Senior Risk & Governance Engineer

AlphaSense
AlphaSense

India

Posted on Sep 10, 2026

About AlphaSense:

The world’s most sophisticated companies rely on AlphaSense to remove uncertainty from decision-making. With market intelligence and search built on proven AI, AlphaSense delivers insights that matter from content you can trust. Our universe of public and private content includes equity research, company filings, event transcripts, expert calls, news, trade journals, and clients’ own research content.

The acquisition of Tegus by AlphaSense in 2024 advances our shared mission to empower professionals to make smarter decisions through AI-driven market intelligence. Together, AlphaSense and Tegus will accelerate growth, innovation, and content expansion, with complementary product and content capabilities that enable users to unearth even more comprehensive insights from thousands of content sets. Our platform is trusted by over 6,000 enterprise customers, including a majority of the S&P 500. Founded in 2011, AlphaSense is headquartered in New York City with more than 2,000 employees across the globe and offices in the U.S., U.K., Finland, India, Singapore, Canada, and Ireland. Come join us!

About the Role

AlphaSense's GRC function is making a deliberate investment in automation and engineering, and we need a Senior GRC Engineer to lead that charge. You will design and build the technical automation that powers our compliance testing, evidence collection, risk monitoring, and GRC platform integrations—and you will own the governance architecture for how AI and agentic systems are built and deployed at AlphaSense. You sit at the intersection of security engineering and compliance operations. You are not just AI-curious; you are AI-native in practice: you use LLMs and agents for real substantive work—analysis, drafting, automation, code, investigation—and you apply rigorous judgment about where AI creates leverage, where it introduces risk, and where a human must remain in the loop. The goal is continuous compliance infrastructure that generates its own proof, not a compliance team that sprints to collect evidence before each audit cycle.The conventional GRC playbook was not built for a company like AlphaSense—and we are not following it. We are building a GRC engineering function that we believe represents what the entire industry will eventually need to become: automated, AI-native, and architected like a product rather than operated like a process. The frameworks are still catching up. The tooling is still maturing. We are doing the work now that others will reference later. If you want to build something that sets the standard—not follow one—this is the role.

Key Responsibilities

Compliance Automation Engineering

Design, build, and maintain automated compliance testing pipelines that continuously validate control adherence across cloud infrastructure, SaaS platforms, and internal systems. Replace point-in-time manual evidence collection with always-on automated checks. Pull evidence directly from APIs—cloud audit logs, identity systems, configuration posture, secrets management—without relying on screenshots or control owner self-attestation.

GRC Platform Engineering & Integration

Own the technical configuration and integration of the GRC platform (Drata or equivalent). Build custom API integrations, automated evidence connectors, and workflow automation that reduce manual control owner burden and keep evidence artifacts current. Know where the platform solves the problem and where custom code is the better answer.

AI-Native GRC Workflows

Develop and deploy AI-assisted workflows for evidence summarization, control narrative drafting, risk analysis, vendor questionnaire triage, and policy gap detection. Build with LLMs and agentic frameworks as a professional standard—not an experiment. Apply domain-specific judgment: know where AI helps, where it hurts, and where sensitive data, attacker-controlled inputs, or privileged access require a human in the loop.

AI & Agentic Systems Governance

Own the governance framework for AlphaSense's AI and agentic systems. Define the policies, control sets, and compliance posture that govern how agents are built and deployed—and build ahead of the compliance frameworks that are still catching up. Anticipate new policy requirements, adapt existing controls, and ensure the governance architecture is ready before auditors ask about it.

Policy as Code & Control Architecture

Build the policy program as code: policies in version control, peer-reviewed, with requirements expressed as enforceable rules and automated checks rather than static documents. Design a common controls framework that satisfies SOC 2, ISO 27001, ISO 42001, and future frameworks from a single control reference—no rework across frameworks.

Continuous Control Monitoring & Observability

Instrument controls with observability tooling so the GRC team receives real-time signals on control health rather than discovering failures at audit time. Build the data pipelines and dashboards that give engineering and product teams live visibility into their risk and compliance posture. Define alerting thresholds and remediation runbooks that make distributed control ownership practical.

Security Tooling Integration & Audit Readiness

Build and maintain integrations between GRC tooling and the broader security stack—SIEM, EDR, CSPM, identity platforms, and vulnerability management. Collaborate with the compliance team and auditors to understand evidence requirements, then engineer automated pipelines that pre-populate and maintain audit evidence. Maintain clear technical documentation and runbooks for all GRC automation so non-engineering GRC team members can operate and extend it.

