Senior Risk & Governance Engineer
AlphaSense · Maharashtra
- Experience6–7 yrs
- SalaryNot disclosed
- Work modeunknown
- Levelsenior
- Posted14 Sept 2026
About AlphaSense
AlphaSense is hiring in Maharashtra in technology software. This role looks for around 6+ years of experience.
Skills
- GRC
- information security
- risk management
- IT audit
- SOC 2
- ISO 27001
- NIST Cybersecurity Framework
- CIS Controls
- ISO 42001
- NIST AI Risk Management Framework
- GRC platforms
- cloud security
- CSPM
- SIEM
- Python
- API integration
- continuous control monitoring
- AI governance
- LLMs
- version control
- CI/CD
- infrastructure-as-code
The role
A GRC engineer at an AI-driven market intelligence company builds compliance automation, AI governance, and continuous control monitoring for cloud and SaaS environments. The role integrates GRC platforms and security tooling while applying policy-as-code and responsible AI practices.
Full job description
About AlphaSense
The world’s most sophisticated companies rely on AlphaSense to remove uncertainty from decision-making. With market intelligence and search built on proven AI, AlphaSense delivers insights that matter from content you can trust. Our universe of public and private content includes equity research, company filings, event transcripts, expert calls, news, trade journals, and clients’ own research content.
The acquisition of Tegus by AlphaSense in 2024 advances our shared mission to empower professionals to make smarter decisions through AI-driven market intelligence. Together, AlphaSense and Tegus will accelerate growth, innovation, and content expansion, with complementary product and content capabilities that enable users to unearth even more comprehensive insights from thousands of content sets. Our platform is trusted by over 6,000 enterprise customers, including a majority of the S&P 500. Founded in 2011, AlphaSense is headquartered in New York City with more than 2,000 employees across the globe and offices in the U.S., U.K., Finland, India, Singapore, Canada, and Ireland. Come join us!
About The Role
AlphaSense's GRC function is making a deliberate investment in automation and engineering, and we need a Senior GRC Engineer to lead that charge. You will design and build the technical automation that powers our compliance testing, evidence collection, risk monitoring, and GRC platform integrations—and you will own the governance architecture for how AI and agentic systems are built and deployed at AlphaSense. You sit at the intersection of security engineering and compliance operations. You are not just AI-curious; you are AI-native in practice: you use LLMs and agents for real substantive work—analysis, drafting, automation, code, investigation—and you apply rigorous judgment about where AI creates leverage, where it introduces risk, and where a human must remain in the loop. The goal is continuous compliance infrastructure that generates its own proof, not a compliance team that sprints to collect evidence before each audit cycle.The conventional GRC playbook was not built for a company like AlphaSense—and we are not following it. We are building a GRC engineering function that we believe represents what the entire industry will eventually need to become: automated, AI-native, and architected like a product rather than operated like a process. The frameworks are still catching up. The tooling is still maturing. We are doing the work now that others will reference later. If you want to build something that sets the standard—not follow one—this is the role.
Key Responsibilities
Compliance Automation Engineering
Design, build, and maintain automated compliance testing pipelines that continuously validate control adherence across cloud infrastructure, SaaS platforms, and internal systems. Replace point-in-time manual evidence collection with always-on automated checks. Pull evidence directly from APIs—cloud audit logs, identity systems, configuration posture, secrets management—without relying on screenshots or control owner self-attestation.
GRC Platform Engineering & Integration
Own the technical configuration and integration of the GRC platform (Drata or equivalent). Build custom API integrations, automated evidence connectors, and workflow automation that reduce manual control owner burden and keep evidence artifacts current. Know where the platform solves the problem and where custom code is the better answer.
AI-Native GRC Workflows
Develop and deploy AI-assisted workflows for evidence summarization, control narrative drafting, risk analysis, vendor questionnaire triage, and policy gap detection. Build with LLMs and agentic frameworks as a professional standard—not an experiment. Apply domain-specific judgment: know where AI helps, where it hurts, and where sensitive data, attacker-controlled inputs, or privileged access require a human in the loop.
AI & Agentic Systems Governance
Own the governance framework for AlphaSense's AI and agentic systems. Define the policies, control sets, and compliance posture that govern how agents are built and deployed—and build ahead of the compliance frameworks that are still catching up. Anticipate new policy requirements, adapt existing controls, and ensure the governance architecture is ready before auditors ask about it.
Policy as Code & Control Architecture
Build the policy program as code: policies in version control, peer-reviewed, with requirements expressed as enforceable rules and automated checks rather than static documents. Design a common controls framework that satisfies SOC 2, ISO 27001, ISO 42001, and future frameworks from a single control reference—no rework across frameworks.
Continuous Control Monitoring & Observability
Instrument controls with observability tooling so the GRC team receives real-time signals on control health rather than discovering failures at audit time. Build the data pipelines and dashboards that give engineering and product teams live visibility into their risk and compliance posture. Define alerting thresholds and remediation runbooks that make distributed control ownership practical.
Security Tooling Integration & Audit Readiness
Build and maintain integrations between GRC tooling and the broader security stack—SIEM, EDR, CSPM, identity platforms, and vulnerability management. Collaborate with the compliance team and auditors to understand evidence requirements, then engineer automated pipelines that pre-populate and maintain audit evidence. Maintain clear technical documentation and runbooks for all GRC automation so non-engineering GRC team members can operate and extend it.
