ASAI job platform logo
  1. Home
  2. /Jobs
  3. /Security Engineer Jobs in Gurgaon
  4. /Senior Technical Consultant - Security GRC
TH
Thinkahead

Senior Technical Consultant - Security GRC

Remote (Gurgaon) · Senior · Remote

Good timing - competition is buildingVerified listingPosted 6d ago

Applicants who checked fit first are 3.1× more likely to hear back

Your match scoreCalculated · locked
86Overall
64Skills
97Experience

Your score for this role already exists

ASAI compared this JD against 41 signals - skills, seniority, domain, stack overlap etc. Add a resume and it unlocks in about 30 seconds.

No credit card · 1 tap with Google

What we know about this role

Hiring pulse

MEDIUM

Thinkahead is reviewing applications at a steady pace. Expect a standard response time as they evaluate the current pool.

Apply window

First 72 hours

Window passed - posted 6d ago

Early applicants get seen before the pile builds.

Not a repost

The first time we've seen this listing - it hasn't been closed and reopened.

Skills required

9 listed
Iso/iecCloud InfrastructureInternal ControlsCyber RiskRisk AnalysisCoherent ControlsFramework DesignRAID+1 more
Iso/iecCloud InfrastructureInternal ControlsCyber RiskRisk Analysis

You almost certainly match several of these already. Unlock your skill map to see the matches, the gaps, and what to fix first.

Job description

AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digital transformation.
At AHEAD, we prioritize creating a culture of belonging, where all perspectives and voices are represented, valued, respected, and heard. We create spaces to empower everyone to speak up, make change, and drive the culture at AHEAD.
We are an equal opportunity employer, and do not discriminate based on an individual's race, national origin, color, gender, gender identity, gender expression, sexual orientation, religion, age, disability, marital status, or any other protected characteristic under applicable law, whether actual or perceived.
We embrace all candidates that will contribute to the diversification and enrichment of ideas and perspectives at AHEAD.

This is a senior consulting role, not an internal control-operations seat. You will be sold to clients as a credible authority on security GRC. You diagnose program maturity, design target-state operating models, quantify risk in business terms, and leave behind frameworks, artifacts, and decisions the client can run without you.

You must be highly proficient in English. Client deliverables, findings, board packs, statements of work, and live workshops are held to an executive and audit standard. Fluency is not enough. The bar is precise, concise, defensible professional English under time pressure.

You must be expert in NIST CSF, NIST SP 800-53, NIST SP 800-171, CIS Controls, the Cyber Risk Institute (CRI) Profile, and ISO/IEC 27001, and you must be able to manage and quantify risk—not only score it.

You must also be a consultant: structure ambiguous problems, manage senior stakeholders, run workshops, write commercial-quality deliverables, defend recommendations, and transfer capability to the client team.

Why this role is Senior
You are expected to operate with limited supervision on complex, multi-framework engagements. Typical work includes regulatory or contractual readiness (including CUI / 800-171), CSF or CRI profile builds, ISO 27001 ISMS design or certification support, control rationalization across overlapping frameworks, and quantified risk analysis for boards, CISOs, and risk committees.
You will often be the most senior GRC voice in the room. That means you set the method, hold the quality bar, and say clearly when a control, a score, or a “green” status is not the same thing as acceptable residual risk.

Core Mandate
Own the analytical and advisory quality of assigned GRC workstreams from scoping through readout and knowledge transfer.
Translate overlapping control frameworks into one coherent control and evidence model the client can operate.
Produce risk positions that combine sound qualitative judgment with quantification the business can use.
Run the engagement like a consultant: scope, stakeholders, workshops, issues, deliverables, and next-step decisions.



Responsibilities
Client consulting and engagement leadership
  • Shape problem statements, engagement scope, assumptions, and success criteria with the client sponsor and the account team.
  • Build workplans, RAID logs, and stakeholder maps; keep delivery on quality even when the client’s evidence or ownership is incomplete.
  • Facilitate workshops with CISOs, control owners, internal audit, legal, procurement, and business executives. Drive decisions, not status meetings.
  • Manage resistance, conflicting frameworks, and “we already have a policy” arguments without losing the room or the facts.
  • Write and present deliverables that survive legal, audit, and executive review: current-state assessments, target operating models, control crosswalks, risk registers, quantified scenarios, roadmaps, and board narratives.
  • Coach client staff so the program does not collapse when the engagement ends. Consulting value is transfer, not slide volume.
  • Support pre-sales and scoping when asked: approach, level of effort, risks to delivery, and what “good” looks like for this client.
  • Framework design, assessment, and rationalization
  • Assess and design against NIST CSF (1.1 and/or 2.0): profiles, subcategory outcomes, tiers, and CSF as the executive reporting spine.
  • Assess and tailor NIST SP 800-53 (Rev. 5 preferred): control families, baselines, overlays, common/hybrid/system-specific controls, and assessment procedures.
  • Assess NIST SP 800-171 implementation for CUI: requirement status, 800-171A-style objectives, scoping of CUI flows, POA&Ms, and contractor obligation implications.
  • Apply CIS Controls (v8 preferred) as a prioritized operational control set (IG1–IG3), mapped to CSF and 800-53 rather than run as a second bureaucracy.
  • Interpret and assess the CRI Profile, including diagnostic statements and financial-sector or critical-third-party expectations.
  • Design or uplift an ISO/IEC 27001 ISMS: scope, SoA, risk assessment and treatment, internal audit liaison, management review inputs, and certification or surveillance readiness.
  • Build and maintain crosswalks so one control, one owner, and one evidence package can satisfy multiple frameworks
  • Assurance, evidence, and defensible writing
  • Design test procedures, challenge evidence quality, and write deficiency and residual-risk narratives that are factual and unambiguous.
  • Prepare clients for internal audit, ISO certification bodies, customer assessments, and 800-171 / CRI / CSF inquiries.
  • Produce executive summaries that a non-specialist leader can act on without a decoder.


