Remotery

Senior Engineer, Governance, Risk & Compliance

Posted Aug 4

This is a fully remote position, open to applicants in India.

📋 Description

• Create and implement solutions utilizing GRC platforms, security technologies, and automation to enhance Information Security and GRC projects.

• Oversee enterprise GRC platforms and associated technologies, including TPRM, Risk Register, Privacy Management, Security Awareness, Identity Governance, Business Continuity, and AI Governance.

• Set up and manage workflows, forms, questionnaires, dashboards, control libraries, evidence management, and reporting functionalities.

• Conduct platform administration, upgrades, testing, user provisioning, troubleshooting, release validation, and provide technical support.

• Assist in TPRM platform setup, user support, workflow improvements, issue resolution, testing, and release validation.

• Configure and manage Identity Governance workflows, access certification campaigns, access reviews, remediation tracking, and governance reporting.

• Administer phishing tools and security awareness technologies, including simulations, training campaigns, completion tracking, and awareness reporting.

• Gather and automate operational metrics, developing CISO dashboards, executive reports, KPI/KRI metrics, and recurring reports.

• Implement workflow automation to optimize processes and minimize manual effort.

• Integrate GRC platforms with ServiceNow, IAM, CMDB, ITSM, HR systems, vulnerability management, security tools, and APIs.

• Facilitate audit and compliance platforms through configuration, workflow enhancements, reporting, issue resolution, testing, and release validation.

• Configure and manage PIA, DPIA, privacy workflows, dashboards, and reporting.

• Set up and support Business Continuity and Disaster Recovery technologies, including BIA workflows, testing schedules, resilience dashboards, remediation tracking, and evidence management.

• Configure and support AI Governance technologies, including AI risk assessment workflows, dashboards, automation, and platform enhancements.

• Collaborate with teams in Information Security, Enterprise Applications, Engineering, Infrastructure, Privacy, Internal Audit, Enterprise Risk, Compliance, and various business stakeholders.

• Assist in customer security assessments and compliance initiatives such as HITRUST, SOC 2, ISO 27001, HIPAA, PCI DSS, and others.

• Create and maintain technical documentation, SOPs, platform configuration guides, and knowledge articles.

• Identify opportunities to enhance GRC technologies, improve automation, maximize platform utilization, and suggest operational enhancements.

• Stay updated on GRC technologies, cybersecurity regulations, industry frameworks, and emerging best practices, including AI governance.


⛳️ Requirements

• Bachelor's Degree in Computer Science or a related field, or an advanced degree, or an equivalent combination of education and experience.

• 4–6 years of pertinent experience or an advanced degree.

• Proven experience in administering, configuring, and supporting GRC platforms, security technologies, and workflow automation solutions.

• Familiarity with phishing campaigns, Identity Governance, IAM, PAM, MFA, RBAC, SSO, TPRM, Risk Register, Privacy Management, workflow automation, dashboards, reporting, vulnerability management, and related GRC technologies.

• Experience with one or more frameworks such as COSO, NIST CSF, RMF, ISO, COBIT, HITRUST, or similar.

• Knowledge of HIPAA, SOX, HITRUST, PCI, SOC 2, or GRC programs.

• Experience collaborating with IT partners and understanding software engineering, enterprise applications, infrastructure, networking, service desk, desktop support, IAM, security operations, and enterprise technology tools.

• Possession of an information security or cybersecurity certification such as CISA, CISSP, CISM, or CRISC, or the ability to obtain certification within 18 months.

• Understanding of the HITRUST Framework and CSF certification.

• Comprehensive knowledge of GRC, information security, cybersecurity principles, phishing campaigns, security awareness, risk assessments, security frameworks, controls, regulations, data protection, TPRM, audit and compliance, privacy management, business continuity, AI governance, workflow automation, and enterprise GRC platforms.

• Familiarity with IAM, PAM, MFA, RBAC, SSO, DLP, ServiceNow, CMDB, ITSM, vulnerability management, DR/BCP, backups, tabletop exercises, encryption, networking, infrastructure, Azure, AWS, Google Cloud, Active Directory, platform integrations, and enterprise AI platforms.

• Proficient in GRC platform administration, workflow automation, platform configuration, dashboard and reporting development, technical documentation, and basic scripting or automation.

• Ability to troubleshoot platform issues, automate manual processes, prioritize workload, multitask, and meet deadlines.


🏝️ Benefits

• Equal opportunity employer.

• Inclusive environment committed to diversity.

People also viewed

RTX3 days ago

Compliance Manager – Triage Management

US flagConnecticut OnlyFull-timeCompliance$107.5k – $204.5k/year
ApplyView job
Finalsite4 days ago

Chief Compliance Officer

US flagUnited States OnlyFull-timeCompliance
ApplyView job
EXALTA Group4 days ago

Regulatory Specialist – Level 2

US flagUnited States OnlyFull-timeCompliance
ApplyView job
Auto Approve4 days ago

Compliance Analyst

US flagUnited States OnlyFull-timeCompliance
ApplyView job
Cushman & Wakefield4 days ago

Contracts and Compliance Administrator

US flagUnited States OnlyFull-timeCompliance$20 – $24/hour
ApplyView job
GE Vernova4 days ago

Lead Compliance Investigator

US flagUnited States OnlyFull-timeCompliance
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers