Security Specialist (GRC)
Keka
Let the right jobs find you
Get personalised suggestions from verified company career pages, matched to your role, location, level, and skills.
Overview
Position Type
Full Time
Experience
5+ years
Job Description
About the Role\nKeka is looking for a GRC professional to own and mature our compliance and risk management program across multiple frameworks and jurisdictions. You will work closely with the CISO, engineering, legal, and customer-facing teams to keep Keka audit-ready, close third-party risk gaps, and represent our security posture to prospects and clients directly.\n\nKey Responsibilities\nFrameworks & Certifications\n- Own day-to-day compliance operations for ISO 27001 and SOC 2 Type II, including control ownership, evidence collection, and continuous readiness (not just audit-time scrambling)\n- Track control gaps, drive remediation with engineering/IT ops, and maintain the compliance calendar across certification cycles\nITGC\n- Own IT General Controls testing and evidence across access management, change management, backup/DR, logical security, and computer operations\n- Design and maintain ITGC control matrices mapped to ISO 27001/SOC 2 requirements, avoiding duplicate audit asks across frameworks\n- Coordinate with engineering/DevOps/IT ops to pull periodic evidence (access reviews, change logs, backup test results) on a recurring cadence rather than only at audit time\n- Support ITGC walkthroughs for financial/SOX-adjacent audits if/when applicable to Keka's customers or investors\nRegulatory Compliance\n- Manage GDPR and DPDPA compliance programs – DPIAs, RoPA, breach notification workflows, data subject request handling\n- Maintain CCPA compliance posture for US-facing operations\n- Build and maintain working knowledge of regional regulations relevant to Keka's expansion markets – Middle East (e.g., UAE PDPL, Saudi PDPL) and Philippines (RA 10173 / Data Privacy Act) – and translate these into internal controls and contract-ready positions\nAudits\n- Serve as primary point of contact for internal and external auditors across ISO 27001, SOC 2, ITGC, and customer-driven audits\n- Prepare audit evidence packages, walk auditors through controls, and manage audit findings through closure\nThird-Party Risk\n- Run vendor/third-party risk assessments (security questionnaires, DPA reviews, sub-processor risk scoring) before onboarding and periodically thereafter\n- Maintain a vendor risk register and escalate high-risk findings\nClient-Facing\n- Own responses to client security questionnaires (SIG, CAIQ, or custom formats)\n- Represent Keka's security and compliance posture on client due-diligence calls, confidently answering technical and regulatory questions in real time\n- Support sales/pre-sales and legal teams during DPA/MSA negotiations on security and privacy clauses\nProgram & Reporting\n- Maintain and evolve GRC tooling (trackers, dashboards, posture scoring) for leadership visibility\n- Contribute to board-level security posture reporting alongside the CISO\nRequired Skills & Experience\n- 5–8+ years in GRC/compliance roles, preferably in a SaaS or multi-tenant product company\n- Hands-on experience implementing/maintaining ISO 27001 and SOC 2 Type II (not just awareness – actual control ownership)\n- Practical ITGC experience – access controls, change management, backup/DR testing, and evidence collection for audit purposes\n- Strong working knowledge of GDPR and DPDPA; CCPA exposure a plus\n- Familiarity with data protection regimes in Middle East and Philippines (or demonstrated ability to quickly get up to speed on new regional frameworks)\n- Experience running third-party/vendor risk assessments end-to-end\n- Comfortable presenting to and fielding tough questions from client security/procurement teams and external auditors\n- Strong written communication – you'll be drafting policies, responses, and audit narratives\n- Relevant certifications a plus: CISA, CIPP/E, ISO 27001 Lead Auditor/Implementer, CDPSE\nNice to Have\n- SOC 1 Type II experience – understanding of ICFR-related controls, distinct from SOC 2's trust services criteria focus\n- Experience with CERT-In incident reporting requirements (India)\n- Exposure to NIST CSF or CIS Controls\n- Prior experience in an HRMS/HR-tech or other regulated SaaS vertical handling employee PII at scale\n- Exposure to SOX ITGC testing (useful if Keka's customer base includes publicly listed companies)