Senior GRC Consultant – Contract
Posted 5hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior GRC Consultant delivering ISO, SOC 2, and GDPR compliance programs for Sprinto’s autonomous trust platform. Building AI-assisted playbooks and owning client engagement quality, margins, and delivery.
Responsibilities:
- Own delivery for standard-framework engagements including ISO 27001 implementation and surveillance, SOC 2 Type I/II readiness, GDPR and PCI DSS compliance programs, gap assessments, control/check mapping, internal audits, policy reviews, and audit-readiness support
- Run multiple concurrent client engagements to a consistent quality bar without close supervision
- Maintain and evolve templates, control-mapping libraries, workshop agendas, and QA rubrics for standard frameworks
- Keep framework materials current as standards and guidance evolve
- Extend the library to adjacent frameworks such as HIPAA, PCI DSS, and ISO 42001 as demand grows
- Define pricing and packaging for standard-framework engagements
- Own utilization, margin, and delivery forecasting for the engagement book
- Partner with Sales, SE, and CS to attach and renew standard-framework services and support technical deal validation
- Build and maintain AI-assisted playbooks for gap assessments, control mapping, and internal audit checklists
- Define structured input forms and checklists for consistent first-draft output by junior staff or AI-assisted workflows
- Set QA guardrails, including mandatory source inputs, validation steps, and human approval gates
- Establish acceptance criteria and review checkpoints for deliverables
- Flag scope creep early and escalate ambiguous liability questions
- Serve as the internal go-to for ISO 27001, SOC 2, GDPR, and PCI DSS maturity questions across Sales, SE, and CS
- Meet success metrics covering utilization, gross margin, QA pass rate, rework rate, deliverable cycle time, CSAT, service attach rate, and playbook reuse rate
Requirements:
- 5+ years in GRC/security consulting or in-house compliance program ownership
- Hands-on delivery track record across ISO 27001, SOC 2, and GDPR at minimum
- Comfortable running several concurrent client engagements
- Deep knowledge of ISO 27001 and SOC 2 Type I/II
- Deep knowledge of GDPR
- Working knowledge of PCI DSS, HIPAA, ISO 42001, etc. is nice to have
- Demonstrated use of AI tools to reduce manual effort and standardize deliverables
- Ability to translate domain expertise into reusable templates and guided systems
- Ability to own pricing/packaging, margin, and utilization for an engagement book
- Strong written communication
- Confidence running client workshops independently
- Good judgment in ambiguous situations and ability to manage scope creep
- ISO 27001 LA/LI, CISA, or CISM preferred
- Ability to join immediately
Benefits:
- Remote work arrangement
- Inclusive and accessible hiring process
- Opportunity to work with AI-driven automation and productization
- Opportunity to build reusable intellectual property and guided systems
- Six-month contract engagement

















