GRC Policy & Standards Specialist
Quick Overview
Job Description
Job Description – GRC Policy & Standards Specialist
Experience: 6–10 years
Level: Mid-Level / Senior Consultant
Role: GRC Policy, Standards & Governance Consultant
Role Overview
• We are looking for a strong GRC Policy & Standards Specialist to develop, enhance, and
operationalize enterprise governance documentation across security, technology, risk,
and operational functions.
• The successful candidate will have demonstrated experience developing enterprise
policies, standards, control requirements, procedures, and supporting governance
documentation that are clear, structured, actionable, and aligned with recognized
regulatory and industry frameworks.
• This role requires more than strong writing skills. The individual must understand what
constitutes effective GRC documentation, including appropriate distinctions between
policies, standards, procedures, controls, and guidelines, and be able to translate
complex regulatory, risk, security, technology, and operational requirements into
documentation that can be practically implemented.
• A critical part of the role will be working across organizational boundaries. The
individual must be comfortable engaging with technology, cybersecurity, operations,
risk, compliance, legal, and business stakeholders, reconciling different perspectives,
challenging unclear requirements, and driving documentation through review, approval,
and adoption.
Key Responsibilities
• Lead the development, review, and enhancement of enterprise GRC policies,
standards, procedures, control requirements, and governance documentation.
• Establish consistent documentation structures, terminology, requirements language,
and governance conventions across policies and standards.
• Translate regulatory, risk, security, technology, and business requirements into clear,
enforceable, and operationally practical policy and standards requirements.
• Ensure appropriate distinction and traceability between policy statements, standards
requirements, control objectives, procedures, and supporting guidance.
• Work directly with subject matter experts across technology, cybersecurity, operations,
risk, compliance, legal, privacy, and business functions to develop and validate
requirements.
• Facilitate working sessions and stakeholder reviews to identify requirements, resolve
conflicting requirements, close documentation gaps, and achieve agreement on
governance expectations.
• Convert complex technical requirements into language that can be understood by
business and operational stakeholders while maintaining sufficient specificity for
technology and control owners.
• Ensure policy and standards requirements are written in a manner that is measurable,
auditable, and capable of being translated into controls and operational processes.
• Support the mapping of policies and standards to regulatory obligations, control
frameworks, risks, and enterprise requirements.
• Partner with control owners and operational teams to ensure documented
requirements can be realistically implemented and evidenced.
• Identify gaps between documented requirements and current operational or
technology practices and help define appropriate remediation actions.
Required Experience
• 6–10 years of experience across policy governance, GRC, cybersecurity governance,
compliance, technology and enterprise risk.
• Demonstrated experience authoring and substantially revising enterprise policies and
standards, rather than solely reviewing documentation created by others.
• Strong understanding of what constitutes effective and enforceable GRC and
governance documentation.
• Ability to write requirements that are clear, concise, enforceable, testable, and
appropriately prescriptive.
• Strong understanding of GRC concepts including risk management, control design,
compliance, assurance, issue management, exceptions, and governance oversight.
• Ability to understand technical concepts and work effectively with technology,
architecture, engineering, cybersecurity, and IT operations teams without needing to be
a hands-on engineer.
• Ability to work with operational and business stakeholders to understand processes,
identify practical requirement gaps, and ensure governance requirements are usable
outside of GRC.
• Experience translating regulatory, framework, security, or risk requirements into
enterprise policy, standards, and control language.
• Strong stakeholder management skills, including the ability to facilitate discussions
involving management-level+ stakeholders.
• Excellent written communication, editing, analytical, and information-structuring skills.
• Strong attention to detail and ability to identify ambiguous language, inconsistent
requirements, documentation gaps, and conflicting governance expectations.
• Confidence working directly with senior leaders, subject matter experts, control
owners, and second-line risk and compliance functions.
Preferred Experience
Experience with several of the following would be valuable:
• NIST CSF / NIST 800-series
• ISO/IEC 27001 and 27002
• ISO/IEC 42001
• NIST AI RMF
• SOC 2
• Privacy and data governance frameworks
• Third-party risk management
• Secure software development and technology governance
• Cloud and infrastructure security standards
• AI and emerging technology governance
• Regulatory compliance frameworks
• GRC platforms and policy management tools
Most Important Profile
• We are not looking for a technical writer who simply documents information provided
by subject matter experts, nor are we looking for a purely technical security or
engineering resource.
• We need someone who understands governance, risk, controls, and enterprise policy
architecture and can independently determine what strong policy and standards
documentation should look like.
• The ideal candidate can sit with a cybersecurity architect, technology leader,
operational process owner, risk professional, or compliance SME; understand their
requirements; challenge ambiguity or impractical expectations; and translate those
discussions into clear, defensible, implementable, and auditable enterprise
requirements.
• Strong candidates should be able to operate as both a governance subject matter
expert and a skilled policy author, while effectively navigating stakeholders across
business, operations, risk, security, and technology
Skills
Similar jobs
End-to-End Space Systems Engineers (Experienced, Lead or Senior) with Security Clearance
Boeing · El Segundo, United States
2 minutes ago$119.8k - $162.2k/yrRF SIGINT Analyst
Vantor · Reston, United States
15 minutes agoRF SIGINT Technical Analyst
Vantor · Reston, United States
15 minutes agoSenior Distinguished Engineer, AI Compute (Remote Eligible)
Capital One · Mc Lean, United States
18 minutes ago$314.8k - $359.3k/yrCatalog Compiler - Part-Time
Lane Automotive · Watervliet, United States
18 minutes agoSenior Distinguished Engineer, AI Compute (Remote Eligible)
Capital One · Richmond, United States
18 minutes ago$314.8k - $359.3k/yr