Neon AI
Website:
neon-ai.uk
Job details:
Location: Remote — anywhere in India
Start date: Immediate; ideally within the next 5 days
Engagement: Approx. 10 hours per week for 3 months : Hands ON involvement requirement and not advisory
Working style: Flexible hours; occasional weekend availability is welcome
We are an early-stage SaaS startup seeking a hands-on compliance and security consultant to take us through a practical SOC 2 / ISO 27001 certification-readiness and audit engagement.
You will work directly with the Founder and Technical PM to build a simple, proportionate and audit-ready compliance programme—without unnecessary process or complexity.
- What you will do
- Assess our current readiness for SOC 2, ISO 27001 and GDPR requirements.
- Create a clear, prioritised 3-month roadmap for certification readiness and audit engagement.
- Define and implement practical security controls suitable for a lean SaaS startup.
- Create or refine essential policies, procedures, risk registers, vendor assessments and compliance documentation.
- Establish a practical VA/PT approach aligned with SOC 2 and ISO 27001 requirements.
- Coordinate periodic vulnerability assessments and penetration-testing activities across the SaaS application, infrastructure and cloud environment where relevant.
- Review VA/PT findings, prioritise remediation based on risk and maintain a clear remediation tracker.
- Set up lightweight recurring routines for vulnerability scans, patch reviews, access reviews, evidence collection and security reporting.
- Ensure security testing reports, remediation records and periodic review evidence are audit-ready.
- Prepare the business and technical team for external audit/certification activity.
- Help identify and work with suitable certification bodies, auditors and external security-testing partners where required.
- Provide end-to-end, hands-on guidance through readiness, evidence gathering, audit preparation and certification/attestation.
2 Essential requirements
- 5–10+ years of experience in information security, GRC, privacy, SOC 2, ISO 27001 and/or GDPR consulting.
- Must have successfully guided at least two SaaS companies through SOC 2 and/or ISO 27001 certification or attestation.
- Proven end-to-end experience: readiness assessment, gap analysis, control implementation, evidence collection, audit support and certification/attestation.
- Demonstrable experience managing or coordinating VA/PT testing and vulnerability remediation processes.
- Strong understanding of SaaS security, cloud controls, access management, data protection, supplier risk, incident management and audit evidence.
- Able to translate compliance requirements into simple, actionable tasks for founders and technical teams.
- Comfortable working independently in a fast-moving startup environment.
3 Ideal candidate
- Based anywhere in India and able to work fully remotely.
- Available to start within the next 5 days.
- Willing to be hands-on rather than providing high-level advisory only.
- Comfortable with flexible work patterns and occasional weekend collaboration.
4 To apply
Please share:
- Your CV or LinkedIn profile.
- Brief examples of at least two SaaS companies you have supported through SOC 2 and/or ISO 27001 certification/attestation.
- Your specific role in those engagements, including VA/PT and audit support.
- Your availability over the next three months.
- Your proposed hourly or weekly rate.
Click on Apply to know more.