GRC Sr.Consultant (India)

GRC Sr.Consultant (India)

18 Aug
|
Seccomply
|
India

18 Aug

Seccomply

India

GRC Consultant, Information Security and Compliance

Company: SecComply Technologies Experience: 2 to 4 years in GRC, information security compliance or IT audit Location: Fully remote (India). No relocation, no office reporting requirement. Function: Governance, Risk and Compliance Engagement: Full time Diversity hiring: This opening is part of a women in cybersecurity hiring initiative and is open to women candidates.this role is part of a returnship initiative and is open to women rejoining the workforce after a career break taken for marriage, family or caregiving responsibilities

About SecComply

SecComply Technologies is an AI first cybersecurity and compliance company. We deliver ISO 27001, SOC 2, HIPAA and DPDP Act programmes for startups, SaaS and healthtech product companies, and mid sized enterprises, supported by our own GRC platform. Our consultants work directly with client CTOs, engineering teams, privacy officers and external auditors.

About the role

You will own compliance engagements, not tasks within them. Expect to run two to four client accounts in parallel, drive them from gap assessment through to certification or attestation, and be the person the client calls when they have a control question.

The core standards for this role are ISO 27001 and HIPAA. SOC 2 and DPDP Act work will come your way as well.

What you will own

- Run ISO 27001 implementation and surveillance engagements end to end: gap assessment, risk assessment and treatment, Statement of Applicability, control design and implementation guidance, internal audit, management review, and certification audit support
- Deliver SOC2 compliance programmes: Security Rule and Privacy Rule mapping, administrative, physical and technical safeguards, risk analysis, Business Associate Agreement review, breach notification procedures, and workforce training content
- Build and maintain the client documentation set: policies, procedures, SOPs, control narratives,



risk registers, evidence indices
- Drive evidence collection cycles with client stakeholders and hold them to dates
- Run client workshops and control walkthroughs with technical and non technical teams
- Coordinate with certification bodies, CPA firms and external auditors through audit windows, and manage findings to closure
- Configure and maintain client programmes on our GRC platform
- Produce gap reports, status reports and management presentations
- Mentor interns and junior analysts on documentation quality and audit readiness

What we are looking for Experience 2 to 4 years of hands on GRC, compliance or IT audit work, with at least one ISO 27001 implementation or audit cycle you can walk us through in detail.

Standards knowledge Working command of ISO 27001:2022 and Annex A controls, and of the HIPAA Security and Privacy Rules. Familiarity with SOC 2 Trust Services Criteria, the DPDP Act 2023, NIST CSF or CIS Controls is an advantage.

English, written and spoken A hard requirement. You will author policies and audit reports, present findings to client leadership, and hold your position in front of an external auditor. We need accurate, well structured writing and confident spoken English.

Technical grounding You should be comfortable discussing access control, encryption, logging and monitoring, vulnerability management, secure SDLC, and cloud security on AWS, Azure or GCP well enough to assess whether a control is genuinely implemented rather than merely claimed.

Ownership This is a remote role with real client responsibility.



We need someone who tracks their own deadlines, escalates early, and does not need to be asked twice for a status update.

Qualification BE, BTech, MCA, MSc or equivalent. Engineering or computer science background preferred.

Good to have

- ISO 27001 Lead Auditor or Lead Implementer certification
- CISA, CISM, CIPP, CHPS or HCISPP
- Experience with healthcare or health tech clients handling protected health information
- Experience with a GRC or compliance automation platform
- Prior experience mentoring junior consultants

What you get
- Full ownership of client accounts, with named client relationships from month one
- Direct exposure across ISO 27001, HIPAA, SOC 2 and DPDP rather than a single standard
- Work alongside a founding team with Fortune 500 CISO experience
- Fully remote, with genuine flexibility on working hours around client commitments
- Certification and training support
- Compensation based on interview outcome and current market benchmarks

Work location and terms
- Fully remote from anywhere in India, permanently. This is not a hybrid role in disguise.
- Occasional travel to client sites or to Pune for audits, workshops or team meetings, at company cost.
- Core overlap hours with the delivery team and clients are expected, with flexibility around them.

Selection process
1. Application and resume screening
2. Written assessment: a scenario based gap analysis and short report writing task
3. Technical discussion on ISO 27001 and HIPAA, walking through a past engagement of yours
4. Final discussion with leadership

How to apply Email your resume to [email protected] with the subject line: GRC Consultant Application: [Your Name].

In the email body, tell us in a short paragraph about one compliance engagement you ran or contributed to, what was broken when you arrived, and what changed because you were on it.

📌 GRC Sr.Consultant (India)
🏢 Seccomply
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: grc sr.consultant (india) / india

Subscribe to this job alert:

Get the latest job offers by email for: grc sr.consultant (india) / india