
Closed
Posted
RoleLens Technologies Private Limited is an early-stage B2B SaaS company building an AI-enabled hiring decision-intelligence platform for enterprises. We are beginning development of our MVP and want information security, privacy and compliance built into the product and operating model from the outset, rather than added shortly before an enterprise audit. RoleLens is subscribing to Sprinto for ISO 27001 and SOC 2 readiness. Sprinto will provide the compliance platform, control framework, policy templates, monitoring, evidence workflows and onboarding support. We are looking for a hands-on, part-time GRC consultant who can act as RoleLens’ internal compliance programme owner and work directly with Sprinto, our Founder, technical leadership team, MVP development partner and, later, the independent auditors. This is not a high-level advisory role. We need someone who will take ownership, follow up on actions, maintain the required evidence and make sure controls are actually implemented rather than simply marked complete on a dashboard. - Time commitment and duration - Approximately 5 hours per week - Primarily remote - Some availability during Indian business hours will be required - Engagement will continue through ISO 27001 certification and the agreed SOC 2 audit cycle, including Type I and subsequent Type II preparation and audit coordination, where applicable - Working hours may vary slightly during readiness reviews and audit periods. Key responsibilities: The selected consultant will: - Set up and manage the ISO 27001 and SOC 2 readiness programme within Sprinto - Participate in working sessions with the Sprinto account management and compliance teams - Understand applicable controls, evidence requirements, ownership, dependencies and milestones - Conduct or coordinate the initial gap and readiness assessment - Develop a practical implementation plan aligned with the MVP development timeline - Coordinate with the Founder, Fractional CTO, development team and vendors to close compliance gaps - Help customise and operationalise policies rather than merely copy standard templates - Maintain the risk register, asset register, vendor register, evidence tracker, compliance calendar and action log - Support processes relating to access control, risk management, vendor management, change management, incident response, business continuity and information security - Ensure security and privacy requirements are reflected in the MVP architecture and engineering practices - Review the quality and sufficiency of evidence before controls are marked complete - Coordinate with the ISO 27001 certification body and SOC 2 auditor - Support audit queries, evidence submissions, remediation actions and closure - Provide a short weekly update covering progress, open actions, risks, dependencies and decisions required Expected deliverables: The engagement should result in: - Sprinto configured with appropriate controls and owners - Initial gap assessment and prioritised implementation plan - Essential policies, registers and operating processes in place - Reliable evidence collected and maintained - Security and compliance actions incorporated into the MVP build - ISO 27001 audit readiness and certification support - SOC 2 Type I readiness and examination support - Continued control monitoring and preparation for SOC 2 Type II, where applicable - Clear audit trail, action tracker and weekly reporting Candidate profile: We are looking for an individual consultant with approximately 3 to 7 years of hands-on experience in one or more of the following: - Information-security governance - Governance, Risk and Compliance - ISO 27001 implementation - SOC 2 Type I and Type II readiness - SaaS security and technology risk - Internal audit or external audit coordination - Cloud and software-development control environments The candidate should have participated meaningfully in at least one ISO 27001 certification or SOC 2 assurance cycle. Experience using Sprinto or a similar compliance-automation platform would be an advantage. Relevant certifications such as ISO 27001 Lead Implementer, Lead Auditor, CISA, CISM or equivalent will be helpful, but practical delivery experience will matter more than certificates alone. What will matter most: We need someone who: - Works independently and follows through until actions are closed - Can translate compliance requirements into practical startup actions - Understands SaaS, cloud environments, access controls, software-development workflows and evidence trails - Communicates clearly with technical and non-technical stakeholders - Can distinguish essential controls from unnecessary bureaucracy - Is comfortable challenging weak evidence or incomplete implementation - Can represent RoleLens professionally in discussions with Sprinto and auditors This is not suitable for someone looking only to provide templates, conduct an occasional review or offer high-level advice. How to apply? Please include the following in your proposal: - Briefly describe one ISO 27001 or SOC 2 assignment in which you personally participated. - Explain your exact role and what you personally delivered. - Mention whether you have worked with Sprinto or a similar platform. - Confirm whether you have supported ISO 27001 certification, SOC 2 Type I, SOC 2 Type II or a combination of these. - Share your availability for approximately five hours per week. - Quote your hourly rate or monthly fee for approximately 20 hours per month. - Mention any relevant certifications. - Share a redacted sample of a gap plan, risk register, control tracker or audit-readiness report, where possible. - Provide one or two client references for similar work. Please begin your proposal with the words “RoleLens GRC” so we know you have read the complete requirement. Individual consultants are preferred. Agencies should apply only if the named consultant who will personally perform the work is clearly identified. If you have successfully taken other SaaS startups from “zero to cert” and can commit roughly 5 hours per week over the next few months, let’s talk.
Project ID: 40614909
8 proposals
Remote project
Active 3 hours ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
8 freelancers are bidding on average ₹1,056 INR/hour for this job

