flow analysis, SPRS and POA&M support, remediation roadmaps, mock assessments, and preparation for authorized C3PAO assessments 

  • HIPAA Security, Privacy, and Breach Notification Rules, including alignment with NIST SP 800-66 and relevant regulatory audit protocols 

  • NIST Cybersecurity Framework (NIST CSF) 

  • NIST SP 800-53 and control-based federal or regulated-industry assessments 

  • CIS Critical Security Controls 

  • ISO/IEC 27001 and related information security standards 

  • ISO 22301 business continuity management 

  • ISO/IEC 42001 and NIST AI Risk Management Framework (NIST AI RMF) 

  • Data privacy and governance requirements 

  • Cloud-security and cloud-governance assessments 

  • Business continuity, disaster recovery, and business impact analysis 

  • Third-party and supply-chain risk management 

  • Cybersecurity program maturity and governance assessments 

Pellera GRC Consultants may perform NIST-aligned GRC programs; PCI DSS ROC assessments & attestations; CMMC readiness, remediation, evidence-validation, and audit-preparation services; cloud-security reviews; data-governance engagements; Cyber Executive Advisory or vCISO services; and resiliency-focused assessments.  

Experience with additional frameworks and requirements is highly valued, including: 

  • SOC 1 and SOC 2 

  • SOX and IT general controls 

  • COBIT 

  • HITRUST CSF 

  • FedRAMP and related federal authorization requirements 

  • DFARS and FAR cybersecurity clauses 

  • ISO/IEC 27701 

  • CSA Cloud Controls Matrix and CSA STAR 

  • GDPR, CCPA, CPRA, and other national or state privacy regulations 

  • GLBA, FFIEC, NYDFS Cybersecurity Regulation, NERC CIP, NIS2, TISAX, TX-RAMP, and other industry-specific requirements 

While not mandatory, these additional areas reflect frameworks and regulatory requirements that Pellera GRC Consultants have consulted on or have familiarity with. 

Provide Strategic GRC Advisory 

  • Help clients establish or mature cybersecurity governance, enterprise risk management, control, compliance, privacy, and assurance programs. 

  • Develop cybersecurity strategies, target operating models, governance structures, policies, standards, procedures, and multi-year roadmaps. 

  • Support vCISO, vDPO, GRC-as-a-Service, and strategic program-management engagements. 

  • Facilitate risk, control, and governance workshops with business and technical stakeholders. 

  • Support executive and board-level reporting on cybersecurity risk, compliance posture, control effectiveness, and improvement progress. 

  • Assist clients with audit preparation, regulatory inquiries, customer assurance requests, and third-party assessments. 

  • Advise on vendor risk management, mergers and acquisitions, security awareness, vulnerability-management governance, incident-response readiness, and cybersecurity investment priorities. 

GRC Consultants are embedded into delivery of compliance services, risk services, and governance services, including framework assessments, risk assessments, cloud-security assessments, BCP/DR and BIA work, vCISO/vDPO services, program management, policy development, audit preparation, executive reporting, M&A support, and special projects.  

Bridge GRC and Technology 

  • Translate regulatory, contractual, risk, and control requirements into language that cloud, infrastructure, security, application, and business teams can act upon. 

  • Assess how controls are implemented across Microsoft Azure, Microsoft 365, AWS, Google Cloud Platform, SaaS, on-premises, hybrid, and multi-cloud environments. 

  • Review technical evidence involving identity and access management, logging and monitoring, vulnerability management, endpoint protection, network security, encryption, data protection, backup and recovery, secure configuration, and incident response. 

  • Work collaboratively with Pellera specialists across cloud, digital workplace, data protection, cybersecurity engineering, artificial intelligence, infrastructure, and managed services. 

  • Support cloud migration and modernization initiatives where GRC obligations must be integrated into architecture, implementation, and operational processes. 

Pellera’s GRC services are blended into many other Pellera provided services including cloud migrations, Cloud FinOps, digital infrastructure and workplace, and GCC High or AWS Gov, and growing Artificial Intelligence enablement initiatives.  

