
Senior GRC Engineer
jobgether · India
About The Role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior GRC Engineer based in India.
This role offers the opportunity to strengthen cybersecurity programs by combining governance, risk management, and engineering <expertise.You> will help organizations improve their security posture through modern GRC practices, continuous assurance, and risk-based decision-making.The position goes beyond traditional compliance by applying engineering principles to create practical, scalable security <solutions.You> will collaborate with technical teams, system owners, and leadership to support secure architectures and mission-critical environments.The ideal candidate brings deep cybersecurity knowledge, strong analytical skills, and experience working within complex security frameworks.This is a high-impact role focused on advancing security maturity through automation, modernization, and innovative risk management approaches.
Accountabilities
- Maintain and enhance the cybersecurity posture of assigned systems and environments by applying security engineering and governance best practices.
- Guide system owners, security teams, and engineering stakeholders in implementing GRC principles throughout the system lifecycle.
- Lead Risk Management Framework activities, including system categorization, control implementation, security assessments, authorization processes, and continuous monitoring.
- Develop and maintain high-quality security documentation, policies, assessment materials, and technical artifacts aligned with cybersecurity objectives.
- Support Authority to Operate (ATO) processes, manage remediation activities, and track Plans of Action and Milestones (POA&Ms).
- Provide security risk briefings and recommendations to leadership, helping stakeholders make informed decisions.
- Integrate security practices into modern development environments through DevSecOps, CI/CD security workflows, and continuous security approaches.
- Support Zero Trust initiatives, supply chain risk management, cloud security modernization, and emerging technology security efforts.
- Evaluate and improve security controls using industry frameworks such as NIST RMF, NIST Cybersecurity Framework, and CIS Critical Security Controls.
- Apply automation, engineering practices, and innovative approaches to improve compliance efficiency and continuous monitoring maturity.
- Analyze vulnerabilities, security risks, network architectures, identity solutions, and technology implementations to strengthen confidentiality, integrity, and availability.
- Collaborate with engineering and security teams to improve security outcomes across IT and operational technology environments.
Requirements
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent additional professional experience.
- 7+ years of experience in cybersecurity, governance, risk management, or security engineering roles.
- 3+ years of experience supporting Information System Security Officer (ISSO) responsibilities within federal environments.
- Experience managing security authorization processes, ATOs, POA&Ms, and executive-level risk reporting.
- Strong knowledge of NIST Risk Management Framework (RMF), NIST Cybersecurity Framework, and cybersecurity documentation practices.
- Experience with FedRAMP standards, cloud service models (IaaS, PaaS, SaaS), and platforms such as Azure, Microsoft 365, Salesforce, ServiceNow, Appian, or MuleSoft.
- Understanding of DevSecOps practices, CI/CD pipelines, Zero Trust architectures, supply chain risk management, and modern security engineering approaches.
- Familiarity with security testing and development tools, including SAST, DAST, Software Composition Analysis, secrets management, and GitHub workflows.
- Experience with Infrastructure as Code, virtualization, containerization, endpoint security, SIEM platforms, and integrity monitoring solutions.
- Knowledge of identity and access management technologies, including authentication, authorization, SAML, OAuth, OIDC, and identity federation.
- Familiarity with PKI, encryption technologies, FIPS requirements, and security architecture principles.
- Ability to assess vulnerabilities using CVE, CWE, and CVSS methodologies.
- Experience with OSCAL, machine-readable security documentation, and automated compliance approaches is a plus.
- Strong technical writing, communication, and stakeholder management skills.
- Ability to evaluate supplier security risks and technology trustworthiness.
- Relevant cybersecurity certifications such as CISSP, CISM, CISA, CAP, CCSP, SSCP, CASP, GPEN, GMON, GSEC, GSLC, or equivalent are preferred.
- Ability to obtain a Public Trust clearance.
Benefits
- Competitive compensation package.
- Comprehensive benefits designed to support employee well-being.
- Fully remote work environment with flexibility.
- Opportunity to work on impactful cybersecurity initiatives supporting mission-critical systems.
- Collaborative culture focused on technical excellence and professional growth.
- Opportunities to develop expertise in modern security engineering, automation, and risk management practices.
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring