Skip to content

Open nowPosted 2 days agoWe saw it 72 min after it went up

Senior Security Engineer GRC Engineering

Jobgether3,933 open roles

Where
India
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Security Engineer GRC EngineeringJobgether · India
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Jobgether's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.3% of postings close within 7 days. Measured by our own scanner across the market. Jobgether postings stay open a median of 6 days.

Share of postings closed within
  1. 1.9%1 day
  2. 4.0%3 days
  3. 8.3%7 days
  4. 15.3%14 days
  5. 34.2%30 days
This job: posted 2 days ago

Jobgether median: 6 days open

The posting

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Engineer GRC Engineering based in India.

This is a senior individual contributor role focused on modernizing governance, risk, and compliance through engineering, automation, and continuous control monitoring. You will build the systems and frameworks that turn security and compliance requirements into measurable, reusable, and continuously monitored controls. The role spans cloud environments, identity platforms, code repositories, endpoints, ticketing systems, and other sources of audit evidence. You will establish a centralized controls framework that supports multiple regulatory and compliance requirements while reducing duplicated effort. Your work will help transform audit evidence from manually assembled documentation into reliable, queryable data and automated workflows. The environment is global, technically hands-on, and highly collaborative, with significant ownership over the direction of the compliance engineering program. This opportunity is ideal for someone who combines strategic GRC expertise with the engineering skills needed to build scalable compliance automation.

Accountabilities

  • Own the end-to-end continuous control monitoring program, integrating identity providers, cloud platforms, code repositories, endpoint management, ticketing systems, and other relevant data sources.
  • Build monitoring and alerting workflows that identify degraded controls, route issues to accountable owners, and verify remediation.
  • Develop and maintain a centralized common controls framework using ISO 27001 and SOC 2 as foundational frameworks, while mapping additional regulatory and compliance requirements against it.
  • Create an evidence management layer that captures, timestamps, indexes, and reuses audit evidence across multiple frameworks.
  • Design the compliance platform so that its own activity, controls, and evidence remain auditable and aligned with the standards it measures.
  • Develop control validations as code, producing outputs that are actionable for engineers and suitable for audit and assessment purposes.
  • Collaborate with infrastructure security teams on policy-as-code initiatives and ensure enforced policies generate the evidence required by applicable frameworks.
  • Identify appropriate applications for AI and agentic workflows in control mapping, evidence classification, validation, and other compliance activities while maintaining appropriate human oversight.
  • Set the strategic direction of the compliance engineering program, including framework priorities, automation opportunities, and allocation of engineering resources.
  • Develop and monitor program metrics covering control health, framework coverage, remediation velocity, and other indicators used by leadership.
  • Integrate cyber risk management into the compliance platform, connecting risk registers, exceptions, control telemetry, ownership, and expiration tracking.
  • Maintain accurate asset prioritization to support risk decisions, control coverage, remediation sequencing, and compliance activities.
  • Provide technical leadership during audits by explaining how controls are implemented, monitored, and evidenced to assessors and other stakeholders.
  • Work closely with compliance analysts and other security teams to automate workflows while ensuring areas requiring human judgment remain appropriately governed.
  • 6+ years of experience spanning compliance program leadership, security engineering, or compliance engineering, with meaningful experience across both governance/framework work and technical implementation.
  • Demonstrated experience leading a major compliance framework through assessment, readiness, certification, or authorization, such as FedRAMP or a comparable framework, or significant ownership of an end-to-end GRC engineering program involving continuous monitoring and evidence automation.
  • Strong experience designing and mapping controls across multiple frameworks, with the ability to establish a practical and defensible common controls structure.
  • Recent hands-on engineering experience using Python and APIs for integrations and automation.
  • Recent experience building or implementing AI-assisted compliance or security workflows, ideally within the last six months, with a clear understanding of how to validate automated outputs.
  • Strong knowledge of ISO 27001 and SOC 2, with familiarity with FedRAMP 20x, NIS2, DORA, and PCI DSS.
  • Understanding of policy-as-code concepts and the role of automated enforcement within security and compliance programs.
  • Sufficient Azure and AWS knowledge to identify where relevant compliance evidence is generated and how cloud controls can be monitored.
  • Experience with compliance automation or GRC platforms and the judgment to determine when to configure existing capabilities versus build custom solutions.
  • Experience managing audit calendars, assessor relationships, evidence requests, and technical audit discussions.
  • Strong understanding of risk management, exception handling, control ownership, remediation tracking, and asset prioritization.
  • Ability to communicate technical compliance concepts clearly to both engineers and auditors.
  • Strong analytical, problem-solving, and organizational skills, with the ability to manage competing priorities and make sound risk-based decisions.
  • Experience working with hosted services and customer-deployed software is advantageous.
  • Experience on the assessor side, IRAP or other international regulatory regimes, or previous experience as a software/platform engineer is a plus.
  • Remote working opportunity based in India.
  • Senior individual contributor role with significant ownership of the GRC engineering strategy and roadmap.
  • Opportunity to build and modernize compliance engineering capabilities from the ground up.
  • Exposure to cloud security, continuous control monitoring, policy-as-code, AI-assisted compliance, and automated evidence management.
  • Direct opportunity to influence how security and compliance programs support audits, certifications, customer requirements, and market expansion.
  • Globally distributed and collaborative working environment.
  • Opportunities for professional development, technical growth, and expanded security leadership responsibilities.
  • Employee-focused health and wellbeing programs.
  • Inclusive and equal-opportunity workplace committed to a respectful and supportive environment.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Jobgether's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Jobgether's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Jobgether's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.