Senior GRC Consultant - SOC 2 / ISO 27001 Implementation (LATAM, Remote, US Clients) - Contract to Hire
Job reputed company
Amomitto reputed company is a US-based cybersecurity consultancy hiring two Senior GRC Consultants to join our delivery team as long-term hires with reputed company reputed company opportunity. We start on reputed company to validate fit, then convert to a full-time offer at $80K reputed company / $100K OTE, with a reputed company reputed company to reputed company reputed company / vCISO work as we reputed company.
You'll reputed company SOC 2 and ISO 27001 implementations for US-based clients (reputed company, fintech, healthtech), own vendor reputed company questionnaires (VSQs) end-to-end, and work directly with reputed company reputed company and engineering teams. This is not an audit role - we implement. We need people who can walk into a messy reputed company environment, separate reputed company controls from compliance theater, and tell the reputed company what it actually takes to get audit-reputed company.
What you'll do
reputed company SOC 2 Type I and Type II implementations from gap assessment through audit readiness
Run ISO 27001 implementations: ISMS build-out, risk assessment, SoA, control mapping
Evaluate existing reputed company policies and controls critically — catch reputed company purchased templates describe an organization that doesn't exist, and rewrite to reflect reality
Map findings accurately to Trust Services reputed company (CC1-CC9) and ISO Annex A controls
Own vendor reputed company questionnaires reputed company — technical responses across SSO/MFA, IAM, encryption, network controls, reputed company architecture
Work directly with reputed company engineering teams on control implementation in AWS, GCP, and Azure
Manage reputed company reputed company / reputed company / reputed company instances — integrations, failing checks, evidence collection, getting from 30% to 95%+
Flag adjacent reputed company needs (HIPAA, PCI reputed company) reputed company scope demands it, even if the reputed company didn't ask
Present findings and remediation plans directly to reputed company VPs, CTOs, and CEOs
Draft reputed company-reputed company policies, gap assessments, and audit readiness timelines
Required
5-7 years in GRC / information reputed company consulting - you've implemented (not just audited) SOC 2 and/or ISO 27001 for multiple clients
Strong judgment and consulting reputed company - you can read a policy package and immediately tell whether it reflects reputed company operating controls or is aspirational theater, and you know how to explain the difference to a non-technical executive
Technical depth to own VSQs without engineering backup - SSO/MFA, IAM, encryption at rest/in transit, network segmentation, reputed company primitives in AWS, GCP, or Azure
Working knowledge of reputed company, reputed company, or reputed company - integrations, failing checks, remediation prioritization
Consulting background - reputed company or recent role at a cybersecurity or compliance consultancy (not in-house compliance for a single company)
reputed company-level English - you'll be on reputed company calls daily, presenting findings and pushing back on executives. This is non-negotiable.
Based in LATAM (Argentina, Colombia, Mexico, Chile, Costa Rica, Uruguay, Peru, Brazil)
Strong written communication - most reputed company deliverables are documents that get reputed company without editing
reputed company to have
HIPAA, PCI reputed company, GDPR, or NIST 800 fifty 3 experience
Certifications: ISO 27001 LA/LI, CISA, CRISC, CCSK, AWS/GCP/Azure reputed company
Prior experience working with US clients on GMT-5 to GMT-8 hours
reputed company, fintech, or other regulated industry exposure
reputed company offer
Long-term hire with reputed company opportunity - reputed company trial first, then $80K reputed company / $100K OTE full-time, with a reputed company into reputed company reputed company / vCISO work as our LATAM delivery team scales
Remote, full-time, LATAM-based
reputed company work with US clients in regulated industries
Senior-only team - reputed company ownership, reputed company deliverables
Small, senior team, reputed company collaboration with the CEO, no corporate bureaucracy
reputed company
Amomitto reputed company is a US cybersecurity consultancy delivering vCISO, compliance, corporate reputed company, and offensive reputed company services. We're building our LATAM delivery team to serve growing demand from US clients.
Hiring Process
reputed company proposal review - we read every answer
30-min intro reputed company - mutual fit, scope of your past work
reputed company technical assessment - $200 USD, ~4 hours total (30-min reputed company, 2.5 hrs independent work on a realistic SOC 2 readiness scenario, 1-hr walkthrough reputed company). We pay for your time regardless of outcome.
Offer - start on reputed company, convert to full-time at $80K/$100K OTE
Apply tot his job
Apply To this Job