Enterprise Controls Consultant – GRC (2 openings)
Location: Malvern, Pennsylvania
Country: United States
Category: Cybersecurity
Workplace Location: Onsite
Employment Type: Contract
Posted Date: August 12, 2026
Job ID: 649836
Job Description
Senior Cybersecurity GRC Consultant - Controls Design & Transformation
Greater Philadelphia area
Hybrid ( three days a week onsite)
$75-$95/hour
The Planet Group has partnered with a Greater Philadelphia area company to locate an Senior Cybersecurity GRC Consultant to support a large-scale enterprise Governance, Risk & Compliance (GRC) modernization initiative.
Candidates must have direct, hands-on experience designing and developing cybersecurity controls. This should include translating cybersecurity risks, policies, standards, and framework requirements into technically meaningful controls that can be implemented by security and technology teams.
We are specifically seeking experience designing controls across cybersecurity domains such as Identity & Access Management (IAM), privileged access, vulnerability management, network security, endpoint security, cloud security, data protection, security logging/monitoring, encryption, secure configuration, or incident response.
Experience primarily focused on control testing, audit execution, evidence collection, compliance assessments, risk assessments, or general GRC activities without direct cybersecurity control design experience will not meet the requirements of this role.
Responsibilities:
- Assess existing cybersecurity and technology controls against policies, standards, risk requirements, audit findings, and regulatory expectations.
- Design and document new and enhanced security controls aligned with frameworks such as NIST 800-53, NIST CSF, CIS Controls, ISO 27001/27002, and COBIT.
- Translate security policies, standards, regulatory requirements, and identified risks into practical, technically sound controls.
- Define clear control objectives, ownership, implementation guidance, testing criteria, monitoring requirements, and evidence requirements.
- Identify redundant, outdated, inconsistent, or overly complex controls and recommend opportunities for consolidation and standardization.
- Partner directly with cybersecurity and technology control owners to validate control design and support implementation.
- Develop and enhance enterprise control libraries, control taxonomies, and mappings across multiple security and regulatory frameworks.
- Facilitate working sessions with Security, Technology, Risk, Compliance, Internal Audit, and business stakeholders to gather requirements and drive agreement on future-state controls.
- Design controls with scalability, automation, and Continuous Controls Monitoring (CCM) in mind.
- Identify opportunities to use automation, analytics, and emerging AI capabilities to improve control monitoring and governance.
- Support broader GRC modernization efforts focused on improving control maturity, governance, regulatory readiness, and operational efficiency.
- 8+ years of experience in cybersecurity governance, GRC, technology risk, controls engineering/design, compliance, internal audit, or a closely related discipline.
- Demonstrated experience designing, developing, modernizing, or transforming cybersecurity or technology controls.
- Strong understanding of the complete control lifecycle, including control design, implementation, testing, evidence collection, monitoring, remediation, and continuous improvement.
- Hands-on experience working with recognized cybersecurity and governance frameworks such as NIST 800-53, NIST CSF, CIS Controls, ISO 27001/27002, and/or COBIT.
- Experience translating policies, technical standards, risk assessments, regulatory requirements, and audit findings into clearly defined and implementable controls.
- Sufficient technical cybersecurity knowledge to collaborate effectively with security engineers, architects, and technology control owners and understand how controls are implemented within enterprise environments.
- Experience working within a large, complex, highly regulated organization; financial services experience is strongly preferred.
- Strong experience facilitating workshops and working across Security, Technology, Risk, Compliance, Audit, and business organizations.
- Excellent written communication and documentation skills, with the ability to turn complex security and regulatory requirements into clear, measurable control language.
- Experience with enterprise-wide GRC modernization, control transformation, or control rationalization initiatives.
- Experience developing enterprise control libraries, taxonomies, and cross-framework mappings.
- Experience designing controls to support Continuous Controls Monitoring (CCM) or automated control testing.
- Financial services, banking, insurance, or other highly regulated industry experience.
- Consulting or advisory experience within a Big Four or other large consulting organization.
- Experience incorporating automation, analytics, or AI into governance, risk, and compliance processes.
- Familiarity with AI governance, AI risk management, or emerging AI regulatory requirements.
- Relevant professional certifications such as CISSP, CISM, CISA, CRISC, CIA, or CPA.
#LI-SC1
#TECH
#Hybrid
EEO Statement
The staffing industry has seen an increase in people falsely representing themselves as recruiters to gather personal information from job seekers. For your safety, do not provide sensitive data to anyone you have not spoken with thoroughly, never provide banking information during the application process, and always double check the email address of the Recruiter to ensure it’s from an official Planet domain (@theplanetgroup.com or @launchcg.com) - and not a domain with an alternative extension like .net, .org, or .jobs.
The Planet Group and our companies are equal opportunity employers. It is our practice not to discriminate against any employee or applicant based on any criteria, condition or basis protected by laws or regulations in the locations where we do business. All qualified applicants are encouraged to apply. We celebrate diversity and are committed to providing an environment of mutual respect. We believe that diversity, equity, and inclusion enable us to better meet our mission and values while serving our clients across the globe. If you have a disability or handicap and would like us to accommodate you in any reasonable way, please inform your recruiter, or contact us, so that we can discuss the appropriate alternatives available.
Apply Now
Apply Via
Stay Up To Date With The Latest Jobs.
Similar Jobs
About The Planet Group
The Planet Group is a global professional services firm delivering strategic staffing and advisory solutions. We operate at the intersection of talent and transformation – connecting the right people with the right opportunities in the areas of technology, engineering, accounting & finance, digital marketing, and manufacturing.
As one of the largest staffing companies in the US, we operate with a global reach and a performance-first mindset. We partner with clients to move fast, stay agile, and drive measurable results – building high-impact teams that fuel transformation and growth.