What Success Looks Like
Security and compliance controls are clearly documented, tested, and consistently implemented—with evidence generated by integrations, not collected by handRisks and compliance gaps are identified early, tracked with owners, and remediated in partnership with technical teams before auditors find themGRC processes scale alongside platform growth and new customer or regulatory requirements without proportional headcount growthStakeholders across Engineering, Legal, and Product view the GRC function as a trusted, enabling partner—not a compliance checkpointAI tools are used deliberately and responsibly: output is validated, sensitive data is protected, and automation creates leverage without introducing new riskCompliance evidence is generated by automated pipelines, not collected by hand—audit readiness is a continuous state, not a quarterly sprintThe policy program lives in version control, is peer-reviewed, and control requirements are expressed as enforceable checks rather than static PDFsEngineering and product teams have live visibility into their compliance and risk posture without needing to ask the GRC team
Who You Are
Basic Requirements
6+ years of experience in GRC, information security, risk management, or IT audit, preferably in a SaaS or cloud-native environmentStrong understanding of security and compliance frameworks including SOC 2, ISO 27001, NIST CSF 2.0, and CIS Controls; working knowledge of ISO 42001 and NIST AI RMFAI-native mindset: you use AI tools—LLMs, agents, automation—for real, substantive work including analysis, drafting, evidence gathering, and workflow automation. You apply judgment about where AI creates leverage and where a human must stay in the loopProficiency with GRC platforms for evidence management and control testing (Drata, Vanta, AuditBoard, ServiceNow GRC, or equivalent)Familiarity with cloud environments (AWS, Azure, or GCP) and the security and compliance posture tooling that runs on them (CSPM, SIEM, identity platforms)Experience supporting external audits across security or privacy domains, including evidence collection, control walkthroughs, and auditor interactionHands-on experience implementing automated control collection and continuous control monitoring—designing pipelines and integrations that pull evidence directly from systems rather than relying on manual artifact submission or self-attestationWorking knowledge of risk registers, control libraries, and policy governance lifecyclesStrong written communication, analytical thinking, and attention to detail; able to produce clear audit responses, risk narratives, and control documentation under deadline6+ years of experience in security engineering, DevSecOps, GRC tooling, or compliance automation—with ownership of both the policy/control side and the technical implementationCoding ability that ships: Python or equivalent—you can call APIs, build integrations, schedule jobs, and deploy a working pipeline without help. Show us something you builtHands-on experience building integrations with GRC platforms via APIs or native connectors, and direct evidence collection from cloud environments (AWS Config, GCP SCC, Azure Policy, or equivalent)Demonstrated professional use of AI and LLM tools to automate documentation, analysis, or workflow tasks—with clear judgment about where AI creates leverage and where guardrails are requiredVersion control and CI/CD practices (Git, GitHub Actions, or equivalent); comfort with infrastructure-as-code concepts.
Nice to Have
Relevant certifications: CISA, CRISC, CISM, CISSP, CCSK, or ISO 27001 Lead Auditor/ImplementerExperience with AI governance frameworks including ISO 42001, NIST AI RMF, EU AI Act, or OECD AI PrinciplesExposure to SOX ITGC cycles—managing evidence, walkthroughs, and findings with external auditorsPrivacy program crossover: data mapping, DPIAs, GDPR/CCPA operational complianceScripting or automation experience (Python, JavaScript, or low-code tools) applied to GRC or compliance workflowsExperience with SOAR platforms or agentic AI orchestration frameworks (LangChain, n8n, Tines, AutoGen, or similar) applied to security or GRC workflowsFamiliarity with policy-as-code and infrastructure-as-code approaches (Terraform, OPA/Rego) in a compliance contextExperience shipping LLM or agent-powered tooling that automates security or compliance activities and was adopted by a broader teamBackground in detection engineering, security operations, or offensive security—you understand how the systems being governed actually failExperience building governance frameworks specifically for AI or agentic systems: model risk controls, ISO 42001 implementation, LLM deployment guardrails
AlphaSense is an equal-opportunity employer. We are committed to a work environment that supports, inspires, and respects all individuals. All employees share in the responsibility for fulfilling AlphaSense’s commitment to equal employment opportunity. AlphaSense does not discriminate against any employee or applicant on the basis of race, color, sex (including pregnancy), national origin, age, religion, marital status, sexual orientation, gender identity, gender expression, military or veteran status, disability, or any other non-merit factor. This policy applies to every aspect of employment at AlphaSense, including recruitment, hiring, training, advancement, and termination.
In addition, it is the policy of AlphaSense to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations, and ordinances where a particular employee works.
Recruiting Scams and Fraud
We At AlphaSense Have Been Made Aware Of Fraudulent Job Postings And Individuals Impersonating AlphaSense Recruiters. These Scams May Involve Fake Job Offers, Requests For Sensitive Personal Information, Or Demands For Payment. Please Note
AlphaSense never asks candidates to pay for job applications, equipment, or training.All official communications will come from an @alpha-sense.com email address.If you’re unsure about a job posting or recruiter, verify it on our Careers page.
If you believe you’ve been targeted by a scam or have any doubts regarding the authenticity of any job listing purportedly from or on behalf of AlphaSense please contact us. Your security and trust matter to us.