We are looking for a GRC Consultant to support cybersecurity governance, risk, and compliance efforts for a growing organization in Illinois. This contract position with the potential to become permanent is ideal for someone who can bring structure to security programs, guide risk-based decision-making, and communicate complex findings in a clear, practical way. The role will partner with technical and business teams to strengthen policy management, vendor oversight, and broader governance activities while helping the organization maintain a strong security posture.
Responsibilities:
- Coordinate governance, risk, and compliance activities that support enterprise cybersecurity objectives and operational priorities.
- Maintain, review, and improve security policies, standards, and related documentation to keep guidance current and actionable.
- Perform third-party and vendor risk evaluations, document findings, and help track remediation efforts through completion.
- Translate technical security issues into concise business language for leadership, cross-functional stakeholders, and external partners.
- Partner with IT, legal, procurement, and business teams to support risk assessments, control reviews, and governance initiatives.
- Monitor compliance-related tasks, produce status reporting, and keep risk registers, dashboards, and supporting records organized and accurate.
- Contribute to assessments involving access controls, data protection practices, SaaS-related risks, and other core cybersecurity domains.
- Use Microsoft 365 tools to manage reporting, coordinate project activity, and track deliverables across multiple concurrent workstreams.