Senior Consultant - IT Governance, Risk & Compliance (GRC)
ABOUT INFINITIVE
Infinitive has been named Best Small Firms to Work For by Consulting Magazine 8 times, most recently in 2025, and has also been recognized as a Washington Post Top Workplace, Washington Business Journal Best Places to Work, and Virginia Business Best Places to Work.
POSITION OVERVIEW
ROLES & RESPONSIBILITIES
- Lead or co-lead the design, implementation, and assessment of IT GRC programs including risk management frameworks, control libraries, and compliance roadmaps
- Conduct risk assessments, control gap analyses, and maturity evaluations aligned to industry frameworks (NIST CSF, ISO 27001, SOC 2, COBIT, CMMC, FedRAMP)
- Develop and maintain GRC deliverables including policies, standards, control matrices, risk registers, and audit evidence packages
- Support clients in remediating audit findings and implementing sustainable controls to reduce residual risk
- Track project progress against milestones, flag risks to leadership, and take ownership of assigned components with accountability for on-time, high-quality delivery
- Maintain 90%+ billability in support of Infinitive's organizational strategy and personal bonus eligibility
- Perform regulatory and compliance gap assessments across frameworks such as HIPAA, PCI-DSS, SOX, GDPR, CCPA, FISMA, and sector-specific requirements
- Act as primary author of—or provide substantial input to—client-facing deliverables including compliance roadmaps, risk treatment plans, audit readiness reports, and remediation trackers
- Map overlapping control requirements across multiple frameworks to streamline compliance efforts and reduce duplication
- Use data to understand the scope of client risk exposures, generate insights, and develop recommended solutions in collaboration with project leadership
- Facilitate risk identification and prioritization workshops with client stakeholders across IT, security, legal, and business functions
- Develop and maintain risk registers, risk heat maps, and third-party/vendor risk assessment programs
- Support the integration of GRC tooling (e.g., ServiceNow GRC, Archer, OneTrust, Vanta) to automate risk and compliance workflows
- Demonstrate a clear understanding of project goals and client ROI; proactively surface potential needs, pain points, and risk exposures to leadership
- Maintain professional, responsive, and constructive client relationships with the goal of becoming a trusted GRC advisor
- Present findings and deliverables to client stakeholders including CISOs, CIOs, compliance officers, and audit committees
- Communicate clearly and with discretion across internal and external audiences, including senior executive and regulatory stakeholders
- Identify new opportunities through client interactions and raise them to Infinitive leadership to support sales activities
- Collaborate cross-functionally with Infinitive and client teams including cybersecurity, data, and cloud engineering practices
- Actively learn adjacent skill sets and engage with fellow team members to build broad consulting capabilities
- Participate actively in Infinitive's cultural events, career development initiatives, and recruiting efforts
- Support sales and marketing activities as schedule allows, including communicating Infinitive's GRC capabilities and differentiators
- Maintain flexibility when navigating change; take initiative to expand your skill set while keeping leadership informed
COMPETENCIES & SKILLS
- Knowledge of IT GRC frameworks including NIST CSF, NIST 800-53, ISO 27001/27002, SOC 2, COBIT, CMMC, and FedRAMP
- Hands-on experience conducting control assessments, risk assessments, and audit readiness activities
- Proficiency with GRC platforms and tooling such as ServiceNow GRC, Archer RSA, OneTrust, Vanta, or equivalent
- Business analysis skills including requirements gathering, process mapping, gap analysis, and stakeholder facilitation — applied to GRC program design and implementation
- Project management methodologies, with experience managing compliance and risk remediation initiatives in Agile and waterfall environments
- Strong interpersonal and communication skills; ability to engage effectively with both technical teams and executive client leadership
- Familiarity with cloud security and compliance postures across AWS, Microsoft Azure, and/or Google Cloud Platform (e.g., shared responsibility model, cloud-native security controls)
Recommended Jobs
Senior NEPA Manager
SC&A is seeking a senior NEPA manager and specialist with demonstrated leadership experience in the preparation of multidisciplinary NEPA documents. To be considered, candidates must have previous s…
Early Childhood Program Director/Center Director
Summary We are seeking a compassionate, experienced, and dedicated Early Childhood Program Director to lead and manage our early childhood education center with heart, professionalism, and purpo…
Retail Sales Associate
Retail Sales Associate (Early Morning) - Tysons Corner Center Part time 7852U Tysons Corner Center, Tysons, VA, US 22102 As a Brand Associate, you're an integral part of our team and bring our b…
Title Reviewer
Job Type Full-time Description McMichael Taylor Gray, LLC is seeking Title Reviewers for states in our legal footprint. Candidates MUST HIGHLIGHT SPECIFIC EXPERIENCE AND LIVE in Virgini…
Manager, Product Management - Card Servicing Platform
Overview Manager, Product Management - Card Servicing Platform Product Management at Capital One is a booming, vibrant craft that requires reimagining the status quo, finding value creation op…
Laborer
Overview: Posillico is Building for Generations. Posillico is a multi-disciplined and diversified construction company. Along with our Civil /foundation group, Posillico’s business units include W…
Mover/Driver
Total Compensation: $15.00-$25.00 per hour which includes hourly rate, tips and performance-based monthly incentives! CDL is NOT required. ACTIVE + VALID DRIVER’S LICENSE IS REQUIRED. PART…
Systems Technician
Once an aircraft launches off a carrier, pilots depend on their jet's complex electronic systems to operate all areas of their craft and complete their mission. There is zero room for failure. That's…
Travel Nurse - CVOR Job in Falls Church, VA - $17,269 per Month (2 Years Experience Needed)
Vetted is seeking a RN - CVOR for a travel job in Falls Church, Virginia . Must have 2+ years of experience. This contract pays approximately $17,269/month gross. Assignment details: C…
Assistant Preconstruction Manager
Description Hourigan is the go-to fully integrated construction management and development firm when it comes to managing complex projects and delivering them to the highest standards. Our portfol…