Compliance Engineer-GRC
Razorpay Β· Bengaluru, Karnataka, India
Razorpay Β· Bengaluru, Karnataka, India
**GRC Engineer** **You're a GRC engineer who reviews and builds. You bring a strong foundational understanding of core security concepts identity boundaries, data flow mapping, least privilege and you know how to apply them to assess the security and compliance of fast-moving systems.** Direct exposure to OAuth, non-human and agentic identities, and LLM data flows is a significant plus, but it's not a prerequisite. What matters more is a fierce appetite and the capability to quickly learn how these foundations translate to cutting-edge AI and agentic systems. **You approach the work with an AI-first mindset: not just reviewing these systems, but using AI coding tools to stand up review and monitoring solutions far faster than any team could do manually.** **ABOUT GRC ENGINEERING AT RAZORPAY** GRC at Razorpay is being re-founded as an engineering discipline. We are transforming a traditional compliance team into GRC Engineering applying software-engineering principles (automation, version control, continuous monitoring) to governance, risk, and compliance. This is not about turning compliance professionals into software engineers. Traditional GRC expertise frameworks, control design, and audit judgement remains the foundation and the accountable core. GRC Engineering builds on it by making execution scalable and repeatable: policy-as-code, automated evidence collection, continuous controls monitoring, and AI workflows that do the mechanical work while a named human stays accountable for every decision. This role sits within the GRC Engineering uni one of two units, alongside Privacy, reporting into the Head of GRC & Privacy. Razorpay operates under one of the densest regulatory stacks in Indian technology the DPDP Act 2023, RBI Payment Aggregator and Payment Gateway directions, PCI-DSS v4.0, ISO 27001/27701, and SOC 2 all at once. Doing this by hand does not scale to our velocity. Our approach is AI-native and pragmatic: AI handles the high-volume, repetitive work evidence collection and summarisation, control crosswalking, drafting test procedures, first-pass alert triage treated like a fast junior analyst whose output is always reviewed. The judgement work risk acceptance, audit scoping, and the regulator relationship stays firmly human. **THE ROLE** Own the technical compliance stack for your area keep controls tested, evidence continuous, and audits boring and review the security and compliance of the fast-moving surfaces Razorpay ships: OAuth integrations, non-human and agentic identities, and LLM pipelines. You bring solid framework knowledge and grow an engineering muscle on top of it. **WHAT YOU'LL OWN** **Review fast-moving security surfaces -**Review the security and compliance arrangements for what Razorpay ships quickly OAuth flows and third-party integrations, and non-human identity (service accounts, API keys, secrets, workload identity) and confirm least privilege actually holds. **Review agentic identity & autonomy -**Assess how AI agents authenticate and what they can reach (agentic identity), and evaluate agent autonomy tool access, memory, decision scope and its guardrails; ensure human-in-the-loop where it matters and that agent actions are logged, bounded, and reversible. **Protect data in LLM pipelines -**Review PII redaction and data minimisation across prompts, context, logs, and outputs for LLM-powered features, and check that personal or cardholder data does not leak to third-party model providers. **Build review & monitoring solutions with AI -**Use AI coding tools (e.g. Claude Code, Codex, or similar) to rapidly stand up the checks, connectors, dashboards, and evidence collectors a review needs you direct and review the code, you don't hand-write it all. **Automate evidence & continuous monitoring -**Turn manual evidence and control tests into automated, repeatable collection and cloud config checks (e.g. AWS Config) that detect drift for DPDP, PCI-DSS v4.0, ISO 27001, and SOC 2, and alert the right people in real time. **Own controls, map to frameworks -**Own a set of controls and modern surfaces end-to-end, and translate technical configuration into framework language so auditors and stakeholders understand the posture. **Support audits -**Assemble evidence packages for RBI, PCI-DSS, ISO, and SOC 2 examinations, and be a hands-on point of contact for the controls and surfaces you own. **SKILLS & EXPERTISE** **Critical** **Compliance foundation** -Solid working knowledge of at least one of DPDP Act 2023, PCI-DSS v4.0, ISO 27001, or SOC 2 β control objectives, not just control names β and the judgement to know what good evidence looks like. **Reviewing fast-moving surfaces** -Strong foundational understanding of core security concepts (identity boundaries, data flow mapping, least privilege). While direct exposure to OAuth, non-human identities, and LLM pipelines is a massive plus, we value a fierce appetite and capability to quickly learn how these frameworks apply to cutting-edge AI and agentic systems. **Building with AI coding tools** -Uses Claude Code, Codex, or similar to stand up review, monitoring, and evidence solutions fast β you direct and sanity-check the code rather than hand-cranking it. This is a review-and-build role powered by AI, not a scripting or software-engineering role. **Cloud & identity literacy** -Working knowledge of AWS and/or GCP IAM, logging, configuration, and how identity and access are structured β and how to pull compliance-relevant signal from APIs. **Core** **AI-native working** -Hands-on with LLMs for real work and disciplined about reviewing their output, analysis or code, before it counts. **Policy-as-code awareness** -Familiarity with, or appetite to learn, policy-as-code and IaC checks (OPA, AWS Config Rules, Terraform) increasingly generated and maintained with AI tools. **Communication** -Can translate a technical finding into plain language for engineers and auditors.