Matcha
Sprinto logo

Senior GRC Consultant - Contract

Sprinto

See similar roles
Apply

Series B GRC automation platform for compliance globally.

$31.5M raised· Backed by Accel, Elevation Capital, Blume Ventures
CONTRACTORRemote · Asia-Pacific442 employeesPosted Oct 6
iso 27001soc 2gdprpci dssgrccompliancerisk managementaudit readinesspolicy reviewgap assessmentai-driven automationproject managementstakeholder managementtechnical writingconsulting

Remote startup roles in your inbox

Matcha reads all job descriptions to surface the handful that actually matter in a zero noise email. Simple by design.

Describe your next role, cut the noise

Sprinto is an Autonomous Trust Platform that centralizes trust requirements across security frameworks, vendors, and customers.

Sprinto autonomously executes tasks needed to maintain trust across compliance, audits, risk management, vendor risk, privacy, and AI governance, enabling organizations to maintain a strong, reliable trust posture without draining operational bandwidth and resources on repetitive tasks.

Backed by top-tier investors such as Accel, Elevation, and Blume Ventures, we’ve raised $31.8M in funding to fuel our mission. Trusted by over 4,000 organizations across 75 countries, Sprinto helps organizations stay audit-ready, manage real-time risks, and scale fearlessly. With 300+ native integrations and AI-driven automation, Sprinto supports 200+ global security standards natively, including SOC 2, ISO 27001, GDPR, HIPAA, PCI-DSS, and more. Sprinto's extensible architecture enables organizations to build and support an infinite number of custom integrations and frameworks.

Founded in 2020 by second-time founders Girish Redekar and Raghuveer Kancherla, Sprinto powers compliance for organizations like Whatfix, Encora, Anaconda, Whatnot, Ultrahuman, WeWork, Everstage, AI Foundation, HackerRank, and many more.

Life as a Sprinter -

Nobody succeeds at Sprinto by staying in their lane.

We are organized around problems, not job titles. Sprinters take ownership beyond their role, solve hard problems, and care deeply about the impact they create. If something can be improved, fixed, or built, we don't wait for permission; we step in.

Being remote means we rely less on proximity and more on trust. We write things down, communicate openly, and move quickly because great teams aren't built by sitting together, they're built by pulling in the same direction.

We believe progress beats perfection, feedback is a gift, and doing the right thing matters, even when nobody is watching.

And while we move with urgency, we never move alone.

The mission -

Owns day-to-day GRC program maturity and delivery for Sprinto's standard-framework services — the highest-volume, highest-repeatability engine of Trust Assurance. Keeps the standard-framework playbook current, delivers consistently, and is the internal go-to for ISO 27001 / SOC 2 / GDPR / PCI DSS etc. maturity questions across Sales, SE, and CS

\n


Where you'll leave your mark?

Deliver

  • Own delivery for standard-framework engagements: ISO 27001 (implementation & surveillance), SOC 2 Type I/II readiness, GDPR, PCI DSS compliance programs, gap assessments, control/check mapping, internal audits, policy reviews, audit readiness support.

  • Run multiple concurrent client engagements to a consistent quality bar without close supervision.

Build reusable IP

  • Maintain and evolve templates, control-mapping libraries, workshop agendas, and QA rubrics for standard frameworks; keep them current as frameworks revise (ISO 27001:2022 transition-type updates, SOC 2 trust criteria changes, GDPR enforcement guidance).

  • Extend the library opportunistically to adjacent frameworks (HIPAA, PCI DSS, ISO 42001) as demand grows.

Own commercial outcomes

  • Define pricing/packaging for standard-framework engagements (fixed-fee tiers, retainer options).

  • Own utilization, margin, and delivery forecasting for your own engagement book.

  • Partner with Sales/SE/CS to attach and renew standard-framework services; support deal conversion where technical validation is needed.

AI-enabled productization

  • Build and maintain AI-assisted playbooks for standard frameworks (gap assessment, control mapping, internal audit checklists).

  • Define structured input forms/checklists so juniors or AI-assisted workflows produce consistent first-draft output.

  • Set QA guardrails: mandatory source inputs, validation steps, human approval gates.

Quality & risk

  • Establish acceptance criteria and review checkpoints for deliverables.

  • Flag scope creep early; escalate ambiguous liability questions rather than absorbing them silently.


The kind of builder we're looking for -

Experience

  • 5+ years in GRC/security consulting or in-house compliance program ownership.

  • Hands-on delivery track record across ISO 27001, SOC 2, and GDPR at minimum.

  • Comfortable running several concurrent client engagements.

Domain mastery

  • Deep: ISO 27001, SOC 2 Type I/II, GDPR.

  • Working knowledge (nice to have): PCI DSS, HIPAA, ISO 42001 etc

AI-enabled workflow proficiency

  • Demonstrated use of AI tools to reduce manual effort and standardize deliverables.

  • Able to translate domain expertise into reusable templates and guided systems.

Operator strengths

  • Can own pricing/packaging, margin, and utilization for their own book without a manager doing it for them.

  • Strong written communication; confident running client workshops solo.

  • Good judgment in ambiguity, without scope creep.

Preferred

  • ISO 27001 LA/LI, CISA, or CISM.

  • This a contract role for six months & we are looking for candidates who can join us immediately 

Success metrics

  • Utilization % and gross margin on standard-framework engagements.

  • QA pass rate, rework rate, deliverable cycle time (benchmarked against standard-framework norms — weeks, not months).

  • Customer satisfaction (CSAT) on delivered engagements.

  • Attach rate for standard-framework services; playbook reuse rate.


\n

 


Inclusion & Diversity -

At Sprinto, talent, curiosity, and ownership matter more than where you come from. We hire people for the problems they can solve, the impact they create, and the way they help others succeed—not their background, identity, or personal circumstances. We believe the best teams are built when people with different perspectives come together around a shared ambition to build something meaningful.

We're proud to be an equal opportunity employer and are committed to creating a fair, inclusive, and accessible hiring process for everyone.

More remote jobs at Sprinto

Similar remote jobs