Enterprise customers choose Rubiscape not
only for its platform capabilities but for the trust it embodies — trust built
on rigorous compliance with ISO 27001, SOC 2, the DPDP Act 2023, and
sector-specific frameworks across BFSI, healthcare, and government. As
Compliance & GRC Engineer, you will own Rubiscape’s governance, risk, and
compliance programme: designing the control framework, managing audit cycles,
and bridging the gap between regulatory obligation and engineering reality. You
will be the custodian of the trust posture that enables Rubiscape to win and
retain Fortune 500 and public sector accounts.
· Own and maintain Rubiscape’s
ISO 27001 ISMS and SOC 2 Type II compliance programmes — including control
design, evidence collection, audit readiness, and ongoing surveillance.
· Interpret and operationalise
India’s DPDP Act 2023 requirements within the Rubiscape platform and internal
data handling processes; maintain the data processing register and consent
management documentation.
· Conduct and coordinate annual
risk assessments: asset inventory, threat-risk mapping, control gap analysis,
and residual risk acceptance with business owners.
· Manage the vendor and
third-party risk programme — security questionnaires, due diligence for
integrations, and contractual security obligations.
· Respond to customer security
questionnaires, RFP security sections, and enterprise trust reviews; maintain a
GRC knowledge base of pre-approved answers and evidence artefacts.
· Design and deliver security
awareness training and role-based compliance training for all Rubiscape
employees on a recurring annual cycle.
· Track regulatory changes
(CERT-IN directives, MeitY notifications, RBI/SEBI cybersecurity circulars) and
assess their impact on Rubiscape’s compliance posture within 30 days of
publication.
· Certifications: CISA, CISM,
CRISC, ISO 27001 Lead Auditor/Implementer, or CCSK.
· Experience with GRC platforms
(ServiceNow GRC, Vanta, Drata, or Tugboat Logic) for automated evidence
collection and continuous compliance monitoring.
· Familiarity with
sector-specific Indian compliance frameworks: RBI’s IT Framework for Banks,
IRDAI Cybersecurity Guidelines, or HIPAA-equivalent controls for healthcare
data.
· Prior experience supporting
government or defence customer security accreditation processes in India (MeitY
empanelment, STQC, or NIC security guidelines).
Rubiscape is India’s leading Decision
Intelligence Platform, unifying data engineering, BI, machine learning, and
agentic AI in a single governed platform. Built in Pune and trusted by Fortune
500 enterprises across BFSI, manufacturing, healthcare, and government. 8
international innovation patents. 10 Industry-Academia Labs & COEs. From BI
to AI — One Platform. Every Decision.
RequirementsRequirements
· 4+ years of GRC, information
security compliance, or audit experience in a technology company or Big-4 /
consulting firm serving technology clients.
· Demonstrated ownership of ISO
27001 certification or SOC 2 Type II audit cycles, including working directly
with external auditors.
· Working knowledge of India’s
DPDP Act 2023 and its operational implications for a SaaS platform collecting
and processing personal data.
· Ability to translate regulatory
and audit requirements into actionable engineering controls and work with
software and infrastructure teams on implementation.
· Strong written communication
skills for policy drafting, risk documentation, board-level risk reporting, and
customer-facing trust documentation.


