Senior GRC Engineer

Qualys

Maharashtra

On-site

INR 2,500,000 - 4,000,000

Full time

7 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Qualys is seeking a Senior GRC Engineer to design, scale, and automate governance, risk, and compliance frameworks across cloud environments. You will map NIST/ISO controls, build libraries, automate evidence collection, and drive audit readiness with engineering teams.

Strong experience with risk management frameworks, IAM, and JSON/YAML data modeling is required to succeed in this role.

Qualifications

  • Implement ISO 27001/27002 and NIST frameworks across environments.
  • Prepare environments for external audits with evidence management.
  • Deep understanding of ISO and NIST RMFs, risk assessment, and remediation workflows.
  • Experience with cloud IAM and security technologies.
  • Experience using JSON/YAML to define validation logic and metadata.

Responsibilities

  • Framework Architecture & Control Management.
  • Design Control Libraries: build scalable, reusable libraries across the org.
  • Framework Mapping: translate standards into standardized control definitions.
  • Risk & Policy Alignment: map evidence requirements across frameworks for ISO/NIST.
  • Compliance Automation & Evidence Engineering: automate evidence collection and validation.
  • Evidence Modeling: define standardized artifacts and assessment criteria.
  • Engineering Collaboration: partner with engineering to build automated evidence pipelines.
  • Data-Driven GRC: model content in JSON/YAML to scale framework content.
  • Audit Readiness & Framework Implementation: drive practical design and mapping of NIST/ISO controls.
  • Assessment Guidance: define implementation guidance and self-assessment criteria.
  • Continuous Improvement: refine GRC workflows and tooling.

Skills

ISO 27001/27002
NIST SP 800-53
NIST CSF
NIST RMF
PCI DSS
SOC 2
CIS Controls
Cloud Platforms
IAM
JSON/YAML
Evidence Management
Automation
Audit Readiness

Tools

ServiceNow GRC
Vanta
Drata
Anecdotes
Custom GRC platforms

Job description

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

We are seeking Senior GRC Engineer to design, scale, and automate security governance, risk, and compliance frameworks. In this role, you will bridge the gap between compliance requirements and technical execution by automation for frameworks like NIST and ISO standards, building standardized control libraries, mapping multi-standard frameworks, and driving audit readiness.

If you have a strong foundation in risk management frameworks (NIST, ISO 27001/2) and an engineering-minded approach to control implementation and evidence automation, you will thrive in this position.

Key Responsibilities:
  • Framework Architecture & Control Management
  • Design Control Libraries: Build and maintain scalable, reusable security and compliance control libraries across the organization.
  • Framework Mapping: Translate complex regulatory and industry standards into standardized, actionable control definitions.
  • Risk & Policy Alignment: Map evidence requirements across overlapping compliance frameworks to eliminate redundancy and support the ISO & NIST Risk Management Frameworks.
  • Compliance Automation & Evidence Engineering
  • Evidence Modeling: Define standardized evidence artifacts, validation logic, and assessment criteria for automated control evaluation.
  • Engineering Collaboration: Partner with engineering and security teams to build automated evidence collection pipelines and continuous compliance monitoring.
  • Data-Driven GRC: Build compliance content and metadata rule libraries using structured data formats (JSON/YAML) to scale platform capabilities.
  • Audit Readiness & Framework Implementation
  • NIST & ISO Implementation: Drive the practical design, implementation, and mapping of NIST (CSF / SP 800-53 / RMF / SOC 2) and ISO 27001/27002 control frameworks across technical environments.
  • Assessment Guidance: Define clear implementation guidance, control validation criteria, and self-assessment objectives for technical teams.
  • Continuous Improvement: Continuously refine GRC workflows, tooling, and framework content as standards and organizational needs evolve.
Qualifications & Skills:
Required Experience
  • Framework Implementation: Required hands-on experience implementing, operationalizing, and mapping ISO 27001/27002 and NIST SP 800-53 / NIST CSF / NIST RMF frameworks. Experience with PCI DSS, SOC 2, and CIS Controls is a strong plus.
  • Audit Readiness: Demonstrated ability to prepare technical environments and control owners for external audits through structured evidence management and control readiness models.
  • Risk Management: Deep understanding of ISO and NIST Risk Management Frameworks, including risk assessment methodologies, control testing, and remediation workflows.
  • Technical Aptitude: Understanding cloud platforms (AWS, Azure, or GCP), Identity & Access Management (IAM), and core security technologies.
  • Data & Automation: Experience working with structured data formats (JSON, YAML) to define validation logic or control metadata.
  • Evidence Management: Familiarity with evidence mapping, automated evidence validation, and modern compliance testing concepts.
Professional Competencies
  • Analytical Thinking: Ability to decompose complex regulatory texts into clear, practical engineering specifications.
  • Cross-Functional Collaboration: Excellent technical communication skills with the ability to bridge conversations between technical engineers, product teams, and management.
  • Documentation & Precision: High attention to detail in defining control definitions, test procedures, and architectural mappings.
Preferred Qualifications (Bonus)
  • Industry certifications such as CISA, CRISC, CISM, or CISSP.
  • Hands‑on experience with GRC automation platforms (e.g., ServiceNow GRC, Vanta, Drata, Anecdotes, or custom GRC platforms).
  • Background in software engineering, security engineering, or compliance automation.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC Specialist
GRC Specialist

Keka Technologies Private Limited • Ernakulam

On-site
INR 1,200,000 - 1,800,000
GRC Analyst
GRC Analyst

AiVantage Inc (Global) • Ahmedabad District

On-site
INR 800,000 - 1,200,000
GRC Solutions Engineer
GRC Solutions Engineer

Globals Inc. • Bengaluru

On-site
INR 1,500,000 - 2,100,000
GRC
GRC

Deloitte Shared Services India • Bengaluru

On-site
INR 2,000,000 - 2,500,000
Product GRC Consultant
Product GRC Consultant

CyRAACS™ • Bengaluru

On-site
INR 600,000 - 1,200,000
Senior IT Audit & Compliance Specialist
Senior IT Audit & Compliance Specialist

Growth For Impact • Bengaluru

On-site
INR 1,400,000 - 2,200,000
Senior GRC Engineer
Senior GRC Engineer

Razorpay • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Cybersecurity GRC Consultant
Cybersecurity GRC Consultant

Sisainfosec • Mumbai

On-site
INR 1,200,000 - 2,400,000
GRC Consultant
GRC Consultant

Lonvec Technologies Private Limited • Hyderabad

On-site
INR 1,200,000 - 2,200,000
Senior GRC Analyst
Senior GRC Analyst

3M HEALTHCARE • Hyderabad

On-site
INR 1,500,000 - 2,200,000