Compliance & GRC Engineer

Posted 4 Days Ago
Be an Early Applicant
Pune, Maharashtra, IND
In-Office
Mid level
Artificial Intelligence • Software • Analytics • Business Intelligence
The Role
Own Rubiscape’s ISO 27001 ISMS and SOC 2 Type II programs, including control design, evidence collection, audit readiness, and surveillance. Operationalize DPDP Act requirements, manage risk assessments and vendor risk, respond to customer security reviews, deliver compliance training, and monitor regulatory changes. Translate regulatory obligations into engineering controls while maintaining policies, risk documentation, data-processing records, and trust evidence.
Summary Generated by Built In
About the Role

Enterprise customers choose Rubiscape not only for its platform capabilities but for the trust it embodies — trust built on rigorous compliance with ISO 27001, SOC 2, the DPDP Act 2023, and sector-specific frameworks across BFSI, healthcare, and government. As Compliance & GRC Engineer, you will own Rubiscape’s governance, risk, and compliance programme: designing the control framework, managing audit cycles, and bridging the gap between regulatory obligation and engineering reality. You will be the custodian of the trust posture that enables Rubiscape to win and retain Fortune 500 and public sector accounts.

 

Key Responsibilities

·         Own and maintain Rubiscape’s ISO 27001 ISMS and SOC 2 Type II compliance programmes — including control design, evidence collection, audit readiness, and ongoing surveillance.

·         Interpret and operationalise India’s DPDP Act 2023 requirements within the Rubiscape platform and internal data handling processes; maintain the data processing register and consent management documentation.

·         Conduct and coordinate annual risk assessments: asset inventory, threat-risk mapping, control gap analysis, and residual risk acceptance with business owners.

·         Manage the vendor and third-party risk programme — security questionnaires, due diligence for integrations, and contractual security obligations.

·         Respond to customer security questionnaires, RFP security sections, and enterprise trust reviews; maintain a GRC knowledge base of pre-approved answers and evidence artefacts.

·         Design and deliver security awareness training and role-based compliance training for all Rubiscape employees on a recurring annual cycle.

·         Track regulatory changes (CERT-IN directives, MeitY notifications, RBI/SEBI cybersecurity circulars) and assess their impact on Rubiscape’s compliance posture within 30 days of publication.

Nice to Have

·         Certifications: CISA, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, or CCSK.

·         Experience with GRC platforms (ServiceNow GRC, Vanta, Drata, or Tugboat Logic) for automated evidence collection and continuous compliance monitoring.

·         Familiarity with sector-specific Indian compliance frameworks: RBI’s IT Framework for Banks, IRDAI Cybersecurity Guidelines, or HIPAA-equivalent controls for healthcare data.

·         Prior experience supporting government or defence customer security accreditation processes in India (MeitY empanelment, STQC, or NIC security guidelines).

 

 

 

About Rubiscape

Rubiscape is India’s leading Decision Intelligence Platform, unifying data engineering, BI, machine learning, and agentic AI in a single governed platform. Built in Pune and trusted by Fortune 500 enterprises across BFSI, manufacturing, healthcare, and government. 8 international innovation patents. 10 Industry-Academia Labs & COEs. From BI to AI — One Platform. Every Decision.



RequirementsRequirements

·         4+ years of GRC, information security compliance, or audit experience in a technology company or Big-4 / consulting firm serving technology clients.

·         Demonstrated ownership of ISO 27001 certification or SOC 2 Type II audit cycles, including working directly with external auditors.

·         Working knowledge of India’s DPDP Act 2023 and its operational implications for a SaaS platform collecting and processing personal data.

·         Ability to translate regulatory and audit requirements into actionable engineering controls and work with software and infrastructure teams on implementation.

·         Strong written communication skills for policy drafting, risk documentation, board-level risk reporting, and customer-facing trust documentation.

 



Skills Required

  • 4+ years of GRC, information security compliance, or audit experience in a technology company or technology-focused Big Four or consulting firm
  • Experience owning ISO 27001 certification or SOC 2 Type II audit cycles
  • Experience working directly with external auditors
  • Working knowledge of India’s DPDP Act 2023 and its implications for SaaS platforms processing personal data
  • Ability to translate regulatory and audit requirements into actionable engineering controls
  • Ability to work with software and infrastructure teams on control implementation
  • Strong written communication skills for policy drafting, risk documentation, board-level risk reporting, and customer-facing trust documentation
  • CISA, CISM, CRISC, ISO 27001 Lead Auditor or Implementer, or CCSK certification
  • Experience with ServiceNow GRC, Vanta, Drata, or Tugboat Logic
  • Familiarity with Indian sector-specific compliance frameworks, including RBI, IRDAI, or healthcare controls
  • Experience supporting government or defense customer security accreditation processes in India
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
30 Employees
Year Founded: 2018

What We Do

Rubiscape is a decision intelligence platform that unifies business intelligence, analytics, data science, and artificial intelligence in one place, helping organizations move from BI to AI. Its technology and product-development work spans AI-focused development, software engineering, product management, agile delivery, security operations, and DevOps, reflecting a software platform mission centered on enabling data-driven decisions across modern organizations.

Similar Jobs

Hybrid
2 Locations
289097 Employees

UL Solutions Logo UL Solutions

Project Engineer

Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Hybrid
Mumbai, Maharashtra, IND
15000 Employees

UL Solutions Logo UL Solutions

Senior Sales Executive

Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Hybrid
2 Locations
15000 Employees

UL Solutions Logo UL Solutions

Engineer Project Associate - Fire Suppression Products

Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Hybrid
Mumbai, Maharashtra, IND
15000 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account