Finde deine nächste berufliche Chance

Suche Stellen nach Beruf, Fähigkeit und Standort. Prüfe die Anforderungen, bevor du deine Bewerbung vorbereitest.

Eine gute Stellensuche endet nicht bei einem interessanten Titel. Vergleiche Aufgaben, Anforderungen und Arbeitsbedingungen mit deiner Erfahrung. Dieser Leitfaden hilft dir, passende Möglichkeiten auszuwählen, relevante Unterlagen vorzubereiten und zu prüfen, wo du deine Bewerbung einreichen kannst.

Die Oberfläche ist auf Deutsch. Die Titel und Beschreibungen der Arbeitgeber bleiben in ihrer ursprünglichen Veröffentlichungssprache, die Englisch sein kann.

Filter zurücksetzen

Ergebnisse: 8.342

← Zurück zu den Ergebnissen

Senior Security Engineer GRC Engineering

One Identity

Remote-Arbeit

Standort
Remote (India)
Arbeitszeit
Full Time
Veröffentlicht
8. Okt. 2026

Prüfe vor der Bewerbung auf der Website des Arbeitgebers, ob die Stelle noch offen ist und welche Bedingungen gelten.

Stellenbeschreibung

Die Oberfläche ist auf Deutsch. Die Titel und Beschreibungen der Arbeitgeber bleiben in ihrer ursprünglichen Veröffentlichungssprache, die Englisch sein kann.

