Cybersecurity GRC Professional at duvari group
—
Jul 20, 2026
—
Jul 22, 2026
What this job asks for AI summary
A senior consulting role focused on governance, risk, and compliance work for both government and commercial clients. Day-to-day responsibilities include leading risk assessments, gap analyses, policy development, and audit readiness efforts across frameworks such as SOC 2, ISO 27001, CMMC, NIST CSF, and HIPAA. The role suits an experienced GRC professional comfortable advising both executive and technical stakeholders across regulated industries.
Senior level · Remote · Contract
“or” means any one of them counts — you don't need all of them.
Posted 2 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 12,600 people nationally plausibly meet what this posting asks for (information security analysts). range 7,600–22,800
Applicant volume Heavy — This req sits in a large pool with little in its requirements to thin it, and auto-apply tools fire at everything in the occupation. Applying early and leading with the rare skills below is what gets read.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (6)
The posting requires experience with 'one or more' of SOC 2, ISO 27001, CMMC, NIST CSF, or HIPAA — these are listed as interchangeable gates on a single requirement. SOC 2 is captured as the primary with the others as alternatives; all five are also listed individually as preferred since any one of them satisfies the gate and deeper familiarity with the others is clearly valued.
No specific years of experience are stated at the role or skill level.
Location is described as 'Remote/Hybrid' with no specific metro or state identified.
Experience supporting regulated industries (government, healthcare, defense, financial services) is explicitly called 'a plus' — no specific technology or tool is named, so it is omitted per the generic-concept rule.
No compensation figures are provided.
Posting is for a contract engagement — the market benchmarks below price full-time roles, so read the comp comparison with that in mind.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.