Senior GRC Engineer

Razorpay · Bengaluru

  • Experience4–5 yrs
  • SalaryNot disclosed
  • Work modeonsite
  • Levelmid
  • Posted11 Sept 2026

About Razorpay

Razorpay is hiring in Bengaluru in financial services. This role looks for around 4+ years of experience.

Skills

  • ISO 27001
  • SOC 2
  • PCI DSS
  • ITGC
  • DPDP
  • cloud security
  • IAM
  • secure SDLC
  • data protection
  • risk management
  • audit handling
  • control testing
  • AI/LLM risk
  • data governance
  • vendor security assessments

The role

A GRC engineer at a financial technology company designs and tests controls, evaluates AI/LLM systems and vendors, and builds compliance automation for regulated payment environments. The role applies security and compliance frameworks, cloud security, and risk management to audits, monitoring, evidence pipelines, and secure engineering practices.

Full job description

GRC engineer is a combination of two prime areas. One is regulatory and compliance depth frameworks, control design and testing, audit judgement, deviations, the Indian financial-sector stack. The other is AI-native practice assessing AI and LLM systems for compliance risk, evaluating AI tools and vendors before they are onboarded, using AI for the mechanical half of the work with validation as a reflex, and directing AI tooling to build the monitoring and evidence automation the function needs.Razorpay operates under one of the densest regulatory stacks in Indian technology the DPDP Act 2023, RBI Payment Aggregator and Payment Gateway directions, the PPI Master Directions, RBI Digital Payment Security Controls and Cyber Security Framework expectations, PCI DSS v4.x, ISO 27001 and 27701, and SOC 2 simultaneously, not sequentially. Doing this by hand does not scale to our velocity. AI handles the highvolume, repetitive work: evidence collection and summarisation, control crosswalking, drafting test procedures, parsing audit logs, first-pass alert triage, questionnaire response. It is treated like a fast junior analyst whose output is always reviewed.Key ResponsibilitiesOwn the end-to-end control lifecycle: design, implementation, testing, evidence, and audit readinessDrive risk assessments, audit findings (deviations), and remediation closure with clear ownershipReview cloud security (AWS/GCP), IAM, application security, and data protection controls in production systemsEvaluate and govern AI/LLM systems, tools, and vendors for data security, privacy, and compliance risksBuild automation-first GRC systems: continuous monitoring, evidence pipelines, and control validation frameworksSupport and lead regulatory audits (RBI, ISO 27001, SOC 2, PCI DSS) with production-backed evidencePartner with engineering to embed controls into architecture and SDLC (policy-as-code mindset)Own third-party/vendor risk assessments with a strong technical lensWhat We’re Looking For4+ years of experience in GRC, IT audit, security, or compliance engineeringStrong hands-on expertise in security and compliance frameworks (ISO 27001, SOC 2, PCI DSS, ITGC, DPDP)Solid understanding of cloud security, IAM, secure SDLC, and data protection controlsProven experience in risk management, audit handling, and control testingExposure to AI/LLM risk, data governance, and vendor security assessmentsAbility to translate deep technical findings into business risk and actionable insightsPreferred Experience in fintech or regulated environments (RBI, payments, banking)Hands-on with GRC tools (Vanta, Drata, Secureframe) or compliance automation systemsFamiliarity with automation, scripting, APIs, or policy-as-code approachesExperience building monitoring, evidence collection, or compliance pipelinesWhy This RoleWork on AI + Compliance + Engineering convergenceBuild scalable, automation-first GRC systems instead of manual audit workflowsHigh ownership role influencing security posture and regulatory strategyOpportunity to set the technical bar for GRC engineering