RoleLens GRC Hi, I can support RoleLens as a hands-on part-time GRC consultant and manage ISO 27001 and SOC 2 readiness inside Sprinto, working with your Founder, technical team, MVP partner, Sprinto team, and auditors. The best solution is to first configure Sprinto with the right controls, owners, milestones, evidence requirements, and action tracker. I’ll then run the initial gap assessment, create a prioritised implementation plan, customise policies, maintain registers, review evidence quality, and make sure controls are actually implemented. I’m comfortable with ISO 27001, SOC 2 Type I/Type II readiness, SaaS security, cloud controls, access control, vendor risk, risk registers, asset registers, incident response, change management, audit evidence, and compliance reporting. Deliverables include: * Sprinto setup and control ownership * Gap assessment * Implementation roadmap * Policy customisation * Risk, asset, vendor and evidence registers * Compliance calendar and action log * MVP security/control alignment * Weekly progress report * Audit query and evidence support * ISO 27001 and SOC 2 readiness support Availability: around 5 hours/week. Sprinto/similar platform experience: [Add details] Certifications/sample reports/references: [Add details] I’ll focus on practical startup-ready compliance, not just templates. Best regards Ankit
₹1,000 INR in 40 days
2.1
2.1

Certified AWS Solutions Architect – Professional Certified AWS Solutions Architect – Associate CISA Certified Security Expert 16+ Years of Experience in Information Security, Cloud & Compliance Hi, I'm excited to support RoleLens in building ISO 27001 and SOC 2 readiness into your MVP from day one. I have hands-on experience leading ISO 27001 implementations, SOC 2 readiness programs, risk assessments, policy implementation, evidence management, and audit coordination for SaaS organizations. I have worked closely with compliance automation platforms similar to Sprinto, managing control mapping, evidence collection, risk registers, asset/vendor registers, and audit trackers while coordinating with technical teams and auditors. I have personally supported ISO 27001 certification and SOC 2 Type I & Type II readiness by driving implementation, closing compliance gaps, reviewing evidence, and ensuring controls are operational—not just documented. I can dedicate 5 hours/week, provide weekly progress updates, and work directly with your Founder, engineering team, Sprinto, and auditors until certification and audit completion. I'd be happy to share sample deliverables and client references upon request. Looking forward to discussing your compliance roadmap. Best regards, SHD
₹1,250 INR in 40 days
1.4
1.4

I have total 9 yrs of experience in managing aws azure cloud secuirty with multiple benchmark like CIS PCI Mitre Framework Best Practices to analyse security gaps and work on remediation
₹1,000 INR in 30 days
0.0
0.0

Hello! As an accomplished Full-Stack Engineer, SaaS founder, and business development professional, I bring a range of unique skills and expertise that make me a prime candidate for your ISO 27001 SOC2 Readiness Consultant role. My multifaceted background in software development, sales, risk management, and technical documentation aligns perfectly with your company's needs to incorporate information security, privacy, and compliance at each stage rather than as afterthoughts. My experience as a SaaS founder selling my own product - which not only culminated in attracting paying customers but also necessitated understanding business requirements and conveying the value of my offering - directly translates to my ability to grasp your specific needs and their integration into your MVP's development timeline. My potential contribution stretches from set up & managing the Sprinto ISO 27001/SOC 2 program through coordinating efforts with stakeholders to maintain records & support audit queries. With me onboard you can count on excellent client relationship management and end-to-end solutions that encompass concept to launch. Choose me for a liaison who can translate complex processes into practical applications while maintaining transparency through strong reporting. Let's leverage my creative problem-solving skills married with tenacious discipline attained through years of entrepreneurship to not just meet but exceed every expectation throughout the project journey!
₹950 INR in 40 days
0.0
0.0

