
Senior GRC Consultant – Standard Frameworks
Posted Jul 19

Posted Jul 19
This is a fully remote position, open to applicants in India.
• Take charge of delivering standard-framework engagements, including ISO 27001 (implementation & surveillance), SOC 2 Type I/II readiness, GDPR, PCI DSS compliance programs, gap assessments, control/check mapping, internal audits, policy reviews, and audit readiness support.
• Manage multiple simultaneous client engagements to maintain a consistent level of quality without requiring close supervision.
• Update and enhance templates, control-mapping libraries, workshop agendas, and QA rubrics for standard frameworks; ensure they remain current as frameworks are revised (including ISO 27001:2022 transition updates, SOC 2 trust criteria changes, and GDPR enforcement guidance).
• Expand the library to include adjacent frameworks (such as HIPAA, PCI DSS, and ISO 42001) as demand increases.
• Establish pricing and packaging for standard-framework engagements (including fixed-fee tiers and retainer options).
• Oversee utilization, margin, and delivery forecasting for your own portfolio of engagements.
• Collaborate with Sales, SE, and CS teams to attach and renew standard-framework services; assist in deal conversion when technical validation is required.
• Develop and maintain AI-assisted playbooks for standard frameworks (including gap assessment, control mapping, and internal audit checklists).
• Create structured input forms and checklists to ensure that juniors or AI-assisted workflows generate consistent first-draft outputs.
• Set QA guardrails, including mandatory source inputs, validation steps, and human approval gates.
• Define acceptance criteria and review checkpoints for deliverables.
• Identify scope creep early; escalate ambiguous liability issues instead of absorbing them quietly.
• A minimum of 5 years of experience in GRC/security consulting or managing in-house compliance programs.
• Proven hands-on delivery experience with ISO 27001, SOC 2, and GDPR at a minimum.
• Comfortable managing several concurrent client engagements.
• In-depth knowledge of ISO 27001, SOC 2 Type I/II, and GDPR.
• Familiarity with additional frameworks (preferably PCI DSS, HIPAA, ISO 42001, etc.) is a plus.
• Proven ability to utilize AI tools to minimize manual effort and standardize deliverables.
• Capable of translating domain expertise into reusable templates and guided systems.
• Ability to manage pricing, packaging, margin, and utilization for your engagements independently.
• Excellent written communication skills; comfortable leading client workshops independently.
• Strong judgment in ambiguous situations, with a focus on avoiding scope creep.
• Preferred qualifications: ISO 27001 LA/LI, CISA, or CISM certifications.
• Work from anywhere: We are fully remote, allowing you to choose your workspace, whether it's home, a café, the hills, or the beach.
• Co-working, on us: If you enjoy co-working, we provide a generous annual allowance.
• Commitment to your growth: We are dedicated to your development and allocate USD 1,000 annually to help you enhance your skills.
• Focus on your well-being: Enjoy unlimited leave so you can recharge when needed.
• Comprehensive safety net: Health insurance coverage up to INR 10 lakh for you and your family, with an additional INR 10 lakh for accident protection, and life insurance worth 3x your annual salary.
• Ideal workspace setup: We contribute INR 35,000 to help you create a workspace that suits your needs.
ZoomInfo
Lifelancer
unybrands
Get handpicked remote jobs straight to your inbox weekly.