Qualifications:
Required
4-8 years of experience in cybersecurity, IT risk, or compliance with a clear focus on GRC; must include hands-on experience with at least two GRC domains (risk management, compliance program management, policy governance, or third-party risk)
Hands-on experience across GRC domains and platforms, including one or more of:
Risk Management - enterprise and IT risk assessments, risk register development, risk quantification (FAIR or qualitative), risk treatment planning, and KRI design
Compliance Program Management - regulatory gap assessments, controls mapping, audit readiness, evidence collection workflows, and remediation tracking against frameworks such as SOC 2, ISO 27001, FedRAMP, HIPAA, PCI DSS, DORA, or SOX ITGC
Policy & Control Governance - policy development and review cycles, control framework design (NIST, CIS, ISO), control testing methodology, and policy exception management
Third-Party & Vendor Risk - vendor risk tiering, assessment questionnaire management, contractual control review, and ongoing monitoring program design
GRC Platforms - ServiceNow GRC, Archer, OneTrust, Vanta, Drata, or equivalent: workflow configuration, risk and compliance module setup, or reporting and dashboard design
Working knowledge of GRC and security frameworks: NIST CSF 2.0, NIST SP 800-53, NIST RMF, ISO 27001/27002, CIS Controls v8, SOC 2 Trust Services Criteria, COBIT, PCI DSS v4, HIPAA Security Rule, SOX ITGC, FedRAMP, and DORA
Understanding of core GRC concepts: risk appetite and tolerance, control design vs. control effectiveness, separation of duties, three lines of defense, audit lifecycle, regulatory change management, and data privacy principles
Demonstrated consulting delivery competencies, including:
Preferred
Key Competencies
Success in this role means executing GRC deliverables with high quality and growing independence, building credibility with client teams through consistent performance, expanding domain depth and consulting skills, and contributing to a practice that clients trust and return to while building toward the skills and experience required to step into a Lead Consultant role
Want to learn more about Consulting & Security Services? Check us out on our platform:
https://www.wwt.com/consulting-services
https://www.wwt.com/category/security-transformation
Certain states and localities require employers to post a reasonable estimate of salary range. A reasonable estimate of the current base pay range for this position is $146,500 to $185,000 annually. Actual salary will be based on a variety of factors, including shift, location, experience, skill set, performance, licensure and certification, and business needs. The range for this position in other geographic locations may differ. Certain positions may also be eligible for variable incentive compensation, such as bonuses or commissions, that is not included in the base pay.
The well-being of WWT employees is essential. So, when it comes to our benefits package, WWT has one of the best. We offer the following benefits to all full-time employees:
We strive to create an environment where all employees are empowered to succeed based on their skills, performance, and dedication. Our goal is to cultivate a culture of belonging that encourages innovation, collaboration, and respect for all team members, ensuring that WWT remains a great place to work for All!
If you have any questions or concerns about this posting, please email taposting@wwt.com.
| Location | MO |
| Salary | $146,500–$185,000 Per Year |
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder