AI GRC Consulting Partner
Near Shore Cyber
—
Jul 19, 2026
—
Jul 21, 2026
What this job asks for AI summary
This posting recruits experienced GRC and cybersecurity consultants into a six-month unpaid development programme, after which graduates join a non-exclusive virtual bench for potential paid client engagements in AI governance, risk, and compliance. Day-to-day bench work centers on leading AI governance assessments, applying frameworks such as NIST AI RMF and ISO/IEC 42001, advising executives on AI risk, and producing policies, control libraries, and remediation roadmaps. The role suits senior practitioners with a decade of IT/cybersecurity experience, at least five years of client-facing GRC consulting, and active CISA and ISO/IEC 27001 credentials — bench membership carries no guarantee of assignments or hours.
Senior level · 10+ years · Remote · Contract
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (12)
This posting describes a non-exclusive consultant bench membership, not a traditional employment engagement. Bench participation is explicitly stated to not be employment and does not guarantee assignments or hours; paid client work is governed by separate written agreements. 'Contract' is the closest employment-type classification.
Compensation is not disclosed in the posting; rates are stated to be set per engagement and disclosed before acceptance.
The role requires a minimum of 10 years in IT/cybersecurity overall and at least 5 years of client-facing GRC consulting experience. The 10-year figure is used as the overall years minimum as it is the broader role-level gate.
Two certifications are hard-gated for admission: ISACA CISA and an ISO/IEC 27001 Implementer or Lead Implementer credential. Both are listed under 'Required certifications.'
The posting covers two parallel opportunities — one for US-based candidates and one for Mexico-based candidates. This extraction covers the US-based (United States Remote) role as the primary posting. The Mexico variant is substantively identical in requirements.
IAPP AIGP, PCI QSA, and PMP are listed under 'Preferred qualifications' and are not extracted as required skills.
ServiceNow GRC is listed as an example enterprise GRC platform alongside Archer, LogicGate, and Drata — all are preferred, not required. Alternatives are populated with the other named platforms.
Python, Microsoft Purview, and cloud AI platforms appear together under a single preferred bullet; Python and Microsoft Purview are extracted separately as preferred skills. 'Cloud AI platforms' is too generic to name as a canonical tool.
SOC confidence is Medium: the role is a GRC/AI governance consulting role that sits at the intersection of information security analysis (15-1212) and a broader advisory/compliance occupation (15-1299). Day-to-day work most closely resembles information security analysis and risk/compliance advisory.
Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-53, ISO/IEC 27001 Lead Implementer.
Posting is for a contract engagement — the market benchmarks below price full-time roles, so read the comp comparison with that in mind.
Caller marked this a fully-remote role — scored against the national candidate pool.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.