Overview Senior Security Engineer GRC Engineering One Identity · Information Security, Customer Trust & Assurance Senior individual contributor · India · Reports to the Director of Information Security Why this role exists One Identity holds certifications because customers require them before they buy, and the ones ahead open international regulatory markets. This role builds the centralized common controls framework, with ISO 27001 and SOC 2 as the base, that each addition maps into. Evidence comes from continuous monitoring, an audit request is answered with a query rather than an email thread, and the next market is a mapping exercise that unlocks revenue opportunities for the company. We run hosted services in Azure and AWS and ship software customers deploy in their own datacenters, so the evidence sits in cloud control planes, build pipelines, identity systems, and endpoints. Compliance analysts run the assessments and own questionnaire response. This seat builds the systems they draw from: an answer to an auditor and an answer to a customer should come from the same facts. We're separating from Quest Software and building an independent security function. The team is lean and globally distributed, and this seat owns the compliance engineering program. Scope comes from what you ship and from what the auditors accept. What you'll do Make evidence a query Own continuous control monitoring end to end: integrations into the identity provider, cloud control planes, code repositories, endpoint management, and ticketing, with alerting and escalation wired in, so a control that degrades reaches its owner with the context to act and the monitoring confirms the fix. Build the centralized common controls framework and the artifact layer on it: ISO 27001 and SOC 2 as the base, each new framework mapped against it, and evidence captured, timestamped, and indexed against the control that requires it. A control tested once answers every framework referencing it, and an audit-ready package assembles on demand. Hold the platform to its own standard. The evidence system sits inside audit scope, logs its own activity, and operates within the controls it measures. Put controls in code Write control validation as code: checks that programmatically test whether a control is implemented, with output an auditor accepts and an engineer can act on. Where a failed check traces to code, the correction arrives as a pull request against the pipeline, policy, or configuration that produced it. PRs, not tickets. Partner with the principal infrastructure seat on policy as code. They set the enforcement architecture inside the cloud platform; you make sure every enforced policy emits the evidence the frameworks require. Decide where agentic workflows belong in compliance engineering. Control mapping, evidence classification, and first-pass validation are tractable now; attestation is a human act. You set where automation acts, where it recommends, and how its output is verified. The same discipline applies to your own build: automation shares the lift, and nothing ships unverified. Own the program Own the program's direction. Which frameworks come next, which controls get automated first, and where the engineering effort goes: those calls are this seat's to make and to defend. Advance the program's metrics: control health, coverage against the framework map, remediation velocity, and the trend lines leadership steers by, produced from the same data the auditors draw on. Integrate cyber risk management into the platform: the risk register and exception handling run on the same control telemetry, automated wherever the workflow allows, with the hands-on remainder worked alongside the compliance analysts. An acceptance carries an owner and an expiry. Own asset prioritization as the base layer of the program: which systems and data matter most, kept current through automation, feeding risk decisions, control coverage, and remediation order. Front the technical side of audits: walk an assessor through how a control is implemented and how its evidence was produced, in language that holds up under the follow-up question. What we're looking for Required Six or more years across compliance program leadership and security or compliance engineering, with time spent on both the framework side and the build side. Equivalent depth counts. Depth in at least one of two forms: a major framework carried through assessment under your leadership, FedRAMP or comparable, from readiness through certification or authorization; or GRC engineering you owned end to end, with control telemetry, continuous monitoring, and evidence automation built and run under your direction. Strategic framework design: control mapping across frameworks you shaped yourself, and a defensible view on how a common controls framework should be structured. Engineering depth you've used recently: Python and API integration work of your own, and hands-on building with AI in the loop within the last six months. We'll ask what you built, when, and how you verified what the tooling produced. The three above are the bar. Everything below is depth we'd like and can build. If you meet the requirements and bring most of the rest, apply. We'd rather assess the gap ourselves than have you decide it for us. Also matters: framework fluency across ISO 27001 and SOC 2, and familiarity with FedRAMP 20x, where machine-validated Key Security Indicators are the assessment mechanism; NIS2, DORA, and PCI DSS and where they surface in customer requirements; policy-as-code frameworks and a view on where enforcement belongs; enough Azure and AWS depth to know where the evidence lives; a compliance automation platform and the judgment to know what to build around it; running an audit calendar and an assessor relationship without drama; writing an auditor and an engineer can both act on. Helpful: time on the assessor's side of the table; IRAP or another regime outside the US; evidence work across hosted services and customer-deployed software; prior time as a software or platform engineer. What you should know going in This seat brings the engineering function to modernize GRC. You direct where the engineering effort goes, you shape the tooling it runs on, and you build it. The bar is strategic and technical at once: the insight to shape the program and the depth to build the system that runs it, using AI to take lift out of the work without handing it the judgment. If you'd rather build the system that answers the question than answer the question, this is that seat. Company Description One Identity enables organizations of all sizes to better secure, manage, monitor, protect, and analyse information and infrastructure to help fuel innovation and drive their businesses forward. With team members around the globe, we intend to continue to grow revenues and add value to customers. When you join our team, you will have the opportunity to build and develop products at a scale few others can provide. Our product portfolio serves a large base of customers and we are addressing the strategic imperatives for enterprise businesses. Working with some of the most talented employees the industry has to offer, we provide enhanced career opportunities for team members to learn and grow in a rapidly changing environment. Why work with us? Life at One Identity means collaborating with dedicated professionals with a passion for technology. When we see something that could be improved, we get to work inventing the solution. Our people demonstrate our winning culture through positive and meaningful relationships. We invest in our people and offer a series of programs that enables them to pursue a career that fulfills their potential. Our team members’ health and wellness is our priority as well as rewarding them for their hard work. One Identity is an Equal Opportunity Employer and Prohibits Discrimination and Harassment of Any Kind: One Identity is committed to the principle of equal employment opportunity for all employees and to providing employees with a work environment free of discrimination and harassment. All employment decisions at One Identity are based on business needs, job requirements and individual qualifications, without regard to race, color, religion or belief, national, social or ethnic origin, sex (including pregnancy), age, physical, mental or sensory disability, HIV Status, sexual orientation, gender identity and/or expression, marital, civil union or domestic partnership status, past or present military service, family medical history or genetic information, family or parental status, or any other status protected by the laws or regulations in the locations where we operate. One Identity will not tolerate discrimination or harassment based on any of these characteristics. One Identity encourages applicants of all ages. Come join us. Note: We do not use text messaging or third-party messaging apps like Telegram to communicate with applicants, so please exercise caution if you are approached in this way and only interact with people claiming to be One Identity employees if they have an email address ending in @oneidentity.com. Originally posted on Himalayas

