Principal GRC Engineer
5 days ago
Who are we?
Smarsh empowers its customers to manage risk and unleash intelligence in their digital communications. Our growing community of over 6500 organizations in regulated industries counts on Smarsh every day to help them spot compliance, legal or reputational risks in 80+ communication channels before those risks become regulatory fines or headlines. Relentless innovation has fueled our journey to consistent leadership recognition from analysts like Gartner and Forrester, and our sustained, aggressive growth has landed Smarsh in the annual Inc. 5000 list of fastest-growing American companies since 2008.
Smarsh is a global leader in digital communications capture, archiving, and oversight. Smarsh is committed to embedding security as a business enabler through governance process excellence and scalable control frameworks. As a GRC Lead, you will play a critical role in advancing our governance, risk, and compliance programs. You'll be responsible for defining, implementing, and optimizing security controls and risk processes that support operational alignment across the organization. This role requires a deep understanding of how governance can scale through automation, control validation workflows, and "Policy as Code" principles. You'll collaborate closely with engineering, security, legal, and business teams to ensure our GRC practices mature in step with our growth.
Core Responsibilities
- ISMS Governance & Controls Assurance
- Lead the ongoing maintenance and enhancement of Smarsh's ISO 27001-aligned ISMS, ensuring policies, controls, and governance processes are clear, actionable, and aligned with business operations.
- Author and maintain security control narratives, working closely with technical teams to ensure controls are designed with enforceability and operational alignment in mind.
- Oversee the Control Assurance Program, ensuring effective evidence collection, control testing, and continuous monitoring practices.
- Coordinate internal and external audit readiness (SOC 2, ISO 27001, FedRAMP, customer audits) through structured governance workflows.
- Risk Management & Governance
- Manage the risk assessment lifecycle, ensuring comprehensive engagement across business, technical, and third-party risk domains.
- Facilitate risk acceptance workflows, maintaining governance rigor through well-defined documentation and approval processes.
- Ensure effective governance of risk treatment plans, enabling clear tracking and status reporting.
- Regulatory, Contractual & Client Assurance
- Translate emerging regulations (e.g., DORA, SEC Cyber Rules, UK AI Act) into internal governance requirements and operational processes.
- Manage customer security assessments and DDQs, utilizing standardized assurance artefacts to deliver efficient, high-quality responses.
- Ensure external assurance artefacts are maintained and accessible through the Smarsh Trust Center.
- Third-Party & Supply Chain Risk
- Lead third-party security reviews and ensure governance controls are extended across the vendor lifecycle.
- Partner with Procurement and Legal to align contractual security requirements and risk acceptance criteria.
- Policy Lifecycle & Governance Metrics
- Own the policy lifecycle process, ensuring policies are regularly reviewed, updated, and tracked for compliance.
- Develop governance reporting and dashboards that provide clear visibility into control effectiveness, risk posture, and audit readiness.
- Support governance forums and leadership committees with data-driven insights and structured governance reports.
- GRC Operations & Enablement
- Lead the continual refinement of GRC workflows, ensuring operational efficiency in documentation, evidence management, and status tracking.
- Collaborate with Engineering and Security teams to ensure controls are practically enforceable within operational workflows.
- Bring forward ideas and experience around scaling governance processes through automation and control validation techniques, supporting Smarsh's long-term governance maturity.
Essential Experience
- 7–10 years of experience in GRC leadership, security governance, or compliance process roles within SaaS or regulated industries.
- Proven experience writing security controls, managing control assurance programs, and leading external audit preparation.
- Deep understanding of how security controls are designed, enforced, and validated within technical and business environments.
- Experience translating regulatory frameworks (ISO 27001, SOC 2, GDPR, FedRAMP, DORA, SEC Cyber Rules) into scalable governance processes and workflows.
- Ability to collaborate cross-functionally across Security, Engineering, Legal, and Product teams to embed governance effectively.
- Exceptional documentation and reporting skills, with the ability to produce executive-level governance artefacts and metrics dashboards.
- Strong background with GRC tooling, control validation workflows, and scalable governance process design.
Don't feel that you meet all of the requirements? We encourage you to apply anyway because studies have shown that some strong candidates may self-select out of the interview process prematurely. We have a diverse, inclusive, equitable, and high-performing environment at Smarsh and want to continuously improve our ability to deliver for customers.
