GRC Consultant – Compliance & Audit Readiness
New
J
JobgetherInformation Security
Based in India, flexible across EU and US working hoursFull-TimeMiddle
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 2–5 years
- Required Skills
- AWSGCPAzureSaaS
Requirements
- 2–5 years of relevant experience in information security, IT audit, compliance consulting, or a closely related customer-facing advisory role.
- Strong working knowledge of SOC 2 Type I and Type II and ISO/IEC 27001, including control design and evidence expectations.
- Direct experience participating in, coordinating, or supporting third-party security audits.
- Comfortable with AWS, GCP, or Azure environments, SaaS architectures, and identity and access management.
- Practical problem-solving skills to distinguish documentation gaps from control-design issues.
- Clear written and verbal communication skills to align technical teams, executives, and external auditors.
- Strong organizational skills and follow-through to manage multiple parallel engagements.
- Ability to work flexibly across EU and US working hours.
- CISA, CISM, CISSP, or ISO/IEC 27001 Lead Auditor/Implementer certifications are a plus.
- Experience with compliance automation platforms or cybersecurity consultancy is desirable.
Responsibilities
- Own the end-to-end audit journey for an assigned portfolio of global customers, from gap assessment and readiness through external audit fieldwork, findings remediation, and closure.
- Assess security controls, cloud environments, organizational policies, and operating practices to identify control, evidence, documentation, and implementation gaps early.
- Translate identified gaps into practical, risk-based remediation plans and coordinate with Engineering, IT, DevOps, and leadership teams to drive timely resolution.
- Review audit evidence for relevance, completeness, and consistency before submission while maintaining a clear and audit-ready trail of requests, responses, decisions, and supporting documentation.
- Serve as a coordination point between customers and independent auditors by facilitating requests, clarifying how controls operate, and helping teams respond accurately while preserving auditor independence.
- Track evidence requests, dependencies, exceptions, and delivery risks across multiple engagements, communicating progress clearly and escalating blockers before they impact audit timelines.
- Guide customers through SOC 2 Type I and Type II examinations and ISO/IEC 27001 audits.
- Work flexibly across EU and US working hours to support international customers and audit firms during critical and time-sensitive stages of engagements.
- Identify recurring audit challenges and contribute to reusable playbooks, evidence guidance, and scalable workflows.
View Full Description & ApplyYou'll be redirected to the employer's site