GRC Consultant – Compliance & Audit Readiness
NewBe an early applicantSummary
A GRC consultant based in India (100% remote) who owns end-to-end audit journeys for global customers — running gap assessments, readiness, fieldwork, and remediation for SOC 2 and ISO/IEC 27001 audits — acting as the bridge between customers and independent auditors across cloud environments, with flexible EU/US working hours.
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a GRC Consultant – Compliance & Audit Readiness based in India.
This role is focused on helping global customers strengthen their security and compliance posture and successfully navigate external audits. You will own audit journeys from initial gap assessments and readiness through fieldwork, remediation, and final closure. Acting as a trusted bridge between customers and independent auditors, you will translate compliance requirements into practical, risk-based actions. The position combines security, IT audit, compliance advisory, and customer-facing work across international engagements. You will assess technical and organizational controls, strengthen evidence readiness, and coordinate stakeholders through time-sensitive audit activities. The role also offers an opportunity to improve scalable audit practices and playbooks within a collaborative, remote-first environment.
Accountabilities:
- Own the end-to-end audit journey for an assigned portfolio of global customers, from gap assessment and readiness through external audit fieldwork, findings remediation, and closure.
- Assess security controls, cloud environments, organizational policies, and operating practices to identify control, evidence, documentation, and implementation gaps early.
- Translate identified gaps into practical, risk-based remediation plans and coordinate with Engineering, IT, DevOps, and leadership teams to drive timely resolution.
- Review audit evidence for relevance, completeness, and consistency before submission while maintaining a clear and audit-ready trail of requests, responses, decisions, and supporting documentation.
- Serve as a coordination point between customers and independent auditors by facilitating requests, clarifying how controls operate, and helping teams respond accurately while preserving auditor independence.
- Track evidence requests, dependencies, exceptions, and delivery risks across multiple engagements, communicating progress clearly and escalating blockers before they impact audit timelines.
- Guide customers through SOC 2 Type I and Type II examinations and ISO/IEC 27001 audits, with exposure to ISO/IEC 27701, HIPAA, GDPR, and PCI DSS where relevant.
- Work flexibly across EU and US working hours to support international customers and audit firms during critical and time-sensitive stages of engagements.
- Identify recurring audit challenges and contribute to reusable playbooks, evidence guidance, and scalable workflows that improve the effectiveness of future engagements.
- Bring 2–5 years of relevant experience in information security, IT audit, compliance consulting, or a closely related customer-facing advisory role, with candidates bringing deeper experience also encouraged to apply.
- Have strong working knowledge of SOC 2 Type I and Type II and ISO/IEC 27001, including control design, evidence expectations, readiness activities, and external audit workflows.
- Demonstrate direct experience participating in, coordinating, or supporting third-party security audits and responding to auditor requests, observations, or findings.
- Be comfortable with AWS, GCP, or Azure environments, SaaS architectures, identity and access management, and the technical context required to assess how security controls operate.
- Be a practical problem-solver who can distinguish documentation gaps from control-design or operating-effectiveness issues and determine the appropriate remediation approach.
- Demonstrate clear written and verbal communication, with the judgment to align technical teams, executives, customers, and external auditors around facts, ownership, risks, and next steps.
- Have strong organizational skills and follow-through, with the ability to manage multiple parallel engagements, changing priorities, and time-sensitive evidence requests.
- Be willing to work flexibly across EU and US working hours to support international customers and audit partners.
- Certifications such as CISA, CISM, CISSP, ISO/IEC 27001 Lead Auditor or Lead Implementer, or a relevant privacy credential are a plus.
- Experience with a compliance automation platform, cybersecurity consultancy, or fast-scaling B2B SaaS company supporting international customers is also desirable.
- 100% remote work, with the flexibility to work from wherever you are most productive.
- Generous annual co-working allowance for employees who prefer a dedicated shared workspace.
- USD 1,000 annual learning and development allowance to support professional growth and skill development.
- Unlimited leave to support flexibility, rest, and personal well-being.
- Health insurance coverage of up to INR 10 lakh for you and your family.
- Additional accident protection of INR 10 lakh and life insurance coverage equivalent to 3x your annual salary.
- INR 35,000 contribution toward setting up a comfortable and effective home workspace.
- Opportunity to work with international customers and independent auditors across global compliance and security frameworks.
- Exposure to SOC 2, ISO/IEC 27001, privacy, healthcare, payment, and other evolving compliance requirements.
- Inclusive and accessible work environment where talent, curiosity, ownership, and impact are valued.
Requirements:
Benefits:
As published by lever
Resume/CV, Full name, Email, Phone, Current location, Current company