Role Overview:This role seeks a hands-on GRC Engineer with strong development and cloud engineering experience, focusing on building secure, scalable systems. The ideal candidate will possess expertise in Python, API development, and modern architectures including microservices, Kubernetes, and Docker, alongside robust database skills and a deep understanding of compliance frameworks. This is a technical GRC profile, emphasizing actual engineering and system implementation.
Key Responsibilities:- Develop Python backend solutions with REST API integration.
- Build and support microservices-based applications using modern architectures.
- Utilize Docker, Kubernetes, and cloud platforms, preferably AWS.
- Implement and integrate security controls such as RBAC, OAuth2/JWT, encryption, IAM, audit logging, and secure coding practices.
- Integrate security and compliance controls into CI/CD pipelines (DevSecOps).
- Engineer and implement compliance automation, audit-ready systems, risk/control platforms, or governance workflows.
Required Skills:- Strong hands-on experience in Python backend development with REST API development.
- Experience building microservices-based applications.
- Hands-on expertise with Docker, Kubernetes, and cloud platforms (AWS preferred).
- Strong understanding of GRC/compliance frameworks such as SOC2, ISO 27001, NIST, FedRAMP.
- Strong knowledge of security implementation including RBAC, OAuth2/JWT, encryption, IAM, audit logging, and secure coding practices.
- Strong database experience with SQL/NoSQL (PostgreSQL, MongoDB, Oracle, etc.).
- Candidate should have a builder mindset with actual engineering and system implementation experience.
Qualifications:- 6-8 years of relevant experience.
Preferred Skills:- Experience with Node.js, FastAPI, or Flask.
- Exposure to real-time compliance monitoring or governance platforms.
- Experience in regulated environments such as banking, healthcare, fintech, or enterprise compliance systems.
- Knowledge of Infrastructure as Code (Terraform, CloudFormation).
- Experience with monitoring/observability tools like Prometheus, Grafana, Datadog, CloudWatch.
- Exposure to GenAI/AI-driven compliance automation.
- Experience with data governance, lineage, and audit traceability systems.
- Familiarity with Agile, DevSecOps, and secure SDLC practices.
- Strong communication skills and ability to work with cross-functional security/compliance stakeholders.