Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
Razorpay seeks an experienced GRC engineer to blend regulatory and AI-native risk assessment. You will evaluate AI tools, govern data privacy, and drive evidence automation within a fintech regulatory stack including DPDP and PCI DSS.
The role focuses on building scalable, automation-first GRC systems and embedding controls into architecture and SDLC. The ideal candidate has 4+ years in GRC or security engineering, strong knowledge of ISO 27001, SOC 2, PCI DSS, and cloud security, and a hands-on
GRC engineer is a combination of two prime areas. One is regulatory and compliance depth frameworks, control design and testing, audit judgement, deviations, the Indian financial-sector stack. The other is AI-native practice assessing AI and LLM systems for compliance risk, evaluating AI tools and vendors before they are onboarded, using AI for the mechanical half of the work with validation as a reflex, and directing AI tooling to build the monitoring and evidence automation the function needs.
Razorpay operates under one of the densest regulatory stacks in Indian technology the DPDP Act 2023, RBI Payment Aggregator and Payment Gateway directions, the PPI Master Directions, RBI Digital Payment Security Controls and Cyber Security Framework expectations, PCI DSS v4.x, ISO 27001 and 27701, and SOC 2 simultaneously, not sequentially. Doing this by hand does not scale to our velocity. AI handles the highvolume, repetitive work: evidence collection and summarisation, control crosswalking, drafting test procedures, parsing audit logs, first-pass alert triage, questionnaire response. It is treated like a fast junior analyst whose output is always reviewed.
Key Responsibilities
What We’re Looking For
Preferred
Why This Role