ISO 27001 SOC2 Readiness Consultant

Cliente Freelancer · Remoto · Remoto · freelance · mid · 750–1250 INR

Publicada el 2026-07-30

Descripción de la oferta

RoleLens Technologies Private Limited is an early-stage B2B SaaS company building an AI-enabled hiring decision-intelligence platform for enterprises. We are beginning development of our MVP and want information security, privacy and compliance built into the product and operating model from the outset, rather than added shortly before an enterprise audit. RoleLens is subscribing to Sprinto for ISO 27001 and SOC 2 readiness. Sprinto will provide the compliance platform, control framework, policy templates, monitoring, evidence workflows and onboarding support. We are looking for a hands-on, part-time GRC consultant who can act as RoleLens’ internal compliance programme owner and work directly with Sprinto, our Founder, technical leadership team, MVP development partner and, later, the independent auditors. This is not a high-level advisory role. We need someone who will take ownership, follow up on actions, maintain the required evidence and make sure controls are actually implemented rather than simply marked complete on a dashboard. - Time commitment and duration - Approximately 5 hours per week - Primarily remote - Some availability during Indian business hours will be required - Engagement will continue through ISO 27001 certification and the agreed SOC 2 audit cycle, including Type I and subsequent Type II preparation and audit coordination, where applicable - Working hours may vary slightly during readiness reviews and audit periods. Key responsibilities: The selected consultant will: - Set up and manage the ISO 27001 and SOC 2 readiness programme within Sprinto - Participate in working sessions with the Sprinto account management and compliance teams - Understand applicable controls, evidence requirements, ownership, dependencies and milestones - Conduct or coordinate the initial gap and readiness assessment - Develop a practical implementation plan aligned with the MVP development timeline - Coordinate with the Founder, Fractional CTO, development team and vendors to close compliance gaps - Help customise and operationalise policies rather than merely copy standard templates - Maintain the risk register, asset register, vendor register, evidence tracker, compliance calendar and action log - Support processes relating to access control, risk management, vendor management, change management, incident response, business continuity and information security - Ensure security and privacy requirements are reflected in the MVP architecture and engineering practices - Review the quality and sufficiency of evidence before controls are marked complete - Coordinate with the ISO 27001 certification body and SOC 2 auditor - Support audit queries, evidence submissions, remediation actions and closure - Provide a short weekly update covering progress, open actions, risks, dependencies and decisions required Expected deliverables: The engagement should result in: - Sprinto configured with appropriate controls and owners - Initial gap assessment and prioritised implementation plan - Essential policies, registers and operating processes in place - Reliable evidence collected and maintained - Security and compliance actions incorporated into the MVP build - ISO 27001 audit readiness and certification support - SOC 2 Type I readiness and examination support - Continued control monitoring and preparation for SOC 2 Type II, where applicable - Clear audit trail, action tracker and weekly reporting Candidate profile: We are looking for an individual consultant with approximately 3 to 7 years of hands-on experience in one or more of the following: - Information-security governance - Governance, Risk and Compliance - ISO 27001 implementation - SOC 2 Type I and Type II readiness - SaaS security and technology risk - Internal audit or external audit coordination - Cloud and software-development control environments The candidate should have participated meaningfully in at least one ISO 27001 certification or SOC 2 assurance cycle. Experience using Sprinto or a similar compliance-automation platform would be an advantage. Relevant certifications such as ISO 27001 Lead Implementer, Lead Auditor, CISA, CISM or equivalent will be helpful, but practical delivery experience will matter more than certificates alone. What will matter most: We need someone who: - Works independently and follows through until actions are closed - Can translate compliance requirements into practical startup actions - Understands SaaS, cloud environments, access controls, software-development workflows and evidence trails - Communicates clearly with technical and non-technical stakeholders - Can distinguish essential controls from unnecessary bureaucracy - Is comfortable challenging weak evidence or incomplete implementation - Can represent RoleLens professionally in discussions with Sprinto and auditors This is not suitable for someone looking only to provide templates, conduct an occasional review or offer high-level advice. How to apply? Please include the following in your proposal: - Briefly describe one ISO 27001 or SOC 2 assignment in which you personally participated. - Explain your exact role and what you personally delivered. - Mention whether you have worked with Sprinto or a similar platform. - Confirm whether you have supported ISO 27001 certification, SOC 2 Type I, SOC 2 Type II or a combination of these. - Share your availability for approximately five hours per week. - Quote your hourly rate or monthly fee for approximately 20 hours per month. - Mention any relevant certifications. - Share a redacted sample of a gap plan, risk register, control tracker or audit-readiness report, where possible. - Provide one or two client references for similar work. Please begin your proposal with the words “RoleLens GRC” so we know you have read the complete requirement. Individual consultants are preferred. Agencies should apply only if the named consultant who will personally perform the work is clearly identified. If you have successfully taken other SaaS startups from “zero to cert” and can commit roughly 5 hours per week over the next few months, let’s talk.

Skills

Fuente original: freelancer

Análisis JobHunter