Information Security Engineer (II)
- AI
- Risk Management
- NIST
- ISO 27001
- PCI DSS
- GCP
- Azure
- Identity Management
- Vulnerability Management
- Network Security
- Machine Learning
- Python
- PowerShell
- REST API
- IaC
- ServiceNow
- SOC2
- SOX
- CISA
- Azure AI
About NCR VOYIX
NCR Voyix Corporation (NYSE: VYX) is a global platform-powered leader in unified commerce for shopping and dining. Combining a flexible, intelligent platform with end-to-end payments capabilities and services developed through its deep industry experience, NCR Voyix empowers retailers and restaurants to accelerate new possibilities for their operations, experiences and business outcomes. NCR Voyix is headquartered in Atlanta, Georgia, and serves customers in more than 35 countries worldwide.
Senior GRC Security Engineer (Compliance Automation & AI)
Location: Chennai, India
Position Summary
The Senior GRC Security Engineer is a member of NCR's Global Information Security organization and is responsible for advancing the company's Governance, Risk, and Compliance (GRC) capabilities through automation, cloud security governance, and AI-enabled solutions.
This role combines cybersecurity, compliance, and engineering expertise to modernize compliance operations and drive continuous controls monitoring. The successful candidate will work closely with security, engineering, cloud, infrastructure teams to automate compliance processes, improve control effectiveness, support regulatory and industry frameworks, and maintain audit readiness.
The ideal candidate possesses a strong technical background, hands-on cloud security experience, an understanding of cybersecurity frameworks, and the ability to leverage automation and AI technologies to improve compliance and risk management outcomes.
Key Responsibilities
GRC Engineering & Compliance Automation
Design, implement, and maintain automated compliance workflows, control validation processes, and evidence collection capabilities.
Develop solutions that reduce manual compliance activities through automation, orchestration, APIs, and AI-assisted technologies.
Partner with engineering and cloud teams to integrate compliance requirements into operational processes and technology solutions.
Implement and maintain continuous controls monitoring capabilities across enterprise and cloud environments.
Drive innovation and efficiency within compliance and audit processes through automation and emerging technologies.
Compliance
Interpret compliance requirements of NIST 800-53; ISO 27001, PCI DSS etc. and translate them into practical technical and operational controls.
Conduct compliance assessments, control reviews, and gap analyses.
Support internal and external audits, customer assessments, and regulatory examinations.
Cloud Security Governance
Assess and monitor security controls across GCP, Azure, and hybrid cloud environments.
Validate implementation of cloud security controls related to identity management, logging, encryption, vulnerability management, network security, and access governance.
Ensure cloud environments maintain alignment with organizational security standards and compliance obligations.
Provide guidance on cloud security architecture and compliance requirements.
Required Qualifications
Bachelor’s degree in Computer Science, Cybersecurity, Software Engineering, Information Technology, Information Systems, or a related technical field.
Minimum 5 years of experience in cybersecurity, security compliance, risk management, GRC, IT audit, security engineering, or related disciplines.
Experience supporting security and compliance programs involving industry and regulatory frameworks.
Strong understanding of security governance, risk management, and control frameworks.
Experience working within cloud environments, including GCP and/or Microsoft Azure.
Practical understanding of:
Security controls and architectures
Cloud security principles
Continuous controls monitoring
Strong verbal and written communication skills with the ability to communicate effectively with technical and business stakeholders.
Demonstrated problem-solving skills and the ability to manage multiple priorities in a fast-paced environment.
Preferred Qualifications
Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or related discipline.
Experience implementing compliance automation, workflow orchestration, or control validation solutions.
Experience leveraging AI and Generative AI technologies to improve governance, risk, compliance, audit, or security operations.
Experience working with global compliance and regulatory requirements.
Preferred Technical Skills
Working knowledge of Python, PowerShell, REST APIs, and automation frameworks.
Experience integrating security, cloud, ticketing, vulnerability management, and GRC platforms.
Familiarity with Infrastructure-as-Code (IaC), Policy-as-Code, Compliance-as-Code, and Continuous Controls Monitoring (CCM) concepts.
Understanding of cloud-native security capabilities and governance services.
Experience with ServiceNow GRC
Security and Compliance Framework Experience
Experience with one or more of the following frameworks and standards:
PCI DSS
ISO 27001 / ISO 27002
NIST Cybersecurity Framework (CSF)
SOC 2
SOX
CIS Critical Security Controls
Ability to align cybersecurity and cloud security controls with industry frameworks and regulatory requirements while ensuring controls are measurable, sustainable, and continuously monitored.
Preferred Certifications
Candidates should possess one or more of the following certifications:
CISA (Certified Information Systems Auditor)
AI-102: Azure AI Engineer Associate
Key Success Measures
Successful implementation and adoption of compliance automation initiatives.
Reduction in manual compliance effort through automation and AI-enabled solutions.
Continuous monitoring and validation of security controls.
Timely remediation of audit findings and identified risks.
Successful completion of internal, external, customer, and regulatory audits.
Improved compliance visibility, efficiency, and governance across the organization.
Why Join NCR
This is an opportunity to help transform compliance from a traditional audit-focused function into an engineering-driven, AI-enabled capability. You will play a key role in shaping the future of governance, risk, and compliance through automation, cloud security governance, and innovative security solutions while supporting a global technology organization.
Offers of employment are conditional upon passage of screening criteria applicable to the job
EEO Statement
Integrated into our shared values is NCR Voyix’s commitment to equal employment opportunity. All qualified applicants will receive consideration for employment without regard to sex, age, race, color, creed, religion, national origin, disability, sexual orientation, gender identity, veteran status, military service, genetic information, or any other characteristic or conduct protected by law. NCR Voyix is committed to being a globally inclusive company where all people are treated fairly, recognized for their individuality, promoted based on performance and encouraged to strive to reach their full potential. We believe in understanding and respecting differences among all people. Every individual at NCR Voyix has an ongoing responsibility to respect and support a globally diverse environment.
Statement to Third Party Agencies
To ALL recruitment agencies: NCR Voyix only accepts resumes from agencies on the preferred supplier list. Please do not forward resumes to our applicant tracking system, NCR Voyix employees, or any NCR Voyix facility. NCR Voyix is not responsible for any fees or charges associated with unsolicited resumes
“When applying for a job, please make sure to only open emails that you will receive during your application process that come from a @ncrvoyix.com email domain.”
Information Security Engineer (II) · NCR Voyix