-
Own end-to-end delivery for standard-framework engagements, including ISO 27001 implementation and surveillance, SOC 2 Type I/II readiness, GDPR programs, PCI DSS compliance, gap assessments, control mapping, internal audits, policy reviews, and audit-readiness support.
-
Manage multiple concurrent client engagements independently while maintaining consistent quality, timelines, and client satisfaction.
-
Maintain and continuously improve reusable GRC assets, including templates, control-mapping libraries, workshop agendas, delivery playbooks, and quality-assurance rubrics.
-
Keep methodologies and supporting materials aligned with evolving regulatory and framework requirements, including updates to ISO 27001, SOC 2, and GDPR guidance.
-
Expand reusable frameworks and methodologies into adjacent areas such as HIPAA, PCI DSS, and ISO 42001 as client demand develops.
-
Contribute to commercial outcomes by defining pricing and packaging models for standard-framework services, including fixed-fee and retainer options.
-
Manage utilization, delivery forecasting, and margins across assigned engagements while supporting sustainable client relationships.
-
Partner with Sales, Solution Engineering, and Customer Success teams to support deal conversion, service attachment, renewals, and technical validation.
-
Develop and maintain AI-assisted workflows for gap assessments, control mapping, internal audit checklists, and other recurring GRC activities.
-
Establish structured inputs, validation processes, quality controls, and human approval checkpoints to ensure AI-assisted deliverables remain accurate and reliable.
-
Define acceptance criteria and review checkpoints for client deliverables, identify scope creep early, and escalate ambiguous liability or risk issues appropriately.
-
Track delivery performance through metrics such as utilization, gross margin, QA pass rates, rework, delivery cycle time, customer satisfaction, service attachment, and playbook reuse.
Requirements
-
5+ years of experience in GRC, security consulting, risk, compliance, or ownership of an internal compliance program.
-
Proven hands-on delivery experience across ISO 27001, SOC 2 Type I/II, and GDPR.
-
Strong working knowledge of compliance frameworks, controls, risk management, audit preparation, policy development, and regulatory requirements.
-
Experience managing several client engagements simultaneously while working independently and maintaining a consistently high delivery standard.
-
Demonstrated ability to use AI tools to reduce manual work, improve consistency, and accelerate GRC deliverables.
-
Ability to translate subject-matter expertise into reusable templates, playbooks, guided workflows, and structured systems.
-
Strong commercial awareness, with the ability to manage pricing, packaging, utilization, margins, and delivery forecasting for an assigned portfolio.
-
Excellent written and verbal communication skills, with confidence facilitating client workshops and presenting recommendations independently.
-
Strong judgment and problem-solving skills, particularly when navigating ambiguity, scope changes, and complex compliance questions.
-
Ability to identify potential risks early, establish appropriate quality controls, and escalate issues when necessary.
-
Working knowledge of PCI DSS, HIPAA, ISO 42001, or related frameworks is an advantage.
-
Certifications such as ISO 27001 Lead Auditor/Lead Implementer, CISA, or CISM are preferred.
-
This is a six-month contract position and candidates should be available to join immediately.
-
Comfortable working remotely with a high degree of ownership, written communication, collaboration, and accountability.
Benefits
-
Fully remote working arrangement within India.
-
Six-month contract opportunity with the potential to make an immediate impact.
-
High degree of autonomy and ownership over client engagements and delivery outcomes.
-
Opportunity to work across multiple international GRC and compliance engagements.
-
Exposure to leading frameworks including ISO 27001, SOC 2, GDPR, PCI DSS, HIPAA, and ISO 42001.
-
Opportunity to develop expertise in AI-enabled GRC workflows and compliance productization.
-
Ability to build reusable methodologies, playbooks, and intellectual property that can influence future delivery at scale.
-
Opportunity to contribute to commercial strategy through pricing, packaging, utilization, and margin ownership.
-
Collaborative remote environment focused on trust, transparency, continuous improvement, and knowledge sharing.
-
Inclusive working culture that values talent, curiosity, ownership, diverse perspectives, and impact.
-
Opportunity to work closely with Sales, Solution Engineering, Customer Success, and other cross-functional teams.