ScaleUpremote

Salary
Posted
Jul 6, 2026
Location
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A senior-level GRC consulting role managing compliance and risk programs across multiple client engagements simultaneously. Day-to-day work covers audit readiness, gap analysis, risk assessments, policy development, and control framework implementation across standards such as SOC 2, ISO 27001, HIPAA, and GDPR, using platforms like Vanta or Drata. The position suits an experienced GRC or compliance professional with a consulting background who is comfortable owning client relationships and working independently.

Senior level · 5+ years · Remote · Contract

Must have (8)
SOC 2ISO 27001HIPAA, GDPR, Ccpa or CpraGRC platforms, Vanta or DrataNIST 800-30Cloud securityIAMCI/CD
Nice to have (2)
ISO 42001CISA, Cism or Crisc

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 5,200 people nationally plausibly meet what this posting asks for (information security analysts). range 1,550–9,400

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
IAM45%CI/CD45%Cloud security42%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (12)

The JD states '5–7+ years' of GRC/compliance/information security experience; the overall years minimum is set to 5 (the lower bound of the stated range).

Employment type is Contract (long-term contractor), as explicitly stated in the posting.

No compensation figures are provided in the posting.

GRC platforms are listed as 'Vanta, Drata, or similar' in the responsibilities section — treated as a hard gate on the capability, with Vanta and Drata captured as the named alternatives.

HIPAA is listed as a required framework alongside SOC 2 and ISO 27001; GDPR, CCPA/CPRA are listed as 'one or more additional frameworks such as…' — treated as a hard gate on at least one of these, with the named options as alternatives.

GDPR hands-on implementation experience is separately called out under 'Nice to Have' and is also captured there as a preferred skill.

Certifications (CISA, CISM, CRISC, ISO 27001 Lead Auditor/Implementer) appear under 'Nice to Have' and are marked preferred.

ISO 42001 (AI Management Systems) appears under 'Nice to Have' and is marked preferred.

No metro is set per caller instruction; role is fully remote within U.S. business hours.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): ISO 27001 Lead Auditor.

Posting is for a contract engagement — the market benchmarks below price full-time roles, so read the comp comparison with that in mind.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