27 Sep
|
NCR Voyix
|
Chennai
Senior GRC Security Engineer (Compliance Automation & AI)
Location: Chennai, India
Position Summary The Senior GRC Security Engineer is a member of NCR's Global Information Security organization and is responsible for advancing the company's Governance, Risk, and Compliance (GRC) capabilities through automation, cloud security governance, and AI-enabled solutions.
This role combines cybersecurity, compliance, and engineering expertise to modernize compliance operations and drive continuous controls monitoring. The successful candidate will work closely with security, engineering, cloud, infrastructure teams to automate compliance processes, improve control effectiveness, support regulatory and industry frameworks, and maintain audit readiness.
The ideal candidate possesses a strong technical background, hands-on cloud security experience, an understanding of cybersecurity frameworks, and the ability to leverage automation and AI technologies to improve compliance and risk management outcomes.
Key Responsibilities
GRC Engineering & Compliance Automation
- Design, implement, and maintain automated compliance workflows, control validation processes, and evidence collection capabilities.
- Develop solutions that reduce manual compliance activities through automation, orchestration, APIs, and AI-assisted technologies.
- Partner with engineering and cloud teams to integrate compliance requirements into operational processes and technology solutions.
- Implement and maintain continuous controls monitoring capabilities across enterprise and cloud environments.
- Drive innovation and efficiency within compliance and audit processes through automation and emerging technologies.
Compliance
- Interpret compliance requirements of NIST 800-53; ISO 27001, PCI DSS etc. and translate them into practical technical and operational controls.
- Conduct compliance assessments, control reviews, and gap analyses.
- Support internal and external audits, customer assessments, and regulatory examinations.
Cloud Security Governance
- Assess and monitor security controls across GCP, Azure,
and hybrid cloud environments.
- Validate implementation of cloud security controls related to identity management, logging, encryption, vulnerability management, network security, and access governance.
- Ensure cloud environments maintain alignment with organizational security standards and compliance obligations.
- Provide guidance on cloud security architecture and compliance requirements.
Required Qualifications
- Bachelors degree in Computer Science, Cybersecurity, Software Engineering, Information Technology, Information Systems, or a related technical field.
- Minimum 5 years of experience in cybersecurity, security compliance, risk management, GRC, IT audit, security engineering, or related disciplines.
- Experience supporting security and compliance programs involving industry and regulatory frameworks.
- Solid understanding of security governance, risk management, and control frameworks.
- Experience working within cloud environments, including GCP and/or Microsoft Azure.
- Practical understanding of
- Security controls and architectures
- Cloud security principles
- Continuous controls monitoring
- Strong verbal and written communication skills with the ability to communicate effectively with technical and business stakeholders.
- Demonstrated problem-solving skills and the ability to manage multiple priorities in a fast-paced environment.
Preferred Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or related discipline.
- Experience implementing compliance automation, workflow orchestration, or control validation solutions.
- Experience leveraging AI and Generative AI technologies to improve governance, risk, compliance, audit,
or security operations.
- Experience working with global compliance and regulatory requirements.
Preferred Technical Skills
- Working knowledge of Python, PowerShell, REST APIs, and automation frameworks.
- Experience integrating security, cloud, ticketing, vulnerability management, and GRC platforms.
- Familiarity with Infrastructure-as-Code (IaC), Policy-as-Code, Compliance-as-Code, and Continuous Controls Monitoring (CCM) concepts.
- Understanding of cloud-native security capabilities and governance services.
- Experience with ServiceNow GRC
Security and Compliance Framework Experience Experience with one or more of the following frameworks and standards:
- PCI DSS
- ISO 27001 / ISO 27002
- NIST Cybersecurity Framework (CSF)
- SOC 2
- SOX
- CIS Critical Security Controls
Ability to align cybersecurity and cloud security controls with industry frameworks and regulatory requirements while ensuring controls are measurable, sustainable, and continuously monitored.
Preferred Certifications
Candidates should possess one or more of the following certifications:
- CISA (Certified Information Systems Auditor)
- AI-102: Azure AI Engineer Associate
Key Success Measures
- Successful implementation and adoption of compliance automation initiatives.
- Reduction in manual compliance effort through automation and AI-enabled solutions.
- Continuous monitoring and validation of security controls.
- Timely remediation of audit findings and identified risks.
- Successful completion of internal, external, customer, and regulatory audits.
- Improved compliance visibility, efficiency, and governance across the organization.
Why Join NCR This is an opportunity to help transform compliance from a traditional audit-focused function into an engineering-driven, AI-enabled capability. You will play a key role in shaping the future of governance, risk, and compliance through automation, cloud security governance, and innovative security solutions while supporting a global technology organization.
📌 Information Security Engineer (Chennai)
🏢 NCR Voyix
📍 Chennai