This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a GRC Engineer I (Special Programs) based in India.
This role offers the opportunity to help organizations strengthen their cybersecurity and compliance programs across a range of recognized frameworks and regulatory standards. You will manage client engagements from implementation through ongoing compliance activities, working directly with stakeholders to deliver measurable program outcomes. The position combines hands-on GRC execution, client relationship management, technical risk remediation, and project coordination. You will support a portfolio of accounts while collaborating with analysts and cross-functional technical teams to keep compliance initiatives moving efficiently. The role is particularly suited to someone who enjoys a fast-paced environment where priorities can evolve quickly and client experience is a central focus. You will also contribute to scalable delivery practices, including policies, playbooks, templates, and operational processes.
Accountabilities:
- Execute end-to-end client security and compliance initiatives aligned with frameworks such as SOC 2, ISO 27001, and NIST CSF.
- Manage a portfolio of active client accounts and serve as a primary point of contact throughout engagements.
- Guide clients through compliance initiatives, maintaining strong communication, trust, and accountability from kickoff through delivery.
- Author, maintain, and update cybersecurity policies, standard operating procedures, control documentation, and evidence repositories.
- Coordinate evidence collection, compliance milestones, project deliverables, and task execution across multiple concurrent engagements.
- Conduct control testing, readiness reviews, and structured compliance assessments to identify gaps and maintain alignment with applicable requirements.
- Identify, assess, and track cybersecurity risks and control deficiencies in collaboration with technical and business stakeholders.
- Partner with IT, security, operations, and other cross-functional teams to develop and execute remediation plans.
- Communicate directly with client stakeholders through email, chat, and video meetings to gather evidence, clarify requirements, resolve issues, and provide progress updates.
- Handle client escalations with professionalism, urgency, and a solutions-oriented approach.
- Coordinate effectively with analysts and other delivery team members to ensure engagement milestones and quality standards are met.
- Contribute to improving delivery processes, templates, playbooks, and standard operating procedures.
- Support the scaling of GRC service delivery by identifying opportunities for greater consistency, efficiency, and automation.
- Adapt quickly to changing priorities, customer requirements, and specialized compliance engagements.
- Participate in client and team meetings while maintaining a high standard of confidentiality and professionalism.
- Hands-on experience delivering cybersecurity compliance or GRC initiatives within technology-focused environments.
- Practical experience working with at least one major framework such as SOC 2, ISO 27001, or NIST CSF.
- Experience managing multiple compliance or cybersecurity projects simultaneously while maintaining organization, quality, and delivery momentum.
- Demonstrated ability to communicate directly with U.S.-based clients and other international stakeholders in a professional, customer-focused manner.
- Strong understanding of cybersecurity policies, controls, evidence management, and the policy lifecycle.
- Practical experience authoring, implementing, maintaining, or enforcing enterprise security policies and control requirements.
- Familiarity with compliance automation or GRC platforms such as Vanta or comparable solutions.
- Additional knowledge of regulatory and compliance frameworks such as GDPR, HIPAA, or PCI DSS is preferred.
- Relevant professional certifications such as ISO 27001 Lead Implementer, CISA, Security+, or comparable credentials are preferred.
- Strong written and verbal English communication skills, with the ability to communicate effectively with both technical and executive audiences.
- Excellent organizational and project management skills, with strong attention to detail and the ability to manage competing priorities.
- Demonstrated analytical, problem-solving, and risk-management capabilities.
- Strong stakeholder management and relationship-building skills, with a client-first approach to service delivery.
- Ability to work effectively in a high-velocity startup environment where priorities and client needs can change quickly.
- Reliable high-speed internet connection and a professional home-office environment suitable for confidential conversations and uninterrupted remote collaboration.
- Willingness and ability to work a standard schedule aligned with 8:00 AM-5:00 PM U.S. Eastern Time.
- Ability to travel locally on occasion for onsite meetings, team gatherings, or business activities when required.
- Willingness to participate in live video interviews with camera enabled and complete applicable identity verification and background screening requirements.
- Competitive base salary with regular performance reviews and merit-based appraisal opportunities.
- Bonus opportunities linked to performance and role outcomes.
- Remote-first flexibility with the ability to work from home while collaborating with a global team.
- Clear career development opportunities supported by mentorship and training.
- Reimbursement for approved role-related training and professional certification courses.
- Exposure to multiple cybersecurity and compliance frameworks, industries, and client environments.
- Opportunity to develop hands-on expertise across GRC, cybersecurity risk, compliance automation, and client delivery.
- Early-stage environment offering opportunities for increased responsibility and career progression.
- Direct interaction with international clients and senior technical and business stakeholders.
- Opportunity to contribute to the development of scalable GRC delivery processes, playbooks, and operational standards.

