Senior GRC Engineer

Posted Yesterday
Be an Early Applicant
Pune, Mahārāshtra, IND
In-Office
Senior level
Information Technology • Security • Cybersecurity
The Role
Design and scale automated GRC frameworks by building control libraries, mapping NIST/ISO standards, modeling evidence, automating evidence collection and validation, partnering with engineering for continuous compliance, and driving audit readiness and improvement of GRC tooling and workflows.
Summary Generated by Built In

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

We are seeking Senior GRC Engineer to design, scale, and automate security governance, risk, and compliance frameworks. In this role, you will bridge the gap between compliance requirements and technical execution by automation for frameworks like NIST and ISO standards, building standardized control libraries, mapping multi-standard frameworks, and driving audit readiness.

If you have a strong foundation in risk management frameworks (NIST, ISO 27001/2) and an engineering-minded approach to control implementation and evidence automation, you will thrive in this position.

Key Responsibilities:

1. Framework Architecture & Control Management

  • Design Control Libraries: Build and maintain scalable, reusable security and compliance control libraries across the organization.
  • Framework Mapping: Translate complex regulatory and industry standards into standardized, actionable control definitions.
  • Risk & Policy Alignment: Map evidence requirements across overlapping compliance frameworks to eliminate redundancy and support the ISO & NIST Risk Management Frameworks.

2. Compliance Automation & Evidence Engineering

  • Evidence Modeling: Define standardized evidence artifacts, validation logic, and assessment criteria for automated control evaluation.
  • Engineering Collaboration: Partner with engineering and security teams to build automated evidence collection pipelines and continuous compliance monitoring.
  • Data-Driven GRC: Build compliance content and metadata rule libraries using structured data formats (JSON/YAML) to scale platform capabilities.

3. Audit Readiness & Framework Implementation

  • NIST & ISO Implementation: Drive the practical design, implementation, and mapping of NIST (CSF / SP 800-53 / RMF / SOC 2) and ISO 27001/27002 control frameworks across technical environments.
  • Assessment Guidance: Define clear implementation guidance, control validation criteria, and self-assessment objectives for technical teams.
  • Continuous Improvement: Continuously refine GRC workflows, tooling, and framework content as standards and organizational needs evolve.

Qualifications & Skills:

Required Experience

  • Framework Implementation: Required hands-on experience implementing, operationalizing, and mapping ISO 27001/27002 and NIST SP 800-53 / NIST CSF / NIST RMF frameworks. Experience with PCI DSS, SOC 2, and CIS Controls is a strong plus.
  • Audit Readiness: Demonstrated ability to prepare technical environments and control owners for external audits through structured evidence management and control readiness models.
  • Risk Management: Deep understanding of ISO and NIST Risk Management Frameworks, including risk assessment methodologies, control testing, and remediation workflows.
  • Technical Aptitude: Understanding cloud platforms (AWS, Azure, or GCP), Identity & Access Management (IAM), and core security technologies.
  • Data & Automation: Experience working with structured data formats (JSON, YAML) to define validation logic or control metadata.
  • Evidence Management: Familiarity with evidence mapping, automated evidence validation, and modern compliance testing concepts.

Professional Competencies

  • Analytical Thinking: Ability to decompose complex regulatory texts into clear, practical engineering specifications.
  • Cross-Functional Collaboration: Excellent technical communication skills with the ability to bridge conversations between technical engineers, product teams, and management.
  • Documentation & Precision: High attention to detail in defining control definitions, test procedures, and architectural mappings.

Preferred Qualifications (Bonus)

  • Industry certifications such as CISA, CRISC, CISM, or CISSP.
  • Hands-on experience with GRC automation platforms (e.g., ServiceNow GRC, Vanta, Drata, Anecdotes, or custom GRC platforms).
  • Background in software engineering, security engineering, or compliance automation.

Skills Required

  • Hands-on experience implementing, operationalizing, and mapping ISO 27001/27002 and NIST SP 800-53 / NIST CSF / NIST RMF frameworks
  • Ability to prepare technical environments and control owners for external audits via structured evidence management
  • Deep understanding of ISO and NIST Risk Management Frameworks, risk assessment methodologies, control testing, and remediation workflows
  • Understanding of cloud platforms (AWS, Azure, or GCP), Identity & Access Management (IAM), and core security technologies
  • Experience working with structured data formats (JSON, YAML) to define validation logic or control metadata
  • Familiarity with evidence mapping, automated evidence validation, and modern compliance testing concepts
  • Ability to decompose regulatory texts into practical engineering specifications; strong technical communication and cross-functional collaboration
  • Attention to detail in defining control definitions, test procedures, and architectural mappings
  • Experience with PCI DSS, SOC 2, and CIS Controls
  • Industry certifications such as CISA, CRISC, CISM, or CISSP
  • Hands-on experience with GRC automation platforms (e.g., ServiceNow GRC, Vanta, Drata, Anecdotes, or custom GRC platforms)
  • Background in software engineering, security engineering, or compliance automation

Qualys Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Qualys and has not been reviewed or approved by Qualys.

  • Affordable Benefits Benefits costs are widely viewed as low for employees and dependents, with healthcare often described as almost fully paid for. Feedback suggests this affordability helps offset perceptions of lower base pay in some roles.
  • Healthcare Strength Healthcare offerings are broad, including multiple medical plan options, dental and vision coverage, mental health support, and disability insurance. Benefits are described as “pretty amazing” or “great,” reinforcing perceived quality and coverage depth.
  • Equity Value & Accessibility Equity participation is accessible through company stock plans and an employee stock purchase plan. Compensation packages commonly include equity alongside salary and bonus, which some consider a meaningful part of total rewards.

Qualys Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Foster City, CA
2,736 Employees
Year Founded: 1999

What We Do

Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings. The Qualys Cloud Platform leverages a single agent to continuously deliver critical security intelligence while enabling enterprises to automate the full spectrum of vulnerability detection, compliance, and protection for IT systems, workloads and web applications across on premises, endpoints, servers, public and private clouds, containers, and mobile devices. Founded in 1999 as one of the first SaaS security companies, Qualys has strategic partnerships and seamlessly integrates its vulnerability management capabilities into security offerings from cloud service providers, including Amazon Web Services, the Google Cloud Platform and Microsoft Azure, along with a number of leading managed service providers and global consulting organizations. For more information, please visit http://www.qualys.com

Similar Jobs

Capco Logo Capco

RWA

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
India
6000 Employees

Capco Logo Capco

Liquidity Reporting

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
India
6000 Employees

Mondelēz International Logo Mondelēz International

Organization Capability Specialist

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
India
90000 Employees

Optum Logo Optum

Software Engineering Lead - Java Full Stack

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Pune, Mahārāshtra, IND
160000 Employees

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account