Senior Risk & Governance Engineer
AlphaSense
Job description
About the role
AlphaSense's GRC function is making a deliberate investment in automation and engineering, and we need a Senior GRC Engineer to lead that charge. You will design and build the technical automation that powers our compliance testing, evidence collection, risk monitoring, and GRC platform integrations—and you will own the governance architecture for how AI and agentic systems are built and deployed at AlphaSense.
Key responsibilities
- Design, build, and maintain automated compliance testing pipelines that continuously validate control adherence across cloud infrastructure, SaaS platforms, and internal systems.
- Own the technical configuration and integration of the GRC platform (e.g., Drata) and build custom API integrations, automated evidence connectors, and workflow automation.
- Develop AI‑assisted workflows for evidence summarization, control narrative drafting, risk analysis, vendor questionnaire triage, and policy gap detection using LLMs and agentic frameworks.
- Define and maintain the governance framework for AlphaSense's AI and agentic systems, anticipating policy requirements and ensuring readiness before audits.
- Implement policy‑as‑code practices: version‑controlled policies, peer‑reviewed rules, and automated checks that satisfy SOC 2, ISO 27001, ISO 42001, and related standards.
- Instrument controls with observability tooling, building data pipelines and dashboards that give engineering teams real‑time visibility into risk and compliance posture.
- Integrate GRC tooling with the broader security stack (SIEM, EDR, CSPM, identity platforms, vulnerability management) and maintain clear technical documentation and runbooks.
Required profile
- 6+ years of experience in GRC, information security, risk management, or IT audit, preferably in a SaaS or cloud‑native environment.
- Strong understanding of security and compliance frameworks such as SOC 2, ISO 27001, NIST CSF, CIS Controls, ISO 42001, and NIST AI RMF.
- AI‑native mindset: regular use of LLMs, agents, and automation for substantive work while applying judgment on human‑in‑the‑loop requirements.
- Proficiency with GRC platforms for evidence management and control testing (e.g., Drata, Vanta, AuditBoard, ServiceNow GRC).
- Familiarity with cloud environments (AWS, Azure, GCP) and associated security tooling (CSPM, SIEM, identity platforms).
- Experience supporting external audits, including evidence collection, control walkthroughs, and auditor interaction.
Required skills
- Drata or equivalent GRC platform
- AWS, Azure, GCP
- CSPM tools
- SIEM solutions
- Identity and access management platforms
- Large language models (LLMs) and agentic frameworks
- Version control systems (e.g., Git) for policy‑as‑code
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in India.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 15 hours ago
Expires 1 month from now
6 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
AlphaSense