Principal GRC, Cyber Security Data Architect

Yantran LLC
  • SAN FRANCISCO, CA
  • Instant Apply
30+ days ago

Job Description

Role Purpose
Lead the delivery of a NIST CSF 2.0 cybersecurity gap and maturity assessment for a global enterprise program, covering assessment planning, stakeholder engagement, evidence review, maturity scoring, risk based gap prioritization, executive reporting, and development of a practical improvement roadmap.
Key Responsibilities
Own end to end engagement governance, project planning, milestones, risks, dependencies, status reporting, and stakeholder communications.
Conduct NIST CSF 2.0 maturity assessment across functions, categories, subcategories, implementation tiers, and profiles.
Review policies, standards, procedures, controls, risk registers, asset inventories, KPIs/KRIs, and supporting evidence.
Facilitate interviews and workshops with cybersecurity, risk, compliance, technology, and business stakeholders.
Define defensible maturity scoring, identify control gaps, assess business risk, and prioritize remediation actions.
Develop executive ready assessment reports, maturity dashboards, prioritized recommendations, and near/mid/long term roadmap.
Required Experience
Area
Requirement
Total Experience
10 to 15 years in cybersecurity, GRC, risk management, audit, security consulting, or cybersecurity program assessment.
NIST CSF Expertise
Strong hands on experience with NIST CSF, preferably NIST CSF 2.0 maturity assessments.
Framework Mapping
Experience mapping controls across NIST CSF, ISO 27001, NIST 800 53, CIS Controls, SOC 2, or similar frameworks.
Assessment Delivery
Proven experience conducting enterprise wide cybersecurity maturity, gap, risk, or control assessments.
Stakeholder Management
Ability to conduct interviews/workshops with senior security, risk, compliance, technology, and business stakeholders.
Executive Reporting
Strong experience creating leadership ready cybersecurity reports, maturity dashboards, and roadmap presentations.
Consulting Delivery
Experience working in consulting/advisory environments with structured methodology, governance, and client facing deliverables.
Risk Prioritization
Ability to convert control gaps into risk ranked remediation recommendations and practical roadmaps.
Required Skills
Strong expertise in NIST CSF 2.0, cybersecurity governance, risk management, compliance, control maturity models, and ISO 27001 / ISMS.
Ability to map controls across NIST CSF, ISO 27001, NIST 800 53, CIS Controls, SOC 2, and similar frameworks.
Experience in evidence based assessment, maturity scoring, risk based gap prioritization, and remediation roadmap development.
Excellent consulting delivery, workshop facilitation, stakeholder management, executive reporting, and written/verbal communication skills.
Preferred Certifications
CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor / Lead Implementer, NIST CSF training/certification, PMP / Prince2 / Agile certification preferred.
Tools / Platforms Knowledge Preferred
GRC and evidence management platforms such as Archer, ServiceNow GRC, OneTrust, MetricStream, SharePoint, Teams, Excel, PowerPoint, Visio, Power BI, and cybersecurity KPI/KRI dashboarding tools.

Numbers & Facts

LocationSAN FRANCISCO, CA

Skills

  • Agile Programming Methodologiesunmatched
  • Auditingunmatched
  • Business Analysisunmatched
  • CISA - Certified Information Systems Auditorunmatched
  • CISM - Certified Information Security Managerunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Communication Skillsunmatched
  • Consultingunmatched
  • Customer Relationsunmatched
  • DataArchitect Data Modeling Toolunmatched
  • Establish Prioritiesunmatched
  • ISO (International Organization for Standardization)unmatched
  • Internet Securityunmatched
  • Leadershipunmatched
  • Microsoft Excelunmatched
  • Microsoft PowerPointunmatched
  • Microsoft SharePointunmatched
  • Microsoft Visiounmatched
  • PRINCE2unmatched
  • Performance Metricsunmatched
  • Power BIunmatched
  • Presentation/Verbal Skillsunmatched
  • Program Evaluationunmatched
  • Project Management Professional (PMP)unmatched
  • Project Planningunmatched
  • Reporting Dashboardsunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Security Architectureunmatched
  • Security Auditingunmatched
  • Security Consultingunmatched
  • ServiceNowunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder