GRC / IT & Cybersecurity Audit Assurance Consultant
F9 Infotech I Cybersecurity GRC Division
Company Overview
F9 Infotech is a leading cybersecurity and information security consultancy headquartered in Kochi, India, with active engagements across India and the UAE. We specialize in Governance, Risk & Compliance (GRC) advisory, ISO management system implementations, data privacy compliance, and cybersecurity audit assurance for clients across BFSI, healthcare, manufacturing, and government sectors. As our GRC practice scales, we are looking for a driven professional to work closely with the GRC Head and strengthen our compliance and audit assurance capability.
Position Details
Job Title GRC / IT & Cybersecurity Audit Assurance Consultant Department Cybersecurity GRC Division
Location Reports To
Kochi, Kerala (On-site) Head — GRC Practice
Experience 4—7 years Employment Type Full-time
Role Summary
We are seeking an experienced GRC/IT Audit Assurance professional to work directly under the GRC Head, supporting a portfolio of information security compliance, audit, and consulting engagements across multiple geographies and regulatory frameworks. The ideal candidate combines strong technical grounding in IT/cybersecurity, hands-on ISO implementation and audit experience, working knowledge of global and regional privacy/compliance frameworks, and the consulting maturity to engage directly with client stakeholders — while also contributing to policy documentation, proposal development, and project delivery.
Key Roles & Responsibilities1. GRC Advisory & Framework Implementation
Lead and support implementation of ISO 27001 (ISMS), ISO 9001 (QMS), ISO 22301 (BCMS), and related management system standards for client organizations.
Conduct gap assessments, risk assessments, and maturity assessments against applicable frameworks.
Design, draft, and maintain information security policies, procedures, SOPs, and control documentation tailored to client environments.
Support development and rollout of risk registers, Statements of Applicability (SoA), and control implementation roadmaps.
2. Audit & Assurance
Plan and execute internal audits, pre-certification audits, and readiness assessments for ISO and other compliance frameworks.
Support external/third-party audit coordination, evidence collection, and remediation tracking.
Perform control testing and compliance reviews against frameworks including COBIT, HIPAA, GDPR, DPDPA, and regional standards (UAE PDPL, SAMA, NCA/NESA/NCC, ECA, DAMA, etc.).
Prepare audit reports, findings, non-conformity reports, and corrective action plans for client and internal stakeholders.
3. Data Privacy & Regulatory Compliance
Support privacy compliance assessments under GDPR, India's DPDPA, and Middle East privacy regulations (UAE PDPL and equivalents).
Assist clients with data mapping, DPIAs, consent frameworks, and privacy governance documentation.
Stay current on evolving regulatory requirements across India, UAE, and other operating geographies, and translate them into actionable client guidance.
4. Consulting & Client Engagement
Independently manage or support mid-to-large client engagements from kickoff through closure. Act as a day-to-day point of contact for assigned clients, building trusted advisory relationships.
Facilitate workshops, stakeholder interviews, and training sessions on security awareness, compliance requirements, and control implementation.
Represent F9 professionally in client meetings, steering committees, and audit closure discussions.
5. Project & Practice Management
Manage engagement timelines, deliverables, and resource coordination for assigned projects, ensuring on-time, quality delivery.
Support the GRC Head in practice-building activities, including methodology development, templates, and reusable frameworks/accelerators.
Track project risks and escalate issues proactively.
6. Proposal & Business Development Support
Contribute to proposal writing, scoping, effort estimation, and solutioning for new GRC/compliance opportunities. Support pre-sales activities including client presentations, RFP responses, and capability decks.
Assist in identifying cross-sell/upsell opportunities within existing client accounts.
7. Emerging Technology & AI Governance
Apply working knowledge of AI/ML concepts to support emerging AI governance and risk assessment engagements.
Leverage Al-enabled tools to improve efficiency in documentation, evidence review, and audit workpaper preparation.
Stay abreast of Al-related regulatory and standards developments (e.g., ISO 42001, emerging AI governance frameworks) and support client advisory in this space.
Required Qualifications & Experience
Education: Bachelor's/Master's degree in Information Technology, Computer Science, Cybersecurity, Artificial Intelligence & Machine Learning, or a related technical discipline.
Experience: 4—7 years in GRC, IT audit, information security compliance, or cybersecurity consulting roles, with
demonstrable client-facing project experience.
Proven experience delivering ISO 27001, ISO 9001, and other management system implementations and/or audits for medium to large enterprise clients.
Working knowledge of GDPR, DPDPA (India), COBIT, HIPAA, and regional/geo-specific frameworks such as UAE
PDPL, SAMA, NCA/NCC, ECA, DAMA, and other applicable data protection or cybersecurity regulations. Experience conducting or supporting internal/external audits, control testing, and compliance assessments. Strong policy and procedure documentation skills — ability to independently draft ISMS/QMS/privacy documentation.
Demonstrated project management capability, including managing timelines, client communication, and deliverable
quality across multiple concurrent engagements.
Experience contributing to proposal development, scoping, and pre-sales support.
Comfortable working with Al-based tools to enhance research, documentation, and audit efficiency.
Preferred Certifications
Lead Auditor (LA) certification — ISO 27001 (mandatory/highly preferred); ISO 9001, ISO 22301, or ISO 42001 (added advantage).
Additional certifications such as CISA, CISSP, CRISC, ISO 27701 LA, DPO/Privacy certifications, CEH, or equivalent are a strong plus.
Key Skills & Attributes
Strong analytical and report-writing skills with attention to detail.
Excellent verbal and written communication; ability to present confidently to client leadership and audit
committees.
Ability to work independently as well as collaboratively within a small, senior-led practice team. Comfortable managing multiple client engagements across India and international (UAE/GCC) geographies. High ownership mindset with the ability to operate closely with and support the GRC Head across delivery, documentation, and business development.
Willingness to travel for client engagements as required.
What F9 Infotech Offers
Direct mentorship and exposure working alongside the GRC Head on strategic, cross-border engagements. Opportunity to work across diverse industries (BFSI, healthcare, manufacturing, government) and geographies (India, UAE).
Exposure to emerging areas including AI governance and next-generation compliance frameworks. A growth-oriented environment within a specialized cybersecurity consultancy.
To Apply: Interested candidates may share their updated resume along with certification copies to [email protected]
Work Location: In person