Senior Security Engineer, GRC Engineering
New
J
JobgetherSecurity compliance
Remote working opportunity based in India.Full-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 6+ years of experience spanning compliance program leadership, security engineering, or compliance engineering
- Required Skills
- AWSPythonAzureRESTful APIs
Requirements
- Have 6+ years of experience spanning compliance program leadership, security engineering, or compliance engineering, with meaningful experience in both governance/framework work and technical implementation.
- Have led a major compliance framework through assessment, readiness, certification, or authorization, such as FedRAMP or a comparable framework, or owned an end-to-end GRC engineering program involving continuous monitoring and evidence automation.
- Have experience designing and mapping controls across multiple frameworks and establishing a practical, defensible common controls structure.
- Have recent hands-on engineering experience using Python and APIs for integrations and automation.
- Have recent experience building or implementing AI-assisted compliance or security workflows and understand how to validate automated outputs.
- Have strong knowledge of ISO 27001 and SOC 2, with familiarity with FedRAMP 20x, NIS2, DORA, and PCI DSS.
- Understand policy-as-code concepts and automated enforcement within security and compliance programs.
- Have sufficient Azure and AWS knowledge to identify where compliance evidence is generated and how cloud controls can be monitored.
- Have experience with compliance automation or GRC platforms and determining when to configure existing capabilities versus build custom solutions.
- Have experience managing audit calendars, assessor relationships, evidence requests, and technical audit discussions.
- Understand risk management, exception handling, control ownership, remediation tracking, and asset prioritization.
- Be able to communicate technical compliance concepts clearly to engineers and auditors.
Responsibilities
- Own the continuous control monitoring program and integrate identity providers, cloud platforms, code repositories, endpoint management, ticketing systems, and other data sources.
- Build monitoring and alerting workflows to identify degraded controls, route issues to owners, and verify remediation.
- Develop and maintain a centralized common controls framework using ISO 27001 and SOC 2, mapping additional requirements against it.
- Create an evidence management layer that captures, timestamps, indexes, and reuses audit evidence across frameworks.
- Design the compliance platform so its activity, controls, and evidence remain auditable and aligned with the standards it measures.
- Develop control validations as code and collaborate with infrastructure security teams on policy-as-code initiatives.
- Identify appropriate applications for AI and agentic workflows in compliance activities while maintaining human oversight.
- Set the compliance engineering program’s strategic direction and develop metrics for control health, framework coverage, and remediation velocity.
- Integrate cyber risk management, including risk registers, exceptions, control telemetry, ownership, and expiration tracking.
- Provide technical leadership during audits and work with compliance analysts and security teams to automate workflows.
View Full Description & ApplyYou'll be redirected to the employer's site