Base Career helps you apply smarter for this job.
Key skills for this role
Design Control Libraries : Build and maintain scalable, reusable security and compliance control libraries across the organization.
Framework Mapping : Translate complex regulatory and industry standards into standardized, actionable control definitions.
Risk & Policy Alignment : Map evidence requirements across overlapping compliance frameworks to eliminate redundancy and support the ISO & NIST Risk Management Frameworks.
Evidence Modeling : Define standardized evidence artifacts, validation logic, and assessment criteria for automated control evaluation.
Engineering Collaboration : Partner with engineering and security teams to build automated evidence collection pipelines and continuous compliance monitoring.
Data-Driven GRC : Build compliance content and metadata rule libraries using structured data formats (JSON/YAML) to scale platform capabilities.
NIST & ISO Implementation : Drive the practical design, implementation, and mapping of NIST (CSF / SP 800-53 / RMF / SOC 2) and ISO 27001/27002 control frameworks across technical environments.
Assessment Guidance : Define clear implementation guidance, control validation criteria, and self-assessment objectives for technical teams.
Continuous Improvement : Continuously refine GRC workflows, tooling, and framework content as standards and organizational needs evolve.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
, IND
Qualys is seeking a Senior Software Engineer to design, develop, and test scalable cloud-based software and distributed microservices. The role requires strong Java, Spring Boot, database, Kubernetes, Docker, and continu
Pune, IND
, IND
Pune, IND
Pune, IND
Pune, IND
Pune, IND
Pune, IND
, IND
Framework Implementation : Required hands-on experience implementing, operationalizing, and mapping ISO 27001/27002 and NIST SP 800-53 / NIST CSF / NIST RMF frameworks. Experience with PCI DSS, SOC 2, and CIS Controls is a strong plus.
Audit Readiness : Demonstrated ability to prepare technical environments and control owners for external audits through structured evidence management and control readiness models.
Risk Management : Deep understanding of ISO and NIST Risk Management Frameworks, including risk assessment methodologies, control testing, and remediation workflows.
Technical Aptitude : Understanding cloud platforms (AWS, Azure, or GCP), Identity & Access Management (IAM), and core security technologies.
Data & Automation : Experience working with structured data formats (JSON, YAML) to define validation logic or control metadata.
Evidence Management : Familiarity with evidence mapping, automated evidence validation, and modern compliance testing concepts.
Analytical Thinking : Ability to decompose complex regulatory texts into clear, practical engineering specifications.
Cross-Functional Collaboration : Excellent technical communication skills with the ability to bridge conversations between technical engineers, product teams, and management.
Documentation & Precision : High attention to detail in defining control definitions, test procedures, and architectural mappings.
Cloud-based security, compliance, and cyber risk management platform.
Visit company websiteJobs and hiring trendsFull-time
Senior
Onsite
Apply faster on company sites with our extension.