Skip to content
← Back to job listings

Senior GRC Engineer

jobgether · India

RemoteExternal listingfull-time10 days ago

About The Role

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior GRC Engineer based in India.

This role offers the opportunity to strengthen cybersecurity programs by combining governance, risk management, and engineering <expertise.You> will help organizations improve their security posture through modern GRC practices, continuous assurance, and risk-based decision-making.The position goes beyond traditional compliance by applying engineering principles to create practical, scalable security <solutions.You> will collaborate with technical teams, system owners, and leadership to support secure architectures and mission-critical environments.The ideal candidate brings deep cybersecurity knowledge, strong analytical skills, and experience working within complex security frameworks.This is a high-impact role focused on advancing security maturity through automation, modernization, and innovative risk management approaches.

Accountabilities

  • Maintain and enhance the cybersecurity posture of assigned systems and environments by applying security engineering and governance best practices.
  • Guide system owners, security teams, and engineering stakeholders in implementing GRC principles throughout the system lifecycle.
  • Lead Risk Management Framework activities, including system categorization, control implementation, security assessments, authorization processes, and continuous monitoring.
  • Develop and maintain high-quality security documentation, policies, assessment materials, and technical artifacts aligned with cybersecurity objectives.
  • Support Authority to Operate (ATO) processes, manage remediation activities, and track Plans of Action and Milestones (POA&Ms).
  • Provide security risk briefings and recommendations to leadership, helping stakeholders make informed decisions.
  • Integrate security practices into modern development environments through DevSecOps, CI/CD security workflows, and continuous security approaches.
  • Support Zero Trust initiatives, supply chain risk management, cloud security modernization, and emerging technology security efforts.
  • Evaluate and improve security controls using industry frameworks such as NIST RMF, NIST Cybersecurity Framework, and CIS Critical Security Controls.
  • Apply automation, engineering practices, and innovative approaches to improve compliance efficiency and continuous monitoring maturity.
  • Analyze vulnerabilities, security risks, network architectures, identity solutions, and technology implementations to strengthen confidentiality, integrity, and availability.
  • Collaborate with engineering and security teams to improve security outcomes across IT and operational technology environments.

Requirements

  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent additional professional experience.
  • 7+ years of experience in cybersecurity, governance, risk management, or security engineering roles.
  • 3+ years of experience supporting Information System Security Officer (ISSO) responsibilities within federal environments.
  • Experience managing security authorization processes, ATOs, POA&Ms, and executive-level risk reporting.
  • Strong knowledge of NIST Risk Management Framework (RMF), NIST Cybersecurity Framework, and cybersecurity documentation practices.
  • Experience with FedRAMP standards, cloud service models (IaaS, PaaS, SaaS), and platforms such as Azure, Microsoft 365, Salesforce, ServiceNow, Appian, or MuleSoft.
  • Understanding of DevSecOps practices, CI/CD pipelines, Zero Trust architectures, supply chain risk management, and modern security engineering approaches.
  • Familiarity with security testing and development tools, including SAST, DAST, Software Composition Analysis, secrets management, and GitHub workflows.
  • Experience with Infrastructure as Code, virtualization, containerization, endpoint security, SIEM platforms, and integrity monitoring solutions.
  • Knowledge of identity and access management technologies, including authentication, authorization, SAML, OAuth, OIDC, and identity federation.
  • Familiarity with PKI, encryption technologies, FIPS requirements, and security architecture principles.
  • Ability to assess vulnerabilities using CVE, CWE, and CVSS methodologies.
  • Experience with OSCAL, machine-readable security documentation, and automated compliance approaches is a plus.
  • Strong technical writing, communication, and stakeholder management skills.
  • Ability to evaluate supplier security risks and technology trustworthiness.
  • Relevant cybersecurity certifications such as CISSP, CISM, CISA, CAP, CCSP, SSCP, CASP, GPEN, GMON, GSEC, GSLC, or equivalent are preferred.
  • Ability to obtain a Public Trust clearance.

Benefits

  • Competitive compensation package.
  • Comprehensive benefits designed to support employee well-being.
  • Fully remote work environment with flexibility.
  • Opportunity to work on impactful cybersecurity initiatives supporting mission-critical systems.
  • Collaborative culture focused on technical excellence and professional growth.
  • Opportunities to develop expertise in modern security engineering, automation, and risk management practices.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing