We are sharing a specialised part-time consulting opportunity for experienced cybersecurity and IT governance, risk, and compliance professionals with strong expertise in information security, IT risk, governance, controls, compliance, and professional security work-product review.
This role focuses on reviewing professional documents, spreadsheets, and presentation materials related to cybersecurity and IT GRC. Selected experts will assess outputs for technical accuracy, risk and control quality, analytical rigour, practical relevance, presentation effectiveness, and overall professional credibility.
Key Responsibilities
Cybersecurity Review
-
Evaluate cybersecurity-related work products for accuracy, completeness, and professional quality
-
Assess whether security analyses and recommendations reflect sound professional judgement
-
Identify factual errors, unsupported assumptions, and gaps in security reasoning
-
Review materials involving information security, technology risk, and organisational controls
-
Apply professional judgement grounded in real-world cybersecurity experience
IT Governance, Risk & Compliance
-
Review governance, risk, and compliance materials related to technology environments
-
Assess whether risks, controls, responsibilities, and recommendations are clearly defined
-
Evaluate the consistency and practical soundness of GRC approaches
-
Identify gaps in governance, accountability, or compliance processes
-
Review whether recommendations appropriately address identified technology risks
IT Risk Assessment
-
Evaluate technology risk assessments and supporting analyses
-
Review risk identification, prioritisation, impact, and supporting rationale
-
Assess whether conclusions are appropriately supported by available information
-
Identify overlooked risks, weak assumptions, or incomplete analyses
-
Evaluate proposed risk responses for practical relevance and consistency
Security Controls & Compliance
-
Review materials involving cybersecurity controls, policies, procedures, and compliance requirements
-
Assess whether controls appropriately address identified risks
-
Identify gaps in control design, documentation, or implementation logic
-
Evaluate compliance-related findings and recommendations
-
Distinguish substantive security or control issues from minor documentation concerns
IT Audit & Assurance
-
Evaluate IT audit-related documentation, findings, and supporting evidence
-
Assess whether conclusions are adequately supported by the underlying information
-
Review control observations, identified deficiencies, and remediation recommendations
-
Identify inconsistencies or gaps in audit-support materials
-
Evaluate whether findings are communicated clearly and professionally
Security & Risk Analysis
-
Review spreadsheets and analyses supporting cybersecurity and GRC decisions
-
Assess calculations, assumptions, risk metrics, and supporting information
-
Evaluate whether underlying data supports stated findings and recommendations
-
Identify analytical inconsistencies or unsupported conclusions
-
Review quantitative and qualitative analyses for clarity and decision usefulness
Documents & Presentation Review
-
Evaluate cybersecurity reports, GRC documents, spreadsheets, and slide decks for accuracy and completeness
-
Review presentations for logical flow, clarity, and professional quality
-
Identify factual, technical, analytical, aesthetic, and formatting issues
-
Assess whether charts, tables, and visuals accurately represent underlying information
-
Ensure findings and recommendations are clearly connected to supporting evidence
Structured Evaluation & Feedback
-
Assess assigned outputs against domain-specific quality criteria
-
Identify cybersecurity, risk, compliance, analytical, factual, and presentation weaknesses
-
Distinguish substantive security issues from minor editorial concerns
-
Provide clear, structured written feedback explaining identified strengths and weaknesses
-
Apply evaluation standards consistently across different cybersecurity and IT GRC work products
Ideal Profile
-
5+ years of relevant professional experience in cybersecurity, IT GRC, information security, IT risk, IT audit, or a closely related field
-
Experience as a GRC Analyst, IT Risk Analyst, Cybersecurity Analyst, Information Security Analyst, IT Auditor, or similar professional
-
Strong practical understanding of cybersecurity and IT governance, risk, and compliance
-
Experience developing or reviewing security assessments, risk analyses, control documentation, audit materials, or related work products
-
Ability to evaluate cybersecurity and GRC recommendations for accuracy, risk relevance, and practical feasibility
-
Strong analytical judgement and attention to security, governance, risk, and compliance detail
-
Highly proficient with Microsoft Office and Google Workspace
-
Advanced proficiency with PowerPoint / Google Slides
-
Strong spreadsheet and analytical skills
-
Native or professional fluency in English
-
Excellent written communication and ability to provide precise, structured feedback
-
Master's degree or higher from a recognised institution is advantageous
Engagement Details
-
Part-time independent contractor engagement
-
Fully remote
-
Flexible scheduling based on project requirements
-
Compensation: $70–$110/hour
-
Work includes evaluation of cybersecurity and IT GRC documents, risk analyses, control materials, spreadsheets, reports, and presentation materials
-
Projects may be extended, shortened, or concluded based on project needs and performance
-
Work must be completed without using confidential or proprietary information belonging to any employer, client, institution, or other third party
-
H1-B and STEM OPT support is unavailable for this engagement
About the Platform
This opportunity is available through 24-MAG LLC. We connect experienced professionals with remote consulting opportunities across technical, evaluation, and project-based workstreams.
By submitting this application, you acknowledge that your information may be processed by 24-MAG LLC for recruitment and opportunity matching in accordance with our Privacy Policy: https://www.24-mag.com/privacy-policy.