Hello, I am interested in supporting RoleLens Technologies as a part-time GRC and compliance consultant. I have 4+ years of experience in audit, compliance, process governance, risk and control assessment, ISO compliance, and audit readiness at Tata Consultancy Services (TCS). My experience includes internal audits, ISO 9001 and ISO 27001 compliance activities, CMMI assessments, audit evidence, process documentation, gap assessments, NCR/CAPA management, corrective-action tracking, and audit closure. I work closely with project teams, process owners, auditors, and stakeholders to identify gaps, resolve compliance issues, maintain evidence, and ensure actions are properly closed. I can support your team with ISO 27001 readiness, gap assessments, risk and control tracking, compliance documentation, audit evidence, corrective actions, process improvement, and stakeholder coordination. My approach is practical and execution-focused: identify the gap, assign ownership, follow up, validate evidence, and close the action. I have not worked directly with Sprinto or personally led a complete SOC 2 Type I/II cycle, and I prefer to be transparent about that. However, my ISO 27001, GRC, audit, and compliance experience provides a strong foundation to quickly understand your requirements and contribute effectively. I can commit approximately 5 hours per week during Indian business hours and would be happy to discuss your requirements.
₹1,000 INR in 40 days
0.0
0.0

**RoleLens GRC** Hello RoleLens Team, I'm a Cybersecurity Engineer with around 3 years of experience in security assessments, penetration testing, risk management, and ISO 27001-aligned governance. I enjoy helping organizations integrate security into their processes rather than treating compliance as a checkbox. I have contributed to ISO 27001 implementation activities, including security gap assessments, risk analysis, policy development, control implementation, and remediation planning. My role has involved working closely with technical teams to translate security requirements into practical actions and improve overall security posture. While I haven't worked directly with Sprinto, I'm experienced with compliance frameworks and evidence-driven security processes, and I'm confident in quickly adapting to new platforms. I have not independently led a full SOC 2 audit cycle, but I understand the requirements for audit readiness and supporting control implementation. I can commit approximately 5 hours per week and am available during Indian business hours when needed. I take ownership, communicate clearly with both technical and non-technical stakeholders, and focus on delivering practical, effective security solutions. I'd be excited to help RoleLens build a strong compliance foundation from the start and support your journey toward ISO 27001 and SOC 2 readiness. Kind regards, Haritiana Rakotoarisoa
₹1,000 INR in 40 days
0.0
0.0

With over 5+ years of experience in Information Security, IT Governance, Risk & Compliance (GRC), ITGC, SOX, ISO 27001, SOC, Third-Party Risk Management (TPRM), Identity & Access Management (IAM), and IT Audit, I can act as your hands-on compliance program owner and help embed security and compliance into RoleLens from the MVP stage. I have practical experience establishing governance frameworks, conducting risk and gap assessments, implementing security controls, maintaining compliance documentation, managing evidence collection, and coordinating with technical teams to ensure controls are effectively implemented. My expertise includes maintaining risk, asset, vendor, and access registers; developing security policies and procedures; supporting incident response, change management, business continuity, and vendor risk processes; and preparing organizations for ISO 27001 and SOC audits.
₹1,000 INR in 40 days
0.0
0.0

I have 4+ years of exact experience in ISO27001 readiness and 5 years in SOC readiness. I have overseen end to end from planning to getting through the audit as an account manager for my banking account.
₹1,250 INR in 40 days
0.0
0.0

Bengaluru, India
Payment method verified
Member since Aug 6, 2025
₹12500-37500 INR
₹600-1500 INR
$30-250 USD
$8-15 USD / hour
$250-750 USD
$30-250 USD
₹750-1250 INR / hour
₹1500-12500 INR
$250-750 USD
$25-50 USD / hour
$10-30 USD
₹750-1250 INR / hour
₹750-1250 INR / hour
$250-750 USD
₹75000-150000 INR
$30-250 USD
₹1500-12500 INR
$25-50 USD / hour
₹600-1500 INR
₹600-1500 INR
$8-15 USD / hour
£20-250 GBP