Enterprise customers choose Rubiscape notonly for its platform capabilities but for the trust it embodies — trust builton rigorous compliance with ISO 27001, SOC 2, the DPDP Act 2023, andsector-specific frameworks across BFSI, healthcare, and government. AsCompliance & GRC Engineer, you will own Rubiscape’s governance, risk, andcompliance programme: designing the control framework, managing audit cycles,and bridging the gap between regulatory obligation and engineering reality. Youwill be the custodian of the trust posture that enables Rubiscape to win andretain Fortune 500 and public sector accounts.
Key Responsibilities
- Own and maintain Rubiscape’s ISO 27001 ISMS and SOC 2 Type II compliance programmes — including control design, evidence collection, audit readiness, and ongoing surveillance.
- Interpret and operationaliseIndia’s DPDP Act 2023 requirements within the Rubiscape platform and internaldata handling processes; maintain the data processing register and consentmanagement documentation.
- Conduct and coordinate annualrisk assessments: asset inventory, threat-risk mapping, control gap analysis,and residual risk acceptance with business owners.
- Manage the vendor andthird-party risk programme — security questionnaires, due diligence forintegrations, and contractual security obligations.
- Respond to customer securityquestionnaires, RFP security sections, and enterprise trust reviews; maintain aGRC knowledge base of pre-approved answers and evidence artefacts.
- Design and deliver securityawareness training and role-based compliance training for all Rubiscapeemployees on a recurring annual cycle.
- Track regulatory changes(CERT-IN directives, MeitY notifications, RBI/SEBI cybersecurity circulars) andassess their impact on Rubiscape’s compliance posture within 30 days ofpublication.
Nice to Have
- Certifications: CISA, CISM,CRISC, ISO 27001 Lead Auditor/Implementer, or CCSK.
- Experience with GRC platforms(ServiceNow GRC, Vanta, Drata, or Tugboat Logic) for automated evidencecollection and continuous compliance monitoring.
- Familiarity withsector-specific Indian compliance frameworks: RBI’s IT Framework for Banks,IRDAI Cybersecurity Guidelines, or HIPAA-equivalent controls for healthcaredata.
- Prior experience supportinggovernment or defence customer security accreditation processes in India (MeitYempanelment, STQC, or NIC security guidelines).
About Rubiscape
Rubiscape is India’s leading DecisionIntelligence Platform, unifying data engineering, BI, machine learning, andagentic AI in a single governed platform. Built in Pune and trusted by Fortune500 enterprises across BFSI, manufacturing, healthcare, and government. 8international innovation patents. 10 Industry-Academia Labs & COEs. From BIto AI — One Platform. Every Decision.
Requirements
- 4+ years of GRC, informationsecurity compliance, or audit experience in a technology company or Big-4 /consulting firm serving technology clients.
- Demonstrated ownership of ISO27001 certification or SOC 2 Type II audit cycles, including working directlywith external auditors.
- Working knowledge of India’sDPDP Act 2023 and its operational implications for a SaaS platform collectingand processing personal data.
- Ability to translate regulatoryand audit requirements into actionable engineering controls and work withsoftware and infrastructure teams on implementation.
- Strong written communicationskills for policy drafting, risk documentation, board-level risk reporting, andcustomer-facing trust documentation.