Suchen, vergleichen und deine Bewerbung vorbereiten

Beginne mit einem Beruf oder einer Fähigkeit, die du einsetzen möchtest. Nutze die Standort- und Berufsfilter und öffne Stellenanzeigen, um die Aufgaben zu vergleichen. Wenn du keine Ergebnisse findest, probiere einen kürzeren Suchbegriff oder entferne jeweils einen Filter.

Unterscheide notwendige Anforderungen von Wünschen. Prüfe Arbeitszeit, Vergütung und Standort, soweit sie angegeben sind. Auch Remote-Stellen können einen bestimmten Wohnsitz, eine Arbeitserlaubnis oder passende Arbeitszeiten verlangen. Bestätige die Verfügbarkeit und die vollständigen Bedingungen beim Arbeitgeber.

Wähle tatsächliche Beispiele aus deiner Erfahrung, die zu den Anforderungen passen. Erkläre deinen Beitrag und verwende nur belegbare Zahlen. Befolge die Vorgaben des Arbeitgebers und prüfe Kontaktdaten, Inhalt und PDF, bevor du die Bewerbung abschickst.

Vor dem Absenden deiner Bewerbung

Fragen zur Stellensuche

Warum sind manche Stellenanzeigen auf Englisch?

Arbeitgeber verfassen ihre eigenen Titel und Beschreibungen. Wir behalten diese Texte bei, damit Anforderungen und Bedingungen unverändert bleiben. Navigation und Leitfaden sind auf Deutsch. Findest du mit deutschen Begriffen keine Stellen, probiere auch die Bezeichnung oder Fähigkeit in der Sprache der Anzeige, etwa „software engineer“.

Kann ich bei einer Remote-Stelle aus jedem Land arbeiten?

Nicht unbedingt. Arbeitgeber können den Wohnsitz auf bestimmte Länder beschränken, eine Arbeitserlaubnis verlangen oder Arbeitszeiten vorgeben. Prüfe die Originalanzeige. Wenn diese Angaben fehlen, kläre sie mit dem Arbeitgeber, bevor du davon ausgehst, dass du von deinem Standort aus arbeiten kannst.

Was kann ich tun, wenn keine Ergebnisse erscheinen?

Versuche einen allgemeineren Titel oder eine einzelne Fähigkeit und entferne die Filter nacheinander. Unternehmen verwenden unterschiedliche Berufsbezeichnungen. Ist eine bestimmte Anzeige verschwunden, suche ihre Referenz auf der Karriereseite des Unternehmens. Weniger Filter machen eine geschlossene Stelle nicht wieder verfügbar.

Wird meine Bewerbung über ResumizeAI abgeschickt?

Die Bewerbungsschaltfläche öffnet eine externe Seite. Folge den Anweisungen des Arbeitgebers oder des Recruiting-Anbieters und bestätige dort den Versand. Ein in ResumizeAI vorbereiteter Lebenslauf ist noch keine eingereichte Bewerbung. Führt der Link nur zur Unternehmenswebsite, suche zuerst die konkrete Stelle.

Wie passe ich Lebenslauf und Anschreiben an?

Verknüpfe die Anforderungen mit Projekten, Aufgaben und Ergebnissen, die du erklären kannst. Hebe passende Erfahrung hervor, ohne Fähigkeiten oder Leistungen zu erfinden. Erläutere im Anschreiben dein Interesse anhand eines konkreten Beispiels. Beachte die verlangte Sprache und das Dateiformat und prüfe beide Dokumente vor dem Absenden.