Contribute to Practice Growth 

  • Support pre-sales discovery, solution development, project scoping, level-of-effort estimation, proposal development, and client presentations. 

  • Partner with account teams and solution architects to identify the right combination of GRC, cybersecurity, cloud, data-protection, and infrastructure services. 

  • Contribute to reusable methodologies, templates, accelerators, workpapers, and delivery standards. 

  • Mentor other consultants and share knowledge across the practice. 

  • Develop thought leadership, client briefings, webinars, white papers, or conference content when appropriate. 

  • Identify follow-on opportunities based on legitimate client risks, needs, and project findings. 

GRC consultants may also be invited to pre-sales discussions because subject matter depth improves GRC discovery and scoping. Team members also contribute to service development, client education, and thought leadership.  

Required Qualifications 

  • Fifteen or more years of progressively responsible experience across cybersecurity, information technology, governance, risk, compliance, internal audit, external audit, privacy, or related disciplines. Candidates with a compelling combination of consulting depth, framework expertise, technical knowledge, and leadership experience will also be considered. 

  • Experience working in a consulting, professional services, audit, advisory, or client-facing environment. 

  • Demonstrated ability to independently lead complex cybersecurity or GRC engagements. 

  • Broad knowledge of cybersecurity control frameworks, regulatory requirements, risk-management practices, and audit methodologies. 

  • Experience assessing control design and effectiveness, documenting evidence, developing findings, and presenting practical remediation recommendations. 

  • Strong understanding of IT general controls, control testing, risk assessment, audit evidence, and issue-remediation lifecycle management. 

  • Proven ability to write polished, accurate, executive-ready reports, presentations, policies, roadmaps, and other client deliverables. 

  • Strong verbal communication, interviewing, workshop-facilitation, and presentation skills. 

  • Ability to communicate equally well with executives, auditors, attorneys, compliance leaders, engineers, administrators, and business stakeholders. 

  • Ability to manage multiple client commitments, deadlines, dependencies, and competing priorities while maintaining delivery quality. 

  • Willingness to travel occasionally for client assessments and workshops. 

  • Authorization to work in the United States. 

Preferred Qualifications 

  • Working knowledge of Azure, Microsoft 365, AWS, GCP, hybrid-cloud, SaaS, or on-premises enterprise environments. 

  • Experience examining technical configurations or evidence related to identity, network security, endpoint security, vulnerability management, logging, monitoring, encryption, data protection, backup, recovery, and cloud-security controls. 

  • Experience with Microsoft and AWS Commercial & Government Cloud environments, cloud-native security & governance tools, cloud-security posture management, data loss prevention, data classification, and multi-cloud architectures. 

  • Experience with GRC or integrated risk-management platforms such as ServiceNow GRC/IRM, Archer, OneTrust, Vanta, LogicGate, OpenPages, or comparable technologies. 

  • Experience developing cybersecurity metrics, KRIs, KPIs, dashboards, risk registers, control libraries, and executive or board reporting. 

  • Experience with AI governance, AI security, model risk, algorithmic transparency, data privacy, or responsible AI. 

  • Experience performing technical pre-sales, developing SOWs, estimating consulting effort, or supporting solution design. 

  • Experience serving clients in healthcare, retail, restaurants, financial services, insurance, manufacturing, aerospace and defense, technology, higher education, government, hospitality, or other highly regulated industries. 

Preferred Certifications 

One or more of the following certifications is preferred: 

  • ISACA CISA, CISM, CRISC 

  • IS2 CISSP, CGRC, CCSP 

  • PCI QSA 

  • CMMC Certified Professional, Certified CMMC Assessor, or Registered Practitioner 

  • ISO/IEC 27001 Lead Auditor or Lead Implementer 

  • HITRUST CCSFP or related HITRUST credential 

  • Microsoft Azure and/or AWS security certifications 

  • Other relevant cybersecurity, audit, privacy, cloud, or risk-management certifications 

What Success Looks Like 

A successful Principal/Senior Consultant will: 

  • Earn client trust through expertise, integrity, responsiveness, and practical advice. 

