Opportunity brief
Role Summary: As a GRC Audit Intern , you will support audit teams in planning, evidence collection, testing, and reporting for management system and assurance engagements, including ISO/IEC 27001 (ISMS), ISO/IEC 42001 (AIMS), ISO/IEC 27701 (PIMS), SOC 2, and compliance assessments aligned with HIPAA, GDPR, and India's DPDP Act. This is a hands-on, onsite internship designed to build practical skills in audit execution, controls testing, and compliance documentation. Responsibilities of the Intern: Assist auditors during onsite audits by taking meeting notes, supporting evidence walkthroughs, and coordinating with client stakeholders. Support audit planning activities, including scope understanding, sampling lists, and evidence requests. Perform controls testing under supervision for security, privacy, and AI governance controls. Collect, organize, and maintain audit evidence such as policies, SOPs, logs, tickets, screenshots, configurations, and training records. Maintain evidence trackers and ensure proper naming, versioning, and traceability. Map evidence to relevant standards, frameworks, Trust Services Criteria, and regulatory requirements. Support the identification of gaps, observations, opportunities for improvement (OFIs), and nonconformities. Draft audit documentation, including checklists, working papers, meeting minutes, and summary notes. Assist with corrective and preventive action (CAPA) tracking and closure documentation. Update audit trackers, risk registers, Statement of Applicability (SoA), controls mapping sheets, and project documentation. Coordinate with internal teams for scheduling, logistics, and documentation. Maintain confidentiality and comply with internal information security policies. Gain exposure to frameworks including ISO/IEC 27001:2022, ISO/IEC 42001:2023, ISO/IEC 27701:2019, SOC 2, HIPAA, GDPR, and the DPDP Act (India), based on project allocation. Requirements: Currently pursuing or recently completed a degree in Information Security, Computer Science, Information Technology, Risk & Compliance, Cybersecurity, Law/Policy (Technology), or a related field. Basic understanding of cybersecurity audit concepts and frameworks. Preferred Skills: Familiarity with ISO 27001 controls, SOC 2, GDPR, HIPAA, DPDP, risk assessment, or privacy principles. Interest in AI governance, AI risk, and model lifecycle concepts, particularly for ISO 42001 projects. Learning Outcomes: Gain an understanding of certification and assurance audit processes and evidence evaluation. Improve professional documentation skills, including working papers, checklists, summaries, and CAPA tracking. Develop exposure to multi-framework compliance across security, privacy, and AI governance. Professional Expectations: Maintain strict confidentiality and adhere to security policies. Be punctual and dependable for onsite schedules and client meetings. Demonstrate attention to detail and a willingness to learn. Maintain professionalism while interacting with clients and internal teams. Potential Full-Time Opportunity: Based on performance, selected interns may be considered for conversion to a full-time position upon completion of the six-month internship.