Live opening · Posted 11 hours ago

Senior GRC Engineer

Qualys · Pune Division, Maharashtra, India (On-site)
Linkedin No
You are 11 hours behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 11 hours ago
CompanyQualys
LocationPune Division, Maharashtra, India (On-site)
Work modeNo
SourceLinkedin
Listed11 hours ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
9 min from Linkedin publishing this role to us finding it
17 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
60,942 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
We are seeking Senior GRC Engineer to design, scale, and automate security governance, risk, and compliance frameworks. In this role, you will bridge the gap between compliance requirements and technical execution by automation for frameworks like NIST and ISO standards, building standardized control libraries, mapping multi-standard frameworks, and driving audit readiness.
If you have a strong foundation in risk management frameworks (NIST, ISO 27001/2) and an engineering-minded approach to control implementation and evidence automation, you will thrive in this position.
Key Responsibilities:
Framework Architecture & Control Management
Design Control Libraries: Build and maintain scalable, reusable security and compliance control libraries across the organization.
Framework Mapping: Translate complex regulatory and industry standards into standardized, actionable control definitions.
Risk & Policy Alignment: Map evidence requirements across overlapping compliance frameworks to eliminate redundancy and support the ISO & NIST Risk Management Frameworks.
Compliance Automation & Evidence Engineering
Evidence Modeling: Define standardized evidence artifacts, validation logic, and assessment criteria for automated control evaluation.
Engineering Collaboration: Partner with engineering and security teams to build automated evidence collection pipelines and continuous compliance monitoring.
Data-Driven GRC: Build compliance content and metadata rule libraries using structured data formats (JSON/YAML) to scale platform capabilities.
Audit Readiness & Framework Implementation
NIST & ISO Implementation: Drive the practical design, implementation, and mapping of NIST (CSF / SP 800-53 / RMF / SOC 2) and ISO 27001/27002 control frameworks across technical environments.
Assessment Guidance: Define clear implementation guidance, control validation criteria, and self-assessment objectives for technical teams.
Continuous Improvement: Continuously refine GRC workflows, tooling, and framework content as standards and organizational needs evolve.
Qualifications & Skills:
Required Experience
Framework Implementation: Required hands-on experience implementing, operationalizing, and mapping ISO 27001/27002 and NIST SP 800-53 / NIST CSF / NIST RMF frameworks. Experience with PCI DSS, SOC 2, and CIS Controls is a strong plus.
Audit Readiness: Demonstrated ability to prepare technical environments and control owners for external audits through structured evidence management and control readiness models.
Risk Management: Deep understanding of ISO and NIST Risk Management Frameworks, including risk assessment methodologies, control testing, and remediation workflows.
Technical Aptitude: Understanding cloud platforms (AWS, Azure, or GCP), Identity & Access Management (IAM), and core security technologies.
Data & Automation: Experience working with structured data formats (JSON, YAML) to define validation logic or control metadata.
Evidence Management: Familiarity with evidence mapping, automated evidence validation, and modern compliance testing concepts.
Professional Competencies
Analytical Thinking: Ability to decompose complex regulatory texts into clear, practical engineering specifications.
Cross-Functional Collaboration: Excellent technical communication skills with the ability to bridge conversations between technical engineers, product teams, and management.
Documentation & Precision: High attention to detail in defining control definitions, test procedures, and architectural mappings.
Preferred Qualifications (Bonus)
Industry certifications such as CISA, CRISC, CISM, or CISSP.
Hands-on experience with GRC automation platforms (e.g., ServiceNow GRC, Vanta, Drata, Anecdotes, or custom GRC platforms).
Background in software engineering, security engineering, or compliance automation.

Work arrangement
No

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App