
GRC Consultant β Compliance, Audit Readiness
Posted 21 hours ago

Posted 21 hours ago
This is a fully remote position, open to applicants in India.
β’ Take charge of the audit process for a designated portfolio of global clients, overseeing everything from gap assessment and readiness to external audit fieldwork, resolution of findings, and finalization.
β’ Evaluate security controls, cloud environments, organizational policies, and operational practices to pinpoint deficiencies.
β’ Collaborate with Engineering, IT, DevOps, and leadership teams to create practical, risk-based remediation plans.
β’ Review evidence for its relevance, completeness, and consistency prior to submission, and maintain an audit-ready documentation trail.
β’ Act as a liaison between clients and independent auditors, facilitating requests and clarifying control operations.
β’ Monitor evidence requests, dependencies, exceptions, and delivery risks; communicate updates and escalate any obstacles.
β’ Assist clients through SOC 2 Type I and Type II examinations and ISO/IEC 27001 audits, with exposure to ISO/IEC 27701, HIPAA, GDPR, and PCI DSS as applicable.
β’ Adapt to working across EU and US hours to support international clients and audit firms during critical engagement periods.
β’ Enhance reusable playbooks, evidence guidance, and audit workflows for the Central Audits Team.
β’ 2β5 years of pertinent experience in information security, IT audit, compliance consulting, or a similar customer-facing advisory role.
β’ Strong understanding of SOC 2 Type I and Type II and ISO/IEC 27001, encompassing control design, evidence expectations, readiness, and external audit processes.
β’ Hands-on experience in participating, coordinating, or supporting third-party security audits and addressing auditor inquiries or findings.
β’ Familiarity with AWS, GCP, or Azure; SaaS architectures; identity and access management; and technical control evaluation.
β’ Capability to differentiate between documentation gaps and control-design or operational effectiveness gaps, driving suitable remediation actions.
β’ Excellent written and verbal communication skills with technical teams, executives, clients, and external auditors.
β’ Strong organizational skills and follow-through across multiple parallel engagements and time-sensitive evidence requests.
β’ Willingness to work flexible hours across EU and US time zones.
β’ CISA, CISM, CISSP, ISO/IEC 27001 Lead Auditor or Lead Implementer, or a relevant privacy credential is a plus.
β’ Experience with a compliance automation platform, cybersecurity consultancy, or a rapidly scaling B2B SaaS company that serves international clients is advantageous.
β’ 100% remote work.
β’ Annual co-working allowance.
β’ USD 1,000 annual budget for learning and professional development.
β’ Unlimited leave.
β’ Health insurance coverage up to INR 10 lakh for the employee and family.
β’ Additional accident protection of INR 10 lakh.
β’ Life insurance valued at 3x the annual salary.
β’ INR 35,000 workspace setup allowance.
IRIUM
Centene Corporation
Triumph Enterprises, Inc.
Get handpicked remote jobs straight to your inbox weekly.