- Location
- Bangalore, India
- Workplace
- Remote
- Type
- Full-time
- Department
- Engineering
- Education
- Master
- Source
- Workday
Description
Job Description:
The Sr. Security Engineer develops solutions leveraging Governance, Risk & Compliance (GRC) platforms, security technologies, and automation to support Information Security and GRC operations. The ideal candidate has experience administering enterprise GRC platforms, configuring workflows, automating business processes, integrating technologies, and developing operational reporting, dashboards and workflow automation to support Audit, Compliance, Enterprise Risk, Third-Party Risk Management (TPRM), Identity Governance, Privacy, Business Continuity, Security Awareness, and AI Governance.- Develop solutions using GRC platforms, security technologies, and automation to support Information Security and Governance, Risk & Compliance (GRC) initiatives
- Serve as system administrator for enterprise GRC platforms and supporting technologies including Third-Party Risk Management (TPRM), Risk Register, Privacy Management, Security Awareness, Identity Governance, Business Continuity, AI Governance, and related GRC solutions.
- Configure and maintain GRC workflows, forms, questionnaires, dashboards, control libraries, evidence management, and reporting capabilities.
- Perform platform administration, upgrades, testing, user provisioning, troubleshooting, release validation, and technical support.
- Provide technical and operational support for the TPRM platform, including platform configuration, user support, workflow enhancements, issue resolution, testing, and release validation.
- Configure and administer Identity Governance workflows including user access certification campaigns, periodic access reviews, remediation tracking, and governance reporting.
- Administer Phishing tool and related security awareness technologies, including phishing simulations, mandatory training campaigns, completion tracking, and awareness reporting.
- Collect operational metrics from Information Security, IT, Engineering, Privacy, Compliance, Risk, and other business teams; automate data collection where feasible; and develop CISO dashboards, executive reporting, KPI/KRI metrics, and recurring operational reports.
- Configure workflow automation across GRC platforms to streamline business processes, improve operational efficiency, and reduce manual effort.
- Support integration of GRC platforms with ServiceNow, IAM, CMDB, ITSM, HR systems, vulnerability management, security tools, and API-based integrations.
- Provide technical support for audit and compliance platforms, including platform configuration, workflow enhancements, reporting, issue resolution, testing, and release validation.
- Configure and administer Privacy Impact Assessment (PIA), Data Protection Impact Assessment (DPIA), privacy workflows, dashboards, and operational reporting.
- Configure and support Business Continuity and Disaster Recovery (BC/DR) technologies, including Business Impact Analysis (BIA) workflows, testing schedules, resilience dashboards, remediation tracking, and evidence management.
- Configure and support AI Governance technologies, including AI risk assessment workflows, dashboards, automation, and platform enhancements supporting responsible AI adoption.
- Collaborate with Information Security, Enterprise Applications, Engineering, Infrastructure, Privacy, Internal Audit, Enterprise Risk, Compliance, and business stakeholders to support GRC platform operations and technology enablement.
- Support customer security assessments, HITRUST, SOC 2, ISO 27001, HIPAA, PCI DSS, and other compliance initiatives through platform administration, reporting, workflow automation, and evidence management.
- Create and maintain technical documentation, standard operating procedures (SOPs), platform configuration guides, and knowledge articles.
- Identify opportunities to optimize GRC technologies, enhance automation, improve platform utilization, and recommend operational improvements.
- Stay current with GRC technologies, cybersecurity regulations, industry frameworks, and emerging best practices, including AI governance, and apply them to existing GRC platforms and operational processes.
Education Required:
- Bachelor's Degree in Computer Science or related discipline or advanced degree.
- Or, any combination of education and experience which would provide the required qualifications for the position.
Experience Required:
- 4-6 years of relevant experience or advanced Degree.
- Experience administering, configuring, and supporting Governance, Risk & Compliance (GRC) platforms, security technologies, and workflow automation solutions.
- Experience working with GRC platforms, security technologies, tools, or processes such as phishing campaigns, Identity Governance, IAM, PAM, MFA, RBAC, SSO, Third-Party Risk Management (TPRM), Risk Register, Privacy Management, workflow automation, dashboards, reporting, vulnerability management, and related GRC technologies.
- Experience with one or more of the following frameworks: COSO, NIST CSF, RMF, ISO, COBIT, HITRUST, or similar governance and compliance frameworks.
- Experience working in an environment with one or more of the following: Health Insurance Portability and Accountability Act (HIPAA), Sarbanes-Oxley Act (SOX), HITRUST, Payment Card Industry (PCI), SOC 2, or Governance, Risk & Compliance (GRC) programs.
- Experience working with IT partners and adequate exposure to their areas such as software engineering, enterprise applications, infrastructure, networking, service desk, desktop support, Identity & Access Management (IAM), security operations, and other enterprise technology teams. This includes experience or sufficient exposure and familiarity with the tools they use.
License/Certification Required:
- Information security or cybersecurity related certifications such as CISA, CISSP, CISM, CRISC or ability to acquire certification within 18 months.
- HITRUST Framework and CSF certification knowledge. Governance, Risk and Compliance tools.
Knowledge, Skills & Abilities:
- Knowledge of: Governance, Risk & Compliance (GRC), information security and cybersecurity principles, phishing campaigns, cybersecurity awareness and training, risk assessments, risk registers, security frameworks, standards, guidelines, controls, federal and state security regulations and trends, data protection, administrative, technical and physical security controls, third-party risk management (TPRM), audit and compliance operations, privacy management, business continuity, AI governance, workflow automation, and enterprise GRC platforms. IT/security processes or technologies such as IAM, PAM, MFA, RBAC, SSO, DLP, Identity Governance, Risk Register, ServiceNow, CMDB, ITSM, vulnerability management, DR & BCP, backups, tabletop exercises, encryption at rest and in transit, networking, infrastructure, hosted environments such as Azure, AWS, or Google Cloud, Active Directory, enterprise platform integrations and AI technologies such as OpenAI, Microsoft Copilot, Claude, Gemini, and other enterprise AI platforms.
- Skill in: Information security, Governance, Risk & Compliance (GRC) platform administration, workflow automation, platform configuration, dashboard and reporting development, technical documentation, basic scripting or automation, working as a member of a team, communicating effectively, and establishing and maintaining effective working relationships.
- Ability to: Determine how enterprise platforms and workflows should operate and how changes in conditions, operations, and the environment affect business outcomes; troubleshoot platform issues; automate manual processes; work in a fast-paced environment; stay organized; prioritize workload; multi-task; and meet deadlines.
The company has reviewed this job description to ensure that essential functions and basic duties have been included. It is intended to provide guidelines for job expectations and the employee's ability to perform the position described. It is not intended to be construed as an exhaustive list of all functions, responsibilities, skills and abilities. Additional functions and requirements may be assigned by supervisors as deemed appropriate. This document does not represent a contract of employment, and the company reserves the right to change this job description and/or assign tasks for the employee to perform, as the company may deem appropriate.
NextGen Healthcare is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.