Enterprise Controls Consultant – GRC (2 openings)
Location: Malvern, Pennsylvania
Country: United States
Category: Cybersecurity
Workplace Location: Onsite
Employment Type: Contract
Posted Date: July 23, 2026
Job ID: 649836
Job Description
Location: Philadelphia, PA (Hybrid - Onsite Tuesday-Thursday)
Duration: 12-Month Contract
This position is centered on cybersecurity controls engineering and design--not operational security or incident response.
The successful candidate will be responsible for designing, documenting, and supporting the implementation of cybersecurity controls aligned with industry frameworks including NIST 800-53, NIST CSF, CIS Controls, ISO 27001/27002, COBIT, and internal security standards.
Candidates must be comfortable:
- Designing new cybersecurity controls and modernizing existing control frameworks.
- Translating security policies, regulatory requirements, and technical standards into practical, measurable controls.
- Defining control objectives, implementation guidance, testing procedures, and evidence requirements.
- Working directly with control owners and cross-functional stakeholders to finalize and implement enterprise security controls.
- Building controls that support automation, governance, and Continuous Controls Monitoring (CCM).
This is not a "heads-down" cybersecurity engineering or SOC role. The hiring manager is looking for a senior consultant who can lead control design discussions, influence stakeholders, and build scalable governance frameworks--not simply operate or maintain existing controls.
Position Overview
We are seeking an experienced Technical Consultant - Cybersecurity Governance & Controls to support a large-scale Governance, Risk & Compliance (GRC) Modernization Program. This consultant will play a key role in redesigning and modernizing the organization's cybersecurity control environment by creating standardized, scalable, and measurable security controls.
The ideal candidate has a strong background in Cybersecurity Governance, GRC, Controls Design, Risk Management, Compliance, or Internal Audit, with proven experience transforming control frameworks within highly regulated organizations.
You will partner with Security, Technology, Risk, Compliance, Internal Audit, and business leaders to simplify legacy controls, establish future-state governance, and enable automation and Continuous Controls Monitoring (CCM).
Key Responsibilities- Design, document, and support implementation of cybersecurity controls aligned to NIST 800-53, NIST CSF, CIS Controls, ISO 27001/27002, COBIT, and internal standards.
- Assess current security controls through review of policies, standards, procedures, risk assessments, audit findings, and regulatory requirements.
- Identify control gaps, redundancies, inconsistencies, and opportunities for standardization.
- Translate security policies, regulatory requirements, and risk assessments into practical, measurable, and auditable control designs.
- Define control objectives, ownership, implementation guidance, testing criteria, and evidence requirements.
- Facilitate workshops with Security, Technology, Risk, Compliance, Internal Audit, and business stakeholders to gather requirements and drive consensus.
- Build and enhance enterprise control libraries, taxonomies, and framework mappings.
- Design controls with automation and Continuous Controls Monitoring (CCM) capabilities in mind.
- Partner with GRC modernization teams to improve governance processes, control maturity, and regulatory readiness.
- Identify opportunities to leverage AI, analytics, and automation to strengthen governance and compliance processes.
- 8+ years of experience in Cybersecurity Governance, GRC, Controls Design, Risk Management, Compliance, or Internal Audit.
- Proven experience designing or transforming cybersecurity, technology, or enterprise risk controls.
- Strong experience creating controls aligned to NIST 800-53, NIST CSF, CIS Controls, ISO 27001/27002, or similar frameworks.
- Demonstrated ability to translate security policies, standards, audit findings, and regulatory requirements into effective enterprise controls.
- Experience defining control objectives, testing methodologies, implementation guidance, and evidence requirements.
- Experience collaborating directly with control owners and senior stakeholders to implement new control frameworks.
- Strong understanding of the complete control lifecycle, including design, implementation, testing, monitoring, remediation, and continuous improvement.
- Experience working within highly regulated industries (financial services preferred).
- Excellent communication, facilitation, documentation, and stakeholder management skills.
- Experience supporting enterprise GRC modernization or control transformation initiatives.
- Experience designing controls for Continuous Controls Monitoring (CCM).
- Knowledge of AI Governance or AI Risk Management.
- Experience building enterprise control libraries, taxonomies, and framework mappings.
- Consulting experience with a Big Four or large consulting organization.
- Professional certifications such as CISSP, CISM, CISA, CRISC, CIA, or CPA.
- Experience leveraging automation or AI to improve governance and compliance processes.
#Philadelphia
#Hybrid
#TECH
EEO Statement
The staffing industry has seen an increase in people falsely representing themselves as recruiters to gather personal information from job seekers. For your safety, do not provide sensitive data to anyone you have not spoken with thoroughly, never provide banking information during the application process, and always double check the email address of the Recruiter to ensure it’s from an official Planet domain (@theplanetgroup.com or @launchcg.com) - and not a domain with an alternative extension like .net, .org, or .jobs.
The Planet Group and our companies are equal opportunity employers. It is our practice not to discriminate against any employee or applicant based on any criteria, condition or basis protected by laws or regulations in the locations where we do business. All qualified applicants are encouraged to apply. We celebrate diversity and are committed to providing an environment of mutual respect. We believe that diversity, equity, and inclusion enable us to better meet our mission and values while serving our clients across the globe. If you have a disability or handicap and would like us to accommodate you in any reasonable way, please inform your recruiter, or contact us, so that we can discuss the appropriate alternatives available.
Apply Now
Apply Via
Stay Up To Date With The Latest Jobs.
Similar Jobs
About The Planet Group
The Planet Group is a global professional services firm delivering strategic staffing and advisory solutions. We operate at the intersection of talent and transformation – connecting the right people with the right opportunities in the areas of technology, engineering, accounting & finance, digital marketing, and manufacturing.
As one of the largest staffing companies in the US, we operate with a global reach and a performance-first mindset. We partner with clients to move fast, stay agile, and drive measurable results – building high-impact teams that fuel transformation and growth.