Senior Security Engineer, GRC Engineering

New
J
JobgetherSecurity compliance
Remote working opportunity based in India.Full-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
6+ years of experience spanning compliance program leadership, security engineering, or compliance engineering
Required Skills
AWSPythonAzureRESTful APIs

Requirements

  • Have 6+ years of experience spanning compliance program leadership, security engineering, or compliance engineering, with meaningful experience in both governance/framework work and technical implementation.
  • Have led a major compliance framework through assessment, readiness, certification, or authorization, such as FedRAMP or a comparable framework, or owned an end-to-end GRC engineering program involving continuous monitoring and evidence automation.
  • Have experience designing and mapping controls across multiple frameworks and establishing a practical, defensible common controls structure.
  • Have recent hands-on engineering experience using Python and APIs for integrations and automation.
  • Have recent experience building or implementing AI-assisted compliance or security workflows and understand how to validate automated outputs.
  • Have strong knowledge of ISO 27001 and SOC 2, with familiarity with FedRAMP 20x, NIS2, DORA, and PCI DSS.
  • Understand policy-as-code concepts and automated enforcement within security and compliance programs.
  • Have sufficient Azure and AWS knowledge to identify where compliance evidence is generated and how cloud controls can be monitored.
  • Have experience with compliance automation or GRC platforms and determining when to configure existing capabilities versus build custom solutions.
  • Have experience managing audit calendars, assessor relationships, evidence requests, and technical audit discussions.
  • Understand risk management, exception handling, control ownership, remediation tracking, and asset prioritization.
  • Be able to communicate technical compliance concepts clearly to engineers and auditors.

Responsibilities

  • Own the continuous control monitoring program and integrate identity providers, cloud platforms, code repositories, endpoint management, ticketing systems, and other data sources.
  • Build monitoring and alerting workflows to identify degraded controls, route issues to owners, and verify remediation.
  • Develop and maintain a centralized common controls framework using ISO 27001 and SOC 2, mapping additional requirements against it.
  • Create an evidence management layer that captures, timestamps, indexes, and reuses audit evidence across frameworks.
  • Design the compliance platform so its activity, controls, and evidence remain auditable and aligned with the standards it measures.
  • Develop control validations as code and collaborate with infrastructure security teams on policy-as-code initiatives.
  • Identify appropriate applications for AI and agentic workflows in compliance activities while maintaining human oversight.
  • Set the compliance engineering program’s strategic direction and develop metrics for control health, framework coverage, and remediation velocity.
  • Integrate cyber risk management, including risk registers, exceptions, control telemetry, ownership, and expiration tracking.
  • Provide technical leadership during audits and work with compliance analysts and security teams to automate workflows.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now