Security Specialist (GRC)
Keka Technologies Pvt. LtdHyderabad, TG, IndiaAugust 19, 2026
On-site
Full-time
GRC
Senior · 5–8 yrs
About the Role
Keka is looking for a GRC professional to own and mature our compliance and risk management program across multiple frameworks and jurisdictions. You will work closely with the CISO, engineering, legal, and customer-facing teams to keep Keka audit-ready, close third-party risk gaps, and represent our security posture to prospects and clients directly.
Key Responsibilities
Frameworks & Certifications
- Own day-to-day compliance operations for ISO 27001 and SOC 2 Type II, including control ownership, evidence collection, and continuous readiness (not just audit-time scrambling)
- Track control gaps, drive remediation with engineering/IT ops, and maintain the compliance calendar across certification cycles
ITGC
- Own IT General Controls testing and evidence across access management, change management, backup/DR, logical security, and computer operations
- Design and maintain ITGC control matrices mapped to ISO 27001/SOC 2 requirements, avoiding duplicate audit asks across frameworks
- Coordinate with engineering/DevOps/IT ops to pull periodic evidence (access reviews, change logs, backup test results) on a recurring cadence rather than only at audit time
- Support ITGC walkthroughs for financial/SOX-adjacent audits if/when applicable to Keka's customers or investors
Regulatory Compliance
- Manage GDPR and DPDPA compliance programs – DPIAs, RoPA, breach notification workflows, data subject request handling
- Maintain CCPA compliance posture for US-facing operations
- Build and maintain working knowledge of regional regulations relevant to Keka's expansion markets – Middle East (e.g., UAE PDPL, Saudi PDPL) and Philippines (RA 10173 / Data Privacy Act) – and translate these into internal controls and contract-ready positions
Audits
- Serve as primary point of contact for internal and external auditors across ISO 27001, SOC 2, ITGC, and customer-driven audits
- Prepare audit evidence packages, walk auditors through controls, and manage audit findings through closure
Third-Party Risk
- Run vendor/third-party risk assessments (security questionnaires, DPA reviews, sub-processor risk scoring) before onboarding and periodically thereafter
- Maintain a vendor risk register and escalate high-risk findings
Client-Facing
- Own responses to client security questionnaires (SIG, CAIQ, or custom formats)
- Represent Keka's security and compliance posture on client due-diligence calls, confidently answering technical and regulatory questions in real time
- Support sales/pre-sales and legal teams during DPA/MSA negotiations on security and privacy clauses
Program & Reporting
- Maintain and evolve GRC tooling (trackers, dashboards, posture scoring) for leadership visibility
- Contribute to board-level security posture reporting alongside the CISO
Required Skills & Experience
- 5–8+ years in GRC/compliance roles, preferably in a SaaS or multi-tenant product company
- Hands-on experience implementing/maintaining ISO 27001 and SOC 2 Type II (not just awareness – actual control ownership)
- Practical ITGC experience – access controls, change management, backup/DR testing, and evidence collection for audit purposes
- Strong working knowledge of GDPR and DPDPA; CCPA exposure a plus
- Familiarity with data protection regimes in Middle East and Philippines (or demonstrated ability to quickly get up to speed on new regional frameworks)
- Experience running third-party/vendor risk assessments end-to-end
- Comfortable presenting to and fielding tough questions from client security/procurement teams and external auditors
- Strong written communication – you'll be drafting policies, responses, and audit narratives
- Relevant certifications a plus: CISA, CIPP/E, ISO 27001 Lead Auditor/Implementer, CDPSE
Nice to Have
- SOC 1 Type II experience – understanding of ICFR-related controls, distinct from SOC 2's trust services criteria focus
- Experience with CERT-In incident reporting requirements (India)
- Exposure to NIST CSF or CIS Controls
- Prior experience in an HRMS/HR-tech or other regulated SaaS vertical handling employee PII at scale
- Exposure to SOX ITGC testing (useful if Keka's customer base includes publicly listed companies)