
Senior GRC Consultant – Contract
Posted 5 days ago

Posted 5 days ago
This is a fully remote position, open to applicants in India.
• Take charge of delivery for standard-framework projects, which includes ISO 27001 implementation and ongoing surveillance, SOC 2 Type I/II readiness, GDPR and PCI DSS compliance programs, gap assessments, control/check mapping, internal audits, policy reviews, and audit-readiness assistance.
• Manage multiple client engagements simultaneously, ensuring a consistent quality standard without needing close supervision.
• Update and enhance templates, control-mapping libraries, workshop agendas, and quality assurance rubrics for standard frameworks.
• Keep framework documentation up to date as standards and guidelines evolve.
• Expand the library to cover related frameworks such as HIPAA, PCI DSS, and ISO 42001 as demand increases.
• Establish pricing and packaging strategies for standard-framework engagements.
• Oversee utilization, margin, and delivery forecasting for the engagement portfolio.
• Collaborate with Sales, SE, and CS teams to attach and renew standard-framework services while supporting technical deal validation.
• Develop and maintain AI-assisted playbooks for gap assessments, control mapping, and internal audit checklists.
• Create structured input forms and checklists to ensure consistent first-draft outputs from junior staff or AI-assisted workflows.
• Set quality assurance guardrails, including required source inputs, validation steps, and human approval gateways.
• Define acceptance criteria and establish review checkpoints for deliverables.
• Identify scope creep early and escalate any ambiguous liability issues.
• Act as the internal expert for ISO 27001, SOC 2, GDPR, and PCI DSS maturity inquiries across Sales, SE, and CS.
• Achieve success metrics related to utilization, gross margin, QA pass rate, rework rate, deliverable cycle time, CSAT, service attach rate, and playbook reuse rate.
• Minimum of 5 years of experience in GRC/security consulting or managing in-house compliance programs.
• Proven track record of hands-on delivery in ISO 27001, SOC 2, and GDPR at a minimum.
• Ability to manage several client engagements concurrently.
• In-depth knowledge of ISO 27001 and SOC 2 Type I/II.
• Comprehensive understanding of GDPR.
• Familiarity with PCI DSS, HIPAA, ISO 42001, etc., is a plus.
• Demonstrated experience using AI tools to streamline manual tasks and standardize deliverables.
• Capability to translate domain expertise into reusable templates and guided systems.
• Proficiency in managing pricing/packaging, margin, and utilization for an engagement portfolio.
• Excellent written communication skills.
• Confidence in independently facilitating client workshops.
• Sound judgment in ambiguous situations and ability to manage scope creep effectively.
• ISO 27001 LA/LI, CISA, or CISM certifications preferred.
• Availability to join immediately.
• Flexible remote work arrangements.
• Inclusive and accessible hiring process.
• Opportunity to engage with AI-driven automation and productization.
• Chance to develop reusable intellectual property and guided systems.
• Six-month contract engagement.
TAG IMF
Neogen Corporation
Parexel
Stone & Company
Get handpicked remote jobs straight to your inbox weekly.