What Success Looks Like

  • Security and compliance controls are clearly documented, tested, and consistently implemented—with evidence generated by integrations, not collected by hand
  • Risks and compliance gaps are identified early, tracked with owners, and remediated in partnership with technical teams before auditors find them
  • GRC processes scale alongside platform growth and new customer or regulatory requirements without proportional headcount growth
  • Stakeholders across Engineering, Legal, and Product view the GRC function as a trusted, enabling partner—not a compliance checkpoint
  • AI tools are used deliberately and responsibly: output is validated, sensitive data is protected, and automation creates leverage without introducing new risk
  • Compliance evidence is generated by automated pipelines, not collected by hand—audit readiness is a continuous state, not a quarterly sprint
  • The policy program lives in version control, is peer-reviewed, and control requirements are expressed as enforceable checks rather than static PDFs
  • Engineering and product teams have live visibility into their compliance and risk posture without needing to ask the GRC team

Who You Are

Basic Requirements

  • 6+ years of experience in GRC, information security, risk management, or IT audit, preferably in a SaaS or cloud-native environment
  • Strong understanding of security and compliance frameworks including SOC 2, ISO 27001, NIST CSF 2.0, and CIS Controls; working knowledge of ISO 42001 and NIST AI RMF
  • AI-native mindset: you use AI tools—LLMs, agents, automation—for real, substantive work including analysis, drafting, evidence gathering, and workflow automation. You apply judgment about where AI creates leverage and where a human must stay in the loop
  • Proficiency with GRC platforms for evidence management and control testing (Drata, Vanta, AuditBoard, ServiceNow GRC, or equivalent)
  • Familiarity with cloud environments (AWS, Azure, or GCP) and the security and compliance posture tooling that runs on them (CSPM, SIEM, identity platforms)
  • Experience supporting external audits across security or privacy domains, including evidence collection, control walkthroughs, and auditor interaction
  • Hands-on experience implementing automated control collection and continuous control monitoring—designing pipelines and integrations that pull evidence directly from systems rather than relying on manual artifact submission or self-attestation
  • Working knowledge of risk registers, control libraries, and policy governance lifecycles
  • Strong written communication, analytical thinking, and attention to detail; able to produce clear audit responses, risk narratives, and control documentation under deadline
  • 6+ years of experience in security engineering, DevSecOps, GRC tooling, or compliance automation—with ownership of both the policy/control side and the technical implementation
  • Coding ability that ships: Python or equivalent—you can call APIs, build integrations, schedule jobs, and deploy a working pipeline without help. Show us something you built
  • Hands-on experience building integrations with GRC platforms via APIs or native connectors, and direct evidence collection from cloud environments (AWS Config, GCP SCC, Azure Policy, or equivalent)
  • Demonstrated professional use of AI and LLM tools to automate documentation, analysis, or workflow tasks—with clear judgment about where AI creates leverage and where guardrails are required
  • Version control and CI/CD practices (Git, GitHub Actions, or equivalent); comfort with infrastructure-as-code concepts.

Nice to Have

  • Relevant certifications: CISA, CRISC, CISM, CISSP, CCSK, or ISO 27001 Lead Auditor/Implementer
  • Experience with AI governance frameworks including ISO 42001, NIST AI RMF, EU AI Act, or OECD AI Principles
  • Exposure to SOX ITGC cycles—managing evidence, walkthroughs, and findings with external auditors
  • Privacy program crossover: data mapping, DPIAs, GDPR/CCPA operational compliance
  • Scripting or automation experience (Python, JavaScript, or low-code tools) applied to GRC or compliance workflows
  • Experience with SOAR platforms or agentic AI orchestration frameworks (LangChain, n8n, Tines, AutoGen, or similar) applied to security or GRC workflows
  • Familiarity with policy-as-code and infrastructure-as-code approaches (Terraform, OPA/Rego) in a compliance context
  • Experience shipping LLM or agent-powered tooling that automates security or compliance activities and was adopted by a broader team
  • Background in detection engineering, security operations, or offensive security—you understand how the systems being governed actually fail
  • Experience building governance frameworks specifically for AI or agentic systems: model risk controls, ISO 42001 implementation, LLM deployment guardrails

AlphaSense is an equal-opportunity employer. We are committed to a work environment that supports, inspires, and respects all individuals. All employees share in the responsibility for fulfilling AlphaSense’s commitment to equal employment opportunity. AlphaSense does not discriminate against any employee or applicant on the basis of race, color, sex (including pregnancy), national origin, age, religion, marital status, sexual orientation, gender identity, gender expression, military or veteran status, disability, or any other non-merit factor. This policy applies to every aspect of employment at AlphaSense, including recruitment, hiring, training, advancement, and termination.

In addition, it is the policy of AlphaSense to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations, and ordinances where a particular employee works.

Recruiting Scams and Fraud

We at AlphaSense have been made aware of fraudulent job postings and individuals impersonating AlphaSense recruiters. These scams may involve fake job offers, requests for sensitive personal information, or demands for payment. Please note:

  • AlphaSense never asks candidates to pay for job applications, equipment, or training.
  • All official communications will come from an @alpha-sense.com email address.
  • If you’re unsure about a job posting or recruiter, verify it on our Careers page.

If you believe you’ve been targeted by a scam or have any doubts regarding the authenticity of any job listing purportedly from or on behalf of AlphaSense please contact us. Your security and trust matter to us.