About Our Culture
Smarsh hires lifelong learners with a passion for innovating with purpose, humility and humor. Collaboration is at the heart of everything we do. We work closely with the most popular communications platforms and the world's leading cloud infrastructure platforms. We use the latest in AI/ML technology to help our customers break new ground at scale. We are a global organization that values diversity, and we believe that providing opportunities for everyone to be their authentic self is key to our success. Smarsh leadership, culture, and commitment to developing our people have all garnered  Best Places to Work Awards. Come join us and find out what the best work of your career looks like.
- 
					  GRC Engineer2 weeks ago 
 Bengaluru, Karnataka, India People Resources Full time ₹ 9,00,000 - ₹ 12,00,000 per yearWe are looking for a GRC (Governance, Risk & Compliance) Engineer to join our Security & Compliance team3–6 years of experience in GRC, IT audit, or compliance roles. 
- 
					  Business Head2 weeks ago 
 Bengaluru, Karnataka, India GRC Infra Full time ₹ 15,00,000 - ₹ 25,00,000 per yearCompany DescriptionThe GRC Group was founded in 1999 and has built a strong reputation through its pioneering work with leading architects to create high-end homes, villas, commercial complexes, and hospitals in Bangalore. The company evolved into an independent developer with the successful residential project GR Vistas and continued to establish a... 
- 
					Security GRC Engineer2 hours ago 
 Bengaluru, Karnataka, India Docusign Full time ₹ 12,00,000 - ₹ 36,00,000 per yearCompany OverviewDocusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify people's lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped inside of documents. Until now,... 
- 
					  GRC Engineer – Compliance Automation7 days ago 
 Bengaluru, Karnataka, India Alteryx Full timeWe're looking for problem solvers, innovators, and dreamers who are searching for anything but business as usual. Like us, you're a high performer who's an expert at your craft, constantly challenging the status quo. You value inclusivity and want to join a culture that empowers you to show up as your authentic self. You know that success hinges on... 
- 
					  GRC business Analyst1 week ago 
 Bengaluru, Karnataka, India VLink Inc Full time ₹ 9,00,000 - ₹ 12,00,000 per yearJob Title: - GRC Business Analyst (Platform Support) ILocation: BengaluruWork Model: Hybrid (2-3 days in a week in office)Shift: 11:30AM to 8:30PM ISTWork experienceWe are seeking enthusiastic & technically savvy professionals to support the current team with the execution and management of engagements in our current and future Client portfolio.•Assist in... 
- 
					GRC Analyst6 days ago 
 Bengaluru, Karnataka, India Ushur Full time ₹ 5,00,000 - ₹ 8,00,000 per yearAbout UsUshur delivers the world's first Customer Experience Automation platform built specifically for regulated industries. Purpose-built for delivering ideal self-service, Ushur infuses intelligence into digital experiences for the most delightful and impactful customer engagements. Equipped with guardrails and compliance-ready infrastructure, Ushur... 
- 
					SAP GRC2 weeks ago 
 Bengaluru, Karnataka, India hirezy Full time ₹ 20,00,000 - ₹ 25,00,000 per yearDescription : About the role : Expertise in SAP GRC Access Control & IAGThe candidate will need : - Hands-on experience in integrating SAP GRC with cloud-based applications, including SAP and non-SAP systems using IAG Bridge - Working knowledge and exposure to SAP Business Technology Platform (BTP), SAP Cloud Identity Services (CIS) and Identity Access... 
- 
					  ServiceNow GRC Engineer2 weeks ago 
 Bengaluru, Karnataka, India Anlage Infotech (I) Pvt. Ltd. Full time ₹ 12,00,000 - ₹ 36,00,000 per yearRole : ServiceNow GRC/IRM Professionals Are you an expert in ServiceNow GRC or IRM modules? We're looking for talented professionals with 5 - 9 years of experience in implementing cutting-edge GRC solutions across platforms like ServiceNow.Role Requirements : - Experience : 5 - 9 years in GRC implementation - Expertise in GRC platform (ServiceNow) ... 
- 
					  GRC Implementation Consultant1 hour ago 
 Bengaluru, Karnataka, India Corporater Full time ₹ 6,00,000 - ₹ 18,00,000 per yearJoin Corporater – A Global Leader in GRC SolutionsAt Corporater, we empower organizations worldwide with cutting-edge Governance, Risk, and Compliance (GRC) solutions that enable smarter decision-making and operational resilience.Our Business Management Platform provides a configurable, no-code approach to managing governance, risk, compliance, strategy... 
- 
					  ServiceNow GRC/IRM Developer4 days ago 
 Bengaluru, Karnataka, India Kyndryl Full time ₹ 12,00,000 - ₹ 36,00,000 per yearWho We AreAt Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward – always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our communities.The RoleAre you...