I am looking for a role in GRC Compliance and Security Auditing role for ISO 27001:2022, PCI DSS, Security Consulting roles.
Aditya Iyer
@adityaiyer
Information security professional with 7+ years across IT audit, risk, and compliance, including 7 years in dedicated GRC roles.
What I'm looking for
Information security professional with 7+ years across IT audit, risk, and compliance, including 4 years in dedicated GRC roles. Currently own the end-to-end GRC program at Scrut Automation, a compliance-automation SaaS platform, covering ISO 27001:2022, ISO 42001:2023, SOC 2 Type II, GDPR, and DPDPA 2023, and serving as Incident Manager for security events. ISO 27001:2022 Lead Auditor with 60+ audits delivered across SaaS, healthcare, and manufacturing clients, including a SOC 2 Type II engagement closed with zero exceptions across 352 controls.
Experience
Work history, roles, and key accomplishments
GRC Program Manager
Scrut Automation
May 2025 - Present (1 year 5 months)
Own the end-to-end GRC program for a compliance-automation SaaS platform, reporting directly to the CISO and partnering
with engineering, product, and customer success — covering ISO 27001:2022, ISO 42001:2023, SOC 2 Type II, GDPR, DPDPA
2023, and NIST CSF 2.0.
• Served as primary internal liaison for the company's SOC 2 Type II audit conducted by EY, coordinating evidence collection.
Senior Consultant - GRCs
Value Point Systems a Noventiq Company
Nov 2022 - Apr 2025 (2 years 5 months)
Conducted several audits on various compliance including SOC2 and ISO 27001, and providing expert recommendations on how to secure the organization. Delivering quality client services to our wide range of clientele domestic and overseas, also manages expectations of client service deliveries. Developed various information security policies and procedures for organizations to better strengthen the
Software Engineer (Security)
Singularity AIX.
Jun 2020 - Jun 2022 (2 years)
Conducted comprehensive security assessments within the Salesforce environment, employing advanced techniques to identify vulnerabilities and bypass security controls, while adhering to robust data security principles. Developed and executed intricate exploits to evaluate the effectiveness of IAM controls, aiming to achieve code execution and compromise systems within the Salesforce ecosystem.
Associate Security Engineer
Castellum Labs
Aug 2022 - Jan 2022 (-1 years 5 months)
Conducted red teaming assessments for clients, simulating real-world attacks to identify weaknesses in their security posture and provide recommendations for improvement. Conducted comprehensive web application audits for clients, identifying vulnerabilities and providing actionable recommendations for remediation. Performed dynamic and static security testing using tools such as Burp Suite, and o
Information Security Consultant
Tech Galassia
Mar 2023 - Oct 2021 (-2 years 7 months)
Conducted physical audit, identifying vulnerabilities and providing actionable recommendations for remediation in 30+ pharmacy in IT security audits. Performed dynamic/static app security testing, source code reviews, and prioritized Security advisories for timely bug patching, mitigating risks. Created detailed reports of findings and recommendations for clients and internal stakeholders, highlig
Education
Degrees, certifications, and relevant coursework
Birla Institute of Technology and Science
Masters of Technology, Cyber Security
2023 - 2025
Truba Institute of Engineering and IT
Bachelors of Technology, Computer Science Engineering
2016 - 2020
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Salary expectations
Social media
Job categories
Interested in hiring Aditya?
You can contact Aditya and 90k+ other talented remote workers on Himalayas.
Message AdityaGet matched with your dream remote job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
