Fractional GRC Expert. Framework Implementation for B2B Compliance Automation Platform
Worldwide
Project Overview We are building a B2B SaaS compliance automation platform for the German Mittelstand. We need an experienced German-native GRC expert to lead the framework interpretation and implementation work that turns regulatory text into machine-readable controls, evidence mappings, GRC workflows and audit-ready product artefacts. This is a mixed engagement combining hands-on authoring, methodology validation and pre-launch sign-off. You will be a core contributor to what ships in the product. Scope of Work: Framework Interpretation Core * Decompose the regulatory text of ISO 27001, TISAX (VDA-ISA 6.0), NIS2 (including NIS2UmsuCG) and GDPR into discrete, testable control statements in structured JSON. * Define evidence-type ontologies specifying what evidence satisfies each control, mapped to standard source systems (Microsoft 365, Entra ID, HRIS, cloud providers). * Build cross-framework mapping tables so the same evidence can satisfy multiple frameworks at once. * Author programmatic test procedures for each control (query logic, pass/fail criteria, edge cases, remediation guidance). Scope of Work · GRC Workflow Modules * Design risk assessment methodology plus risk register templates (ISO 27001 Clause 6, NIS2 Article 21(2)(a)). * Design Third-Party Risk Management workflows and vendor risk assessment templates (GDPR Article 28, ISO 27001 A.5.19 to A.5.22, NIS2 supply chain security). * Author incident response plan templates and reporting timeline workflows (NIS2 24-hour early warning / 72-hour notification / 1-month final report, GDPR 72-hour breach notification). * Design asset inventory schema plus classification model (ISO 27001 A.5.9, NIS2 asset visibility requirements). * Design GDPR Article 30 Records of Processing Activities structure, data flow mapping templates and DPIA workflow. * Author Business Continuity Plan templates and Disaster Recovery test workflows (ISO 27001 A.5.29 to A.5.30, NIS2 Article 21(2)(c)). * Design training and awareness tracking data model with per-role curricula per framework (ISO 27001 A.6.3, NIS2 Article 21(2)(i)). * Design internal audit / self-assessment workflows including gap analysis and remediation tracking. Scope of Work: Product Content * Draft 15 to 20 core policy templates per framework in native German (DIN 5008 formatting). * Write native-German UI copy for controls, evidence prompts and remediation guidance. * Design auditor-facing evidence pack templates (PDF and Excel) formatted for VDA, DEKRA, TÜV and DQS style. Scope of Work: Validation and Launch * Validate the framework interpretation with 2 to 3 design partner compliance owners and coordinate an external auditor review. * Sign off on the methodology for the first production release. * Establish ongoing regulatory monitoring cadence (BSI, DSK, ENISA, EC delegated acts, VDA publications). * Support customer success and sales on compliance questions, RFP answers and security questionnaire responses post-launch. Required Qualifications * Native German (C2) plus fluent business English (C1 minimum). * 5+ years hands-on experience in information security compliance in DACH. * ISO 27001 Lead Auditor certification (mandatory). * TISAX assessor experience or equivalent VDA-ISA depth (strongly preferred). * Practical familiarity with NIS2 implementation in Germany (NIS2UmsuCG, BSI KRITIS regulations). * Solid GDPR technical-controls understanding (data protection by design, Article 32, Article 30 RoPA). * Experience designing GRC workflows (risk register, TPRM, incident response, BCP) inside a product or ISMS. * Comfort with structured content authoring (JSON, YAML, control catalogs). * Excellent use of AI tools. * Ability to work with product and engineering teams to translate regulation into machine-testable form. Duration and Commitment Mixed engagement, project-based deliverables plus ongoing part-time retainer. * Phase 1 (weeks 1 to 4): Framework authoring. * Phase 2 (weeks 5 to 11): Product content plus validation. * Ongoing after launch: retainer for regulatory monitoring, framework updates and customer/sales support. Rate Open to discussion based on scope, experience and availability. Please indicate your preferred rate structure in your application: daily rate, monthly retainer or hybrid. Location and Working Mode Remote-first, DACH-based preferred. Working language with the engineering team is English. All source material and product content is bilingual (German first, English second). Confidentiality NDA required before any specific framework interpretation, product architecture or customer details are shared. How to Apply Send a short message including: 1. Which of the four frameworks (ISO 27001, TISAX, NIS2, GDPR) you consider your primary depth. 2. A specific example of a framework interpretation, GRC workflow design or control catalog you have authored (redacted if under NDA). 3. Your availability window and preferred engagement structure. 4. Your rate expectations. Please be very clear about this.
- More than 30 hrs/weekHourly
- 3-6 monthsDuration
- ExpertExperience Level
- Remote Job
- Ongoing projectProject Type
Skills and Expertise
Activity on this job
- Proposals:5 to 10
- Last viewed by client:yesterday
- Interviewing:3
- Invites sent:3
- Unanswered invites:1
About the client
- AustraliaAdelaide3:35 PM
- Tech & ITIndividual client
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by