  • Deliver clear, accurate, well-supported, audit-defensible work. 

  • Convert complex control and regulatory requirements into prioritized actions clients can understand and execute. 

  • Lead engagements with appropriate independence while collaborating effectively with project managers, technical specialists, and other consultants. 

  • Communicate risks and recommendations without unnecessary alarm, jargon, or over-engineering. 

  • Maintain quality and predictability across scope, schedule, deliverables, and client expectations. 

  • Strengthen Pellera’s methodologies by contributing real-world knowledge and reusable intellectual capital. 

  • Help clients achieve measurable reductions in risk, stronger controls, improved audit readiness, and more sustainable governance. 

Work Environment and Travel 

This is a remote position. Most consulting, analysis, documentation, and project collaboration will be performed remotely. Occasional travel to client locations may be required for onsite assessments, interviews, workshops, observations, evidence validation, or executive presentations. The amount of travel will vary based on the engagement and will be coordinated in advance whenever practical. 

Why Join Pellera? 

At Pellera, GRC is not an isolated function. It is part of a broader technology and cybersecurity organization with capabilities spanning artificial intelligence, analytics, cloud, digital infrastructure, application modernization, digital workplace, data protection, offensive security, and managed services. That breadth gives GRC consultants the opportunity to help clients not only identify risk, but also connect them with specialists who can help design, implement, and operate solutions. Pellera’s public cybersecurity portfolio similarly positions GRC alongside application and cloud security, cyber resiliency, identity, infrastructure, security operations, and managed services.  

The work is varied and substantive. Consultants may help a defense contractor prepare for CMMC, lead a PCI DSS assessment for a large retail environment, assess healthcare security and privacy controls, evaluate an Azure or Microsoft 365 tenant, design an enterprise GRC operating model, develop an AI risk-governance program, or advise executives on a multi-year cybersecurity roadmap.  

With over 3,200 employees, Pellera is an enterprise technology partner combining digital infrastructure and workplace, hybrid cloud, cybersecurity, and artificial intelligence capabilities, delivered through its Advise, Implement, and Manage approach.  

About the company

Converge Technology Solutions

Converge is now Pellera Technologies. This page no longer posts content or updates as it relates to Converge's solutions and services, and all new information will be posted on Pellera Technologies' page. Thank you for following Converge and your continued support throughout the years. We hope you will continue to be a part of our journey by following Pellera's LinkedIn page.

Company size

1,001-5,000 employees

Industry

IT Services and IT Consulting

Org type

Public Company

Headquarters

Gatineau, Québec

Apply Now

About the company

Converge Technology Solutions

Converge is now Pellera Technologies. This page no longer posts content or updates as it relates to Converge's solutions and services, and all new information will be posted on Pellera Technologies' page. Thank you for following Converge and your continued support throughout the years. We hope you will continue to be a part of our journey by following Pellera's LinkedIn page.

Company size

1,001-5,000 employees

Industry

IT Services and IT Consulting

Org type

Public Company

Headquarters

Gatineau, Québec

Footer

sidehustles.com
Facebook Twitter Instagram LinkedIn Reddit TikTok YouTube

Show Me The Money

  • Side Hustle Basics
  • Side Hustle Job Board (Remote & Part-Time Jobs)
  • Gig App Reviews
  • Job Hunting
  • Manage Your Money
  • The Gig Apple: News & Events

Company

  • About Us
  • Contact Us
  • Become a Contributor
  • Advertising & Sponsorships
  • Partner With Us
  • Editorial Guidelines

Side Hustles © All rights reserved

  • Privacy Policy
  • Terms of Service

Thanks for using our free job board

Your review would mean a lot to us.

If you love that we're just giving away remote jobs for free with no paywall, please spread the word. (You will need to create an account on Trustpilot, for which we'll be eternally grateful.) Good luck out there!

Leave a Review Not yet. Send me to the job post.