Sobre este puesto de GRC Consultant – Compliance & Audit Readiness en Sprinto
Sprinto is an Autonomous Trust Platform that centralizes trust requirements across security frameworks, vendors, and customers.
Sprinto autonomously executes tasks needed to maintain trust across compliance, audits, risk management, vendor risk, privacy, and AI governance, enabling organizations to maintain a strong, reliable trust posture without draining operational bandwidth and resources on repetitive tasks.
Backed by top-tier investors such as Accel, Elevation, and Blume Ventures, we’ve raised $31.8M in funding to fuel our mission. Trusted by over 4,000 organizations across 75 countries, Sprinto helps organizations stay audit-ready, manage real-time risks, and scale fearlessly. With 300+ native integrations and AI-driven automation, Sprinto supports 200+ global security standards natively, including SOC 2, ISO 27001, GDPR, HIPAA, PCI-DSS, and more. Sprinto's extensible architecture enables organizations to build and support an infinite number of custom integrations and frameworks.
Founded in 2020 by second-time founders Girish Redekar and Raghuveer Kancherla, Sprinto powers compliance for organizations like Whatfix, Encora, Anaconda, Whatnot, Ultrahuman, WeWork, Everstage, AI Foundation, HackerRank, and many more.
Life as a Sprinter -
Nobody succeeds at Sprinto by staying in their lane.
We are organised around problems, not job titles. Sprinters take ownership beyond their role, solve hard problems, and care deeply about the impact they create. If something can be improved, fixed, or built, we don't wait for permission; we step in.
Being remote means we rely less on proximity and more on trust. We write things down, communicate openly, and move quickly because great teams aren't built by sitting together; they're built by pulling in the same direction.
We believe progress beats perfection, feedback is a gift, and doing the right thing matters, even when nobody is watching.
And while we move with urgency, we never move alone.
The mission -
Act as the trusted bridge between customers and independent auditors. You will identify security and compliance gaps, drive practical remediation, strengthen evidence readiness, and guide customers through external audits to timely closure without compromising auditor independence.
Where you'll leave your mark?
Own the audit journey for an assigned portfolio of global customers - from gap assessment and readiness through external audit fieldwork, findings resolution and closure.
Assess security controls, cloud environments, organizational policies and operating practices to identify control, evidence and implementation gaps early.
Turn identified gaps into practical, risk-based remediation plans with Engineering, IT, DevOps and leadership teams, balancing audit urgency with operational reality.
Review evidence for relevance, completeness and consistency before submission, and maintain a clear, audit-ready trail of requests, responses and decisions.
Serve as the coordination point between customers and independent auditors - facilitate requests, clarify how controls operate and help teams respond accurately without compromising auditor independence.
Track open evidence requests, dependencies, exceptions and delivery risks; communicate progress clearly and escalate roadblocks before they threaten timelines.
Guide customers across SOC 2 Type I and Type II examinations and ISO/IEC 27001 audits, with exposure to ISO/IEC 27701, HIPAA, GDPR and PCI DSS where relevant.
Work flexibly across EU and US hours to support international customers and audit firms during time-sensitive stages of an engagement.
Improve reusable playbooks, evidence guidance and audit workflows by turning recurring issues into scalable practices for the Central Audits Team.
The kind of builder we're looking for -
2-5 years of relevant experience in information security, IT audit, compliance consulting or a closely related customer-facing advisory role; strong candidates with deeper experience are also welcome.
Strong working knowledge of SOC 2 Type I and Type II and ISO/IEC 27001, including control design, evidence expectations, readiness and external audit workflows.
Direct experience participating in, coordinating or supporting third-party security audits and responding to auditor requests or findings.
Comfort with AWS, GCP or Azure, SaaS architectures, identity and access management, and the technical context needed to assess how controls operate.
A practical problem-solver who can distinguish a documentation gap from a control-design or operating-effectiveness gap and drive the right remediation.
Clear written and verbal communication, with the judgment to align technical teams, executives, customers and external auditors around facts, ownership and next steps.
Strong organization and follow-through across multiple parallel engagements, changing priorities and time-sensitive evidence requests.
Willingness to work with flexibility across EU and US working hours.
Nice to have: CISA, CISM, CISSP, ISO/IEC 27001 Lead Auditor or Lead Implementer, or a relevant privacy credential.
Nice to have: experience with a compliance automation platform, cybersecurity consultancy or fast-scaling B2B SaaS company supporting international customers.
How we care for our Sprinters?
- Work wherever you are: We are 100% remote, so you get to choose if you want to work from home, a cafe, the hills, or the beach.
- Co-working, on the house: If co-working is your jam, we offer a generous annual allowance.
- We care about your learning: We are invested in seeing you grow and commit USD 1,000 annually to help you level up your skills.
- We count your spark, not your leaves: Unlimited leave so you can reset when you need to.
- Your Safety Net, Woven In: Health insurance with coverage up to INR 10 lakh for you and your family, accident protection of an additional INR 10 lakh, and life insurance worth 3x your annual salary.
- Workspace setup of your dreams: We chip in INR 35,000 to help you build a setup that works for you.
Inclusion & Diversity -
At Sprinto, talent, curiosity, and ownership matter more than where you come from. We hire people for the problems they can solve, the impact they create, and the way they help others succeed—not their background, identity, or personal circumstances. We believe the best teams are built when people with different perspectives come together around a shared ambition to build something meaningful.
We're proud to be an equal opportunity employer and are committed to creating a fair, inclusive, and accessible hiring process for everyone.