29 Sep
|
Razorpay
|
Mumbai
GRC engineer is a combination of two prime areas. One is regulatory and compliance depth frameworks, control design and testing, audit judgement, deviations, the Indian financial-sector stack. The other is AI-native practice assessing AI and LLM systems for compliance risk, evaluating AI tools and vendors before they are onboarded, using AI for the mechanical half of the work with validation as a reflex, and directing AI tooling to build the monitoring and evidence automation the function needs.
Razorpay operates under one of the densest regulatory stacks in Indian technology the DPDP Act 2023, RBI Payment Aggregator and Payment Gateway directions, the PPI Master Directions, RBI Digital Payment Security Controls and Cyber Security Framework expectations, PCI DSS v4.x, ISO 27001 and 27701, and SOC 2 simultaneously, not sequentially.
Doing this by hand does not scale to our velocity. AI handles the highvolume, repetitive work: evidence collection and summarisation, control crosswalking, drafting test procedures, parsing audit logs, first-pass alert triage, questionnaire response.
It is treated like a fast junior analyst whose output is always reviewed.
Key Responsibilities
Own the
end-to-end control lifecycle : design, implementation, testing, evidence, and audit readiness
Drive
risk assessments, audit findings (deviations), and remediation closure with explicit ownership
Review
cloud security (AWS/GCP), IAM, application security, and data protection controls in production systems
Evaluate and govern
AI/LLM systems, tools, and vendors
for data security, privacy, and compliance risks
Build
automation-first GRC systems : continuous monitoring, evidence pipelines, and control validation frameworks
Support and lead
regulatory audits (RBI, ISO 27001, SOC 2, PCI DSS)
with production-backed evidence
Partner with engineering to
embed controls into architecture and SDLC (policy-as-code mindset)
Own
third-party/vendor risk assessments
with a strong technical lens
What We’re Looking For
4+ years of experience
in GRC, IT audit, security, or compliance engineering
Strong hands-on expertise in
security and compliance frameworks
(ISO 27001, SOC 2, PCI DSS, ITGC, DPDP)
Solid understanding of
cloud security, IAM, secure SDLC, and data protection controls
Proven experience in
risk management, audit handling, and control testing
Exposure to
AI/LLM risk, data governance, and vendor security assessments
Ability to
translate deep technical findings into business risk and actionable insights
Preferred
Experience in
fintech or regulated environments (RBI, payments, banking)
Hands-on with
GRC tools (Vanta, Drata, Secureframe) or compliance automation systems
Familiarity with
automation, scripting, APIs, or policy-as-code approaches
Experience building
monitoring, evidence collection, or compliance pipelines
Why This Role
Work on
AI + Compliance + Engineering convergence
Build
scalable, automation-first GRC systems
instead of manual audit workflows
High ownership role influencing
security posture and regulatory strategy
Opportunity to set the
technical bar for GRC engineering
📌 Senior GRC Engineer (Mumbai)
🏢 Razorpay
📍 Mumbai