✦ Luna Orbit — Consulting & Advisory

Compliance Consultant – GRC Practice

at Artemis Connection

📍 Remote, US Remote Posted April 04, 2026
Type Contract
Experience mid
Exp. Years 5+ years
Education Bachelor's degree in information systems, computer science, business, law, or closely related field, or equivalent demonstrated experience
Category Consulting & Advisory

Compliance Consultant in a GRC practice delivering assessments, framework implementations, and advisory engagements across SOC 2, ISO 27001, CMMC 2.0, and NIST CSF for diverse clients.

  • Client engagement & delivery
  • Framework translation & reconciliation
  • Risk assessment & control design
  • Policy & documentation development
  • Audit support & remediation management

Focus on information security controls, risk assessment, policy development, and audit support with fluency in multiple regulatory standards; experience with GRC frameworks and evidence collection.

The ideal candidate is a mid-career compliance and information security professional with 5+ years delivering audits and framework implementations across SOC 2, ISO 27001, CMMC 2.0, and NIST CSF in a consulting or client-facing capacity. They should hold an active certification (CISA/CISSP/CISM/CRISC/CCSFP) and be adept at communicating findings to executives and boards.

Bachelor's degree or equivalent experience5+ years in compliance/information securityhands-on experience with at least two of the following: SOC 2ISO 27001CMMC 2.0NIST CSFHIPAAPCI-DSSor FedRAMPAt least one active professional certification — CISACISSPCISMCRISCor CCSFPStrong written and verbal communication skills
GRC platforms: VantaDrataOneTrustServiceNow GRCor ArcherExposure to regulated industries — healthcaredefense industrial basefinancial servicesor government contractingCloud security architecture concepts across AWSAzureor GCPExperience in a Big Four or mid-market advisory firm environmentMinimum 2+ years of consulting experience
VantaDrataOneTrustServiceNow GRCArcher
Bachelor's degree or equivalent5+ years in compliance/information securityhands-on experience with SOC 2 ISO 27001 CMMC 2.0 NIST CSF HIPAA PCI-DSS FedRAMPactive certifications (CISA/CISSP/CISM/CRISC/CCSFP)strong communication
SOC 2SOC 2 Type I/IIISO 27001CMMC 2.0NIST CSFHIPAAPCI-DSSFedRAMPgap analysiscontrol testingremediation managementpolicy writingevidence collectionaudit supportframework crosswalksinformation security policies
communicationclient-facingstakeholder managementpresentationbusiness developmentproject managementrelationship managementleadership

Required

CISACISSPCISMCRISCCCSFP
Industry Consulting
Job Function Deliver compliance assessments and advisory engagements across frameworks for clients in a GRC practice.
Role Subtype IT Consultant
SOC 2 Type I/IIISO 27001CMMC 2.0NIST CSFHIPAAPCI-DSSFedRAMPCISACISSPCISMCRISCCCSFPGRC platformsVantaDrataOneTrustServiceNow GRCArcherinformation security policiesgap analysisaudit supportcisacisspcismcriscccsfpsoc 2iso 27001cmmc 2.0nist csffedramp

Lack of active certification, Less than 5 years experience in compliance/information security, No consulting or client-facing delivery experience

Apply for this Position →

Get matched to jobs like this

Luna finds roles that fit your skills and career goals — no endless scrolling required.

Create a Free Profile