Cybersecurity GRC Framework Evaluation

Job ID: 40449276

Budget: ₹1,250 – ₹2,500 INR

I need a seasoned Cyber Security GRC professional to perform a deep-dive evaluation of our existing governance, risk and compliance framework. The goal is to measure how well our current policies, controls and day-to-day practices align with GDPR, ISO 27001 and NIST requirements, then highlight every gap that could expose us to regulatory, operational or reputational risk.

Scope
• Review all documented policies, procedures, control matrices and evidence repositories.
• Interview key stakeholders to validate that written processes match real-world execution.
• Map every applicable control to GDPR, ISO 27001 and NIST, flagging overlaps and conflicts.
• Provide a clear, prioritized remediation roadmap and an executive-level summary that can be shared with leadership and auditors.

Acceptance criteria
1. A concise executive summary (max. 5 pages) that highlights critical findings.
2. A detailed gap analysis spreadsheet or report, clearly referencing GDPR articles, ISO 27001 clauses and NIST controls.
3. A 90-day and 180-day remediation plan with effort estimates and ownership suggestions.
4. Recommendations must be actionable, ranked by risk and effort, and traceable back to your assessment evidence.

Please attach a detailed project proposal outlining your methodology, the artefacts you will deliver, key milestones and any tooling you plan to use (e.g., risk registers, GRC platforms, compliance checklists). Past success stories are welcome, but a well-structured proposal will carry the most weight.