  • Required qualifications
    Highly proficient written and spoken English at an executive, audit, and client-delivery standard. Grammar, structure, and tone must be consistently professional. You can explain a control failure, a residual-risk position, or a quantified scenario to an engineer, an auditor, and a board member in the register each expects. A writing sample or timed drafting exercise may be required.
    Demonstrated senior consulting or equivalent client-advisory experience: scoping ambiguous problems, facilitating senior workshops, managing difficult stakeholders, producing commercial-quality deliverables, defending recommendations under challenge, and transferring methods to the client. Internal GRC operations experience alone is not sufficient unless you can show the same client-facing muscle.

    Frameworks (all required, with working depth—not acronym familiarity)

  • NIST Cybersecurity Framework
  • NIST SP 800-53
  • NIST SP 800-171
  • CIS Controls
  • CRI Profile
  • ISO/IEC 27001 (working command of 27002 expected)
  • Risk (required)
    End-to-end risk management (identify, analyze, evaluate, treat, accept, monitor) and risk quantification (scenarios, ranges, expected loss or equivalent, explicit assumptions). “High / medium / low” without a method is not qualification.

    Experience and education
    Roughly 5+ years in security GRC, risk, audit, or control assurance, including substantial time in consulting, professional services, or a comparably senior client-advisory capacity. Bachelor’s degree in a relevant field or equivalent experience. Seniority is judged by judgment, writing, and client impact—not title inflation.



    Why AHEAD:
    Through our daily work and internal groups like Moving Women AHEAD and RISE AHEAD, we value and benefit from diversity of people, ideas, experience, and everything in between.
    We fuel growth by stacking our office with top-notch technologies in a multi-million-dollar lab, by encouraging cross department training and development, sponsoring certifications and credentials for continued learning.
    India Employment Benefits include:
    Comprehensive health insurance coverage for employees, with options to extend coverage to dependents
    Paid time off and company holidays, along with additional leave benefits as per policy
    Flexible work arrangements, supporting work-life balance
    Learning and development opportunities to support continuous growth and upskilling
    Employee wellness initiatives and programs focused on physical and mental well-being
    Retirement and statutory benefits in line with India regulations
    Inclusive and people-first culture, with a strong focus on collaboration and ownership

    Free · no signup

    Get tomorrow's jobs before you have to search

    Daily job drops, skill trends and free resources - posted straight to the group. Leave any time.

    Join WhatsAppJoin Telegram

    No spam. Just jobs and resources.

    Why people use ASAI

    Someone shared one job with you. ASAI keeps finding the rest.

    • Scored, not searched. Every role ranked against your actual profile.

    • Alerts as often as hourly. Reach new roles while the pile is still small.

    • Skill gaps, spelled out. See exactly which requirements you don't meet yet.

    • Verified jobs, only. Say no to ghost jobs. Your time deserves respect.

    More Security Engineer roles in Gurgaon

    See all

    Endpoint Security Analyst

    ChargePoint · Remote (Gurgaon)

    Senior Security Engineer

    GLG · Gurgaon

    AVP - IT & Infosec Audit

    SBIC · Gurgaon

    Senior Network Engineer

    Mksinst · Gurgaon

    Keep browsing

    All open roles at ThinkaheadAll Security Engineer jobs in Gurgaon

    Two ways in

    Applicants who checked fit first are 3.1× more likely to hear back

    Your match scoreCalculated · locked
    86Overall
    64Skills
    97Experience

    Your score for this role already exists

    ASAI compared this JD against 41 signals - skills, seniority, domain, stack overlap etc. Add a resume and it unlocks in about 30 seconds.

    No credit card · 1 tap with Google

    Free · no signup

    Get tomorrow's jobs before you have to search

    Daily job drops, skill trends and free resources - posted straight to the group. Leave any time.

    Join WhatsAppJoin Telegram

    No spam. Just jobs and resources.

    Why people use ASAI

    Someone shared one job with you. ASAI keeps finding the rest.

    • Scored, not searched. Every role ranked against your actual profile.

    • Alerts as often as hourly. Reach new roles while the pile is still small.

    • Skill gaps, spelled out. See exactly which requirements you don't meet yet.

    • Verified jobs, only. Say no to ghost jobs. Your time deserves respect.

    ASAI job platform logo

    A job platform finally, balanced in your favour.

    Jobs by CityJobs by CompanyGuidesHow We VerifyAboutPrivacy PolicyTerms of Service

    Built in India 🇮🇳

    © 2026 ASAI. All rights reserved.