Information Security Engineer (II)
NCR Corporation Chennai, Tamil Nadu, India
Software Development · 10,001+ employees
About the role
The role involves designing and implementing automated compliance workflows and continuous controls monitoring to modernize GRC capabilities. You will partner with engineering and cloud teams to integrate security requirements and ensure audit readiness across global environments.
What they look for
Requirements
Candidates must have at least 5 years of experience in cybersecurity, compliance, or risk management with a strong technical background in cloud security. A bachelor's degree in a relevant technical field is required, along with proficiency in security frameworks and automation technologies.
Full description
About NCR VOYIX
NCR Voyix Corporation (NYSE: VYX) is a global platform-powered leader in unified commerce for shopping and dining. Combining a flexible, intelligent platform with end-to-end payments capabilities and services developed through its deep industry experience, NCR Voyix empowers retailers and restaurants to accelerate new possibilities for their operations, experiences and business outcomes. NCR Voyix is headquartered in Atlanta, Georgia, and serves customers in more than 35 countries worldwide.
Senior GRC Security Engineer (Compliance Automation & AI)
Location: Chennai, India
Position Summary
The Senior GRC Security Engineer is a member of NCR's Global Information Security organization and is responsible for advancing the company's Governance, Risk, and Compliance (GRC) capabilities through automation, cloud security governance, and AI-enabled solutions.
This role combines cybersecurity, compliance, and engineering expertise to modernize compliance operations and drive continuous controls monitoring. The successful candidate will work closely with security, engineering, cloud, infrastructure teams to automate compliance processes, improve control effectiveness, support regulatory and industry frameworks, and maintain audit readiness.
The ideal candidate possesses a strong technical background, hands-on cloud security experience, an understanding of cybersecurity frameworks, and the ability to leverage automation and AI technologies to improve compliance and risk management outcomes.
Key Responsibilities
GRC Engineering & Compliance Automation
- Design, implement, and maintain automated compliance workflows, control validation processes, and evidence collection capabilities.
- Develop solutions that reduce manual compliance activities through automation, orchestration, APIs, and AI-assisted technologies.
- Partner with engineering and cloud teams to integrate compliance requirements into operational processes and technology solutions.
- Implement and maintain continuous controls monitoring capabilities across enterprise and cloud environments.
- Drive innovation and efficiency within compliance and audit processes through automation and emerging technologies.
Compliance
- Interpret compliance requirements of NIST 800-53; ISO 27001, PCI DSS etc. and translate them into practical technical and operational controls.
- Conduct compliance assessments, control reviews, and gap analyses.
- Support internal and external audits, customer assessments, and regulatory examinations.
Cloud Security Governance
- Assess and monitor security controls across GCP, Azure, and hybrid cloud environments.
- Validate implementation of cloud security controls related to identity management, logging, encryption, vulnerability management, network security, and access governance.
- Ensure cloud environments maintain alignment with organizational security standards and compliance obligations.
- Provide guidance on cloud security architecture and compliance requirements.
Required Qualifications
- Bachelor’s degree in Computer Science, Cybersecurity, Software Engineering, Information Technology, Information Systems, or a related technical field.
- Minimum 5 years of experience in cybersecurity, security compliance, risk management, GRC, IT audit, security engineering, or related disciplines.
- Experience supporting security and compliance programs involving industry and regulatory frameworks.
- Strong understanding of security governance, risk management, and control frameworks.
- Experience working within cloud environments, including GCP and/or Microsoft Azure.
- Practical understanding of:
- Security controls and architectures
- Cloud security principles
- Continuous controls monitoring
- Strong verbal and written communication skills with the ability to communicate effectively with technical and business stakeholders.
- Demonstrated problem-solving skills and the ability to manage multiple priorities in a fast-paced environment.
Preferred Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or related discipline.
- Experience implementing compliance automation, workflow orchestration, or control validation solutions.
- Experience leveraging AI and Generative AI technologies to improve governance, risk, compliance, audit, or security operations.
- Experience working with global compliance and regulatory requirements.
Preferred Technical Skills
- Working knowledge of Python, PowerShell, REST APIs, and automation frameworks.
- Experience integrating security, cloud, ticketing, vulnerability management, and GRC platforms.
- Familiarity with Infrastructure-as-Code (IaC), Policy-as-Code, Compliance-as-Code, and Continuous Controls Monitoring (CCM) concepts.
- Understanding of cloud-native security capabilities and governance services.
- Experience with ServiceNow GRC
Security and Compliance Framework Experience
Experience with one or more of the following frameworks and standards:
- PCI DSS
- ISO 27001 / ISO 27002
- NIST Cybersecurity Framework (CSF)
- SOC 2
- SOX
- CIS Critical Security Controls
Ability to align cybersecurity and cloud security controls with industry frameworks and regulatory requirements while ensuring controls are measurable, sustainable, and continuously monitored.
Preferred Certifications
Candidates should possess one or more of the following certifications:
- CISA (Certified Information Systems Auditor)
- AI-102: Azure AI Engineer Associate
Key Success Measures
- Successful implementation and adoption of compliance automation initiatives.
- Reduction in manual compliance effort through automation and AI-enabled solutions.
- Continuous monitoring and validation of security controls.
- Timely remediation of audit findings and identified risks.
- Successful completion of internal, external, customer, and regulatory audits.
- Improved compliance visibility, efficiency, and governance across the organization.
Why Join NCR
This is an opportunity to help transform compliance from a traditional audit-focused function into an engineering-driven, AI-enabled capability. You will play a key role in shaping the future of governance, risk, and compliance through automation, cloud security governance, and innovative security solutions while supporting a global technology organization.
Offers of employment are conditional upon passage of screening criteria applicable to the job
EEO Statement
Integrated into our shared values is NCR Voyix’s commitment to equal employment opportunity. All qualified applicants will receive consideration for employment without regard to sex, age, race, color, creed, religion, national origin, disability, sexual orientation, gender identity, veteran status, military service, genetic information, or any other characteristic or conduct protected by law. NCR Voyix is committed to being a globally inclusive company where all people are treated fairly, recognized for their individuality, promoted based on performance and encouraged to strive to reach their full potential. We believe in understanding and respecting differences among all people. Every individual at NCR Voyix has an ongoing responsibility to respect and support a globally diverse environment.
Statement to Third Party Agencies To ALL recruitment agencies: NCR Voyix only accepts resumes from agencies on the preferred supplier list. Please do not forward resumes to our applicant tracking system, NCR Voyix employees, or any NCR Voyix facility. NCR Voyix is not responsible for any fees or charges associated with unsolicited resumes
“When applying for a job, please make sure to only open emails that you will receive during your application process that come from a @ncrvoyix.com email domain.”
Similar roles
-
Senior Account Executive, Public Relations (Cybersecurity)
Highwire Connecticut, United States
-
Staff Product Security Engineer, PSIRT
ServiceNow Hyderabad, Telangana, India
-
Senior Security Engineer
Capco London, England, United Kingdom
-
Principal Security Engineer
Capco London, England, United Kingdom
-
Senior Security Engineer
DAIWA CAPITAL MARKETS AMERICA INC New York, New York, United States · $160K–$190K/yr
-
Information Security Engineer
Peoples Bank Louisville, Kentucky, United States