Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
One Identity

Senior Security Engineer – GRC Engineering

One Identity

. Own continuous control monitoring end to end across identity providers, cloud control planes, code repositories, endpoint management, and ticketing .

Posted 10/6/2026full-timeRemote • IndiaSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in compliance program leadership and security engineering, with a strong focus on framework design, control mapping, and evidence automation. Proficient in Python and API integration, with hands-on experience in compliance automation platforms and cloud environments.

Highest-signal resume keywords
Compliance Program LeadershipFramework Design and Control MappingPython and API IntegrationISO 27001 and SOC 2 FluencyCompliance Automation Platform Experience

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Compliance EngineeringControl Validation as CodeAudit-Ready Evidence ProductionPolicy as Code FrameworksAutomated Asset PrioritizationControl TelemetryContinuous MonitoringFramework AssessmentAI IntegrationCloud Enforcement
Soft Skills
Communication with Auditors and EngineersStrategic ThinkingRelationship Management
Tools & Technologies
AzureAWSCompliance Automation Platforms
Certifications & Qualifications
FedRAMP CertificationISO 27001 Certification
Industry Keywords
GRC EngineeringNIS2DORAPCI DSSIRAP

Tech Stack

Tools & technologies
AWSAzureCloudPython

About the role

Key responsibilities & impact
  • Own continuous control monitoring end to end across identity providers, cloud control planes, code repositories, endpoint management, and ticketing
  • Build alerting, escalation, and remediation confirmation for degraded controls
  • Build a centralized common controls framework based on ISO 27001 and SOC 2
  • Map additional frameworks to the common controls framework
  • Capture, timestamp, index, and assemble audit-ready evidence on demand
  • Ensure the evidence system operates within and logs its own controls
  • Write control validation as code and produce auditor-accepted, engineer-actionable outputs
  • Create pull-request-based corrections against pipelines, policies, or configurations
  • Partner with infrastructure engineering on policy as code and evidence emission
  • Define appropriate uses of agentic workflows for control mapping, evidence classification, and validation
  • Own the compliance engineering program's direction, framework priorities, automation priorities, and engineering allocation
  • Advance metrics covering control health, framework coverage, remediation velocity, and trends
  • Integrate cyber risk management, risk registers, and exception handling with control telemetry
  • Own automated asset prioritization to inform risk decisions, control coverage, and remediation order
  • Lead the technical side of audits and explain control implementation and evidence production to assessors

Requirements

What you’ll need
  • Six or more years across compliance program leadership and security or compliance engineering, including experience on both the framework side and the build side; equivalent depth counts
  • Experience leading a major framework through assessment from readiness through certification or authorization, such as FedRAMP or comparable, or owning GRC engineering end to end with control telemetry, continuous monitoring, and evidence automation
  • Strategic framework design and control mapping across frameworks
  • Recent hands-on Python and API integration experience
  • Hands-on building with AI in the loop within the last six months, including verification of tooling output
  • Framework fluency across ISO 27001 and SOC 2
  • Familiarity with FedRAMP 20x, NIS2, DORA, and PCI DSS
  • Knowledge of policy-as-code frameworks and cloud enforcement
  • Sufficient Azure and AWS experience to identify where evidence resides
  • Experience with a compliance automation platform
  • Ability to run an audit calendar and assessor relationship
  • Ability to write for both auditors and engineers
  • Helpful: assessor-side experience; IRAP or another non-US regime; evidence work across hosted services and customer-deployed software; prior software or platform engineering experience

Benefits

Comp & perks
  • Health and wellness programs
  • Career development opportunities
  • Programs supporting employees in pursuing fulfilling careers
  • Opportunities to learn and grow
  • Equal employment opportunity and harassment-free work environment