GRC Consultant – Compliance & Audit Readiness
India · Remote · Full-time
- Posted 1mo ago
- From Sprinto’s careers page
- Location
- India
- Work mode
- Remote
- Type
- Full-time
- Level
- Senior
- Experience
- 2+ years
- Department
- Information Technology
Apply on Sprinto’s site
Opens the listing on jobs.lever.co
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
Where you'll leave your mark?
- Own the audit journey for an assigned portfolio of global customers - from gap assessment and readiness through external audit fieldwork, findings resolution and closure.
- Assess security controls, cloud environments, organizational policies and operating practices to identify control, evidence and implementation gaps early.
- Turn identified gaps into practical, risk-based remediation plans with Engineering, IT, DevOps and leadership teams, balancing audit urgency with operational reality.
- Review evidence for relevance, completeness and consistency before submission, and maintain a clear, audit-ready trail of requests, responses and decisions.
- Serve as the coordination point between customers and independent auditors - facilitate requests, clarify how controls operate and help teams respond accurately without compromising auditor independence.
- Track open evidence requests, dependencies, exceptions and delivery risks; communicate progress clearly and escalate roadblocks before they threaten timelines.
- Guide customers across SOC 2 Type I and Type II examinations and ISO/IEC 27001 audits, with exposure to ISO/IEC 27701, HIPAA, GDPR and PCI DSS where relevant.
- Work flexibly across EU and US hours to support international customers and audit firms during time-sensitive stages of an engagement.
- Improve reusable playbooks, evidence guidance and audit workflows by turning recurring issues into scalable practices for the Central Audits Team.
The kind of builder we're looking for -
- 2-5 years of relevant experience in information security, IT audit, compliance consulting or a closely related customer-facing advisory role; strong candidates with deeper experience are also welcome.
- Strong working knowledge of SOC 2 Type I and Type II and ISO/IEC 27001, including control design, evidence expectations, readiness and external audit workflows.
- Direct experience participating in, coordinating or supporting third-party security audits and responding to auditor requests or findings.
- Comfort with AWS, GCP or Azure, SaaS architectures, identity and access management, and the technical context needed to assess how controls operate.
- A practical problem-solver who can distinguish a documentation gap from a control-design or operating-effectiveness gap and drive the right remediation.
- Clear written and verbal communication, with the judgment to align technical teams, executives, customers and external auditors around facts, ownership and next steps.
- Strong organization and follow-through across multiple parallel engagements, changing priorities and time-sensitive evidence requests.
- Willingness to work with flexibility across EU and US working hours.
- Nice to have: CISA, CISM, CISSP, ISO/IEC 27001 Lead Auditor or Lead Implementer, or a relevant privacy credential.
- Nice to have: experience with a compliance automation platform, cybersecurity consultancy or fast-scaling B2B SaaS company supporting international customers.
Skills they ask for
Pick one to see other roles that ask for it.
About Sprinto
More roles at Sprinto
See all 19- Information Security Compliance InternIndia · Intern · RemoteLegal and Compliance · Intern · RemoteIndia20h
- Organic Growth ManagerBengaluru · RemoteMarketing · RemoteBengaluru, India1d
- Senior GRC Consultant - ContractIndia · Senior · RemoteInformation Technology · Senior · RemoteIndia3d
- Director, Professional Services & Audit Delivery PartnershipsIndia · Director · RemoteBusiness Operations · Director · RemoteIndia2w
Share this role
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.