Security Specialist (GRC)
Keka HR · Hyderabad, Telangana, India
Free to search · AI fit score against your CV · tailor your résumé in one click
Keka HR · Hyderabad, Telangana, India
About The Role Keka is looking for a GRC professional to own and mature our compliance and risk management program across multiple frameworks and jurisdictions. You will work closely with the CISO, engineering, legal, and customer-facing teams to keep Keka audit-ready, close third-party risk gaps, and represent our security posture to prospects and clients directly. Key Responsibilities Frameworks & Certifications • Own day-to-day compliance operations for ISO 27001 and SOC 2 Type II, including control ownership, evidence collection, and continuous readiness (not just audit-time scrambling) • Track control gaps, drive remediation with engineering/IT ops, and maintain the compliance calendar across certification cycles ITGC • Own IT General Controls testing and evidence across access management, change management, backup/DR, logical security, and computer operations • Design and maintain ITGC control matrices mapped to ISO 27001/SOC 2 requirements, avoiding duplicate audit asks across frameworks • Coordinate with engineering/DevOps/IT ops to pull periodic evidence (access reviews, change logs, backup test results) on a recurring cadence rather than only at audit time • Support ITGC walkthroughs for financial/SOX-adjacent audits if/when applicable to Keka's customers or investors Regulatory Compliance • Manage GDPR and DPDPA compliance programs – DPIAs, RoPA, breach notification workflows, data subject request handling • Maintain CCPA compliance posture for US-facing operations • Build and maintain working knowledge of regional regulations relevant to Keka's expansion markets – Middle East (e.g., UAE PDPL, Saudi PDPL) and Philippines (RA 10173 / Data Privacy Act) – and translate these into internal controls and contract-ready positions Audits • Serve as primary point of contact for internal and external auditors across ISO 27001, SOC 2, ITGC, and customer-driven audits • Prepare audit evidence packages, walk auditors through controls, and manage audit findings through closure Third-Party Risk • Run vendor/third-party risk assessments (security questionnaires, DPA reviews, sub-processor risk scoring) before onboarding and periodically thereafter • Maintain a vendor risk register and escalate high-risk findings Client-Facing • Own responses to client security questionnaires (SIG, CAIQ, or custom formats) • Represent Keka's security and compliance posture on client due-diligence calls, confidently answering technical and regulatory questions in real time • Support sales/pre-sales and legal teams during DPA/MSA negotiations on security and privacy clauses Program & Reporting • Maintain and evolve GRC tooling (trackers, dashboards, posture scoring) for leadership visibility • Contribute to board-level security posture reporting alongside the CISO Required Skills & Experience • 5–8+ years in GRC/compliance roles, preferably in a SaaS or multi-tenant product company • Hands-on experience implementing/maintaining ISO 27001 and SOC 2 Type II (not just awareness – actual control ownership) • Practical ITGC experience – access controls, change management, backup/DR testing, and evidence collection for audit purposes • Strong working knowledge of GDPR and DPDPA; CCPA exposure a plus • Familiarity with data protection regimes in Middle East and Philippines (or demonstrated ability to quickly get up to speed on new regional frameworks) • Experience running third-party/vendor risk assessments end-to-end • Comfortable presenting to and fielding tough questions from client security/procurement teams and external auditors • Strong written communication – you'll be drafting policies, responses, and audit narratives • Relevant certifications a plus: CISA, CIPP/E, ISO 27001 Lead Auditor/Implementer, CDPSE Nice to Have • SOC 1 Type II experience – understanding of ICFR-related controls, distinct from SOC 2's trust services criteria focus • Experience with CERT-In incident reporting requirements (India) • Exposure to NIST CSF or CIS Controls • Prior experience in an HRMS/HR-tech or other regulated SaaS vertical handling employee PII at scale • Exposure to SOX ITGC testing (useful if Keka's customer base includes publicly listed companies)