Senior GRC Engineer

Razorpay

Bengaluru

On-site

INR 1,500,000 - 2,100,000

Full time

6 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Razorpay seeks an experienced GRC engineer to blend regulatory and AI-native risk assessment. You will evaluate AI tools, govern data privacy, and drive evidence automation within a fintech regulatory stack including DPDP and PCI DSS.

The role focuses on building scalable, automation-first GRC systems and embedding controls into architecture and SDLC. The ideal candidate has 4+ years in GRC or security engineering, strong knowledge of ISO 27001, SOC 2, PCI DSS, and cloud security, and a hands-on

Qualifications

  • 4+ years of experience in GRC, IT audit, security, or compliance engineering.
  • Solid understanding of ISO 27001, SOC 2, PCI DSS, ITGC, and DPDP.
  • Experience with cloud security, IAM, secure SDLC, and data protection controls.

Responsibilities

  • Own the end-to-end control lifecycle: design, implementation, testing, evidence, and audit readiness.
  • Drive risk assessments, audit findings (deviations), and remediation closure with clear ownership.
  • Review cloud security, IAM, application security, and data protection controls in production systems.
  • Evaluate and govern AI/LLM systems, tools, and vendors for data security and compliance risks.
  • Build automation-first GRC systems: monitoring, evidence pipelines, and control validation.
  • Support regulatory audits with production-backed evidence and embed controls into SDLC.

Skills

GRC
IT audit
Security controls
Regulatory frameworks
Cloud security

Education

Bachelor's degree in CS/Engineering

Tools

Vanta
Drata
Secureframe

Job description

GRC engineer is a combination of two prime areas. One is regulatory and compliance depth frameworks, control design and testing, audit judgement, deviations, the Indian financial-sector stack. The other is AI-native practice assessing AI and LLM systems for compliance risk, evaluating AI tools and vendors before they are onboarded, using AI for the mechanical half of the work with validation as a reflex, and directing AI tooling to build the monitoring and evidence automation the function needs.

Razorpay operates under one of the densest regulatory stacks in Indian technology the DPDP Act 2023, RBI Payment Aggregator and Payment Gateway directions, the PPI Master Directions, RBI Digital Payment Security Controls and Cyber Security Framework expectations, PCI DSS v4.x, ISO 27001 and 27701, and SOC 2 simultaneously, not sequentially. Doing this by hand does not scale to our velocity. AI handles the highvolume, repetitive work: evidence collection and summarisation, control crosswalking, drafting test procedures, parsing audit logs, first-pass alert triage, questionnaire response. It is treated like a fast junior analyst whose output is always reviewed.

Key Responsibilities

  • Own the end-to-end control lifecycle: design, implementation, testing, evidence, and audit readiness
  • Drive risk assessments, audit findings (deviations), and remediation closure with clear ownership
  • Review cloud security (AWS/GCP), IAM, application security, and data protection controls in production systems
  • Evaluate and govern AI/LLM systems, tools, and vendors for data security, privacy and compliance risks
  • Build automation-first GRC systems: continuous monitoring, evidence pipelines, and control validation frameworks
  • Support and lead regulatory audits (RBI, ISO 27001, SOC 2, PCI DSS) with production-backed evidence
  • Partner with engineering to embed controls into architecture and SDLC (policy-as-code mindset)
  • Own third-party/vendor risk assessments with a strong technical lens

What We’re Looking For

  • 4+ years of experience in GRC, IT audit, security, or compliance engineering
  • Strong hands-on expertise in security and compliance frameworks (ISO 27001, SOC 2, PCI DSS, ITGC, DPDP)
  • Solid understanding of cloud security, IAM, secure SDLC, and data protection controls
  • Proven experience in risk management, audit handling and control testing
  • Exposure to AI/LLM risk, data governance and vendor security assessments
  • Ability to translate deep technical findings into business risk and actionable insights

Preferred

  • Experience in fintech or regulated environments (RBI, payments, banking)
  • Hands-on with GRC tools (Vanta, Drata, Secureframe) or compliance automation systems
  • Familiarity with automation, scripting, APIs or policy-as-code approaches
  • Experience building monitoring, evidence collection or compliance pipelines

Why This Role

  • Work on AI + Compliance + Engineering convergence
  • Build scalable, automation-first GRC systems instead of manual audit workflows
  • High ownership role influencing security posture and regulatory strategy
  • Opportunity to set the technical bar for GRC engineering
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Analyst / Senior Analyst — Governance, Risk & Compliance (GRC)
Analyst / Senior Analyst — Governance, Risk & Compliance (GRC)

NMT Security • Dadri

On-site
INR 700,000 - 1,400,000
Senior GRC Engineer
Senior GRC Engineer

Qualys • Maharashtra

On-site
INR 4,000,000 - 8,000,000
GRC Lead
GRC Lead

Baldor Technologies • Mumbai

On-site
INR 300,000 - 600,000
GRC Solutions Engineer
GRC Solutions Engineer

Globals Inc. • Bengaluru

On-site
INR 1,500,000 - 2,100,000
GRC - Security Analyst
GRC - Security Analyst

Jobgether • India

Remote
INR 1,200,000 - 1,800,000
Fully remote in India
Full-time employment
Exposure to multiple security framesk—
+2
GRC Specialist – Solution Delivery & Customer Success
GRC Specialist – Solution Delivery & Customer Success

Andpayments • Dadri

On-site
INR 1,500,000 - 2,100,000
Lead GRC
Lead GRC

Ashley Global Capability Center • Chennai District

On-site
INR 1,200,000 - 1,800,000
GRC Specialist
GRC Specialist

Keka Technologies Private Limited • Ernakulam

On-site
INR 1,200,000 - 1,800,000
GRC Lead / Security Compliance Lead
GRC Lead / Security Compliance Lead

Gnani Innovations Private Limited. • India

On-site
INR 350,000 - 600,000
Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

Power Bridge • Arishinakunte

On-site
INR 1,200,000 - 2,400,000
Health insurance
Long-term savings plan with employer’匹
Professional development opportunities