Associate Compliance Manager Tech Bangalore, Karnataka

meesho

Bengaluru

On-site

INR 1,200,000 - 1,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Meesho is seeking a hands-on individual contributor in its Security & Compliance team to drive a multi-framework compliance program. This role involves managing ISO 27001:2022 and SOC 2 Type II certifications, operationalising India's DPDP Rules 2025, and collaborating with various departments including Engineering, IT, and Legal.

The ideal candidate will have 4–6 years of experience in security compliance or IT audits, with a strong background in IT General Controls and vendor risk management.

Qualifications

  • Hands-on experience with SOC 2 Type II end-to-end.
  • Strong design and testing of IT controls.
  • Experience across the vendor lifecycle in TPRM.

Responsibilities

  • Own ISO 27001:2022 and SOC 2 Type II certification cycles.
  • Design and test IT General Controls (ITGC).
  • Conduct internal audits and maintain the enterprise risk register.

Skills

Security compliance
ITGC experience
TPRM experience
Cloud knowledge (AWS/GCP)
Stakeholder management
Excellent written communication

Education

4–6 years in security compliance or IT audit

Tools

GRC platforms (Sprinto, Vanta, etc.)

Job description

Meesho's Security & Compliance team safeguards a platform that 5% of Indian households shop with – millions of orders, billions of data points, zero downtime as a baseline. We own the Information Security Management System, drive every external certification, and shape how Meesho earns trust with sellers, buyers, partners and regulators. We move fast, default to automation, and obsess over evidence.

About the Role

This is a hands‑on individual contributor role for someone who wants to drive – not just oversee – a multi‑framework compliance program. You'll be the DRI for ISO 27001:2022 and SOC 2 Type II, run end‑to‑end ITGC and TPRM cycles, and help operationalise India's DPDP Rules 2025 across a product organisation that processes data at meaningful scale. You'll work directly with Engineering, IT, Legal, Product, and external auditors.

What you will do
Certifications & external audits

Own the certification and surveillance cycle for ISO 27001:2022 and SOC 2 Type II; act as the single point of contact for external auditors.

Plan and execute readiness assessments, gap closure, evidence collection, control walkthroughs, and management responses.

Maintain audit calendars, evidence repositories, and bridge letters between audit windows.

Drive PCI DSS v4.0.1 scope‑reduction and assessment activities for in‑scope environments.

Maintain Meesho's ISMS aligned to ISO 27001:2022 – all 93 Annex A controls mapped across Organizational, People, Physical and Technological themes, with named owners and live evidence.

Author, review, version‑control and socialise security policies, standards, and procedures.

Map controls across frameworks: ISO 27001:2022, SOC 2 TSC, PCI DSS v4.0.1, NIST CSF 2.0, CIS Controls v8, DPDP.

ITGC & internal audits

Design, test and continuously improve IT General Controls: access management, change management, IT operations, and SDLC.

Plan and execute internal audits; track findings to closure with engineering and IT.

Build and maintain the enterprise risk register; run RCSA, define KRIs, drive risk treatment plans and residual‑risk acceptance with leadership.

Third‑Party Risk Management (TPRM)

Partner with Legal and Procurement to embed security clauses in MSAs, DPAs, and sub‑processor agreements.

Conduct on‑site / virtual vendor audits for tier‑1 vendors and report to the security council.

Privacy & data protection

Operationalise the DPDP Act 2023 + DPDP Rules 2025 across the business: DPIAs, consent and notice flows, data‑principal rights, 72‑hour breach notification, and Records of Processing Activity.

Prepare Meesho for likely Significant Data Fiduciary (SDF) obligations: independent data‑auditor coordination, DPO interfacing, algorithmic transparency, and children's‑data safeguards.

Track IT Act, CERT‑In directions, and sector‑specific guidelines as relevant.

Business continuity

Maintain BCP and DR aligned to ISO 22301 – BIAs, RTO/RPO definitions, and annual DR / failover testing.

Awareness & culture

Run organisation‑wide security and privacy awareness: onboarding, refreshers, phishing simulations, and role‑based modules.

Partner & customer trust

Respond to seller, partner and enterprise security questionnaires; maintain the Trust Center and security collateral.

What you will need

4–6 years in security compliance, IT audit, or GRC at a product company (SaaS, fintech, e‑commerce, payments, consumer internet).

Hands‑on experience driving SOC 2 Type II end‑to‑end, including auditor management.

Strong ITGC experience: access, change, ops, and SDLC control design and testing.

Strong TPRM experience across the full vendor lifecycle.

Working knowledge of cloud (AWS and/or GCP) – shared‑responsibility model, CIS benchmarks, native services for evidence (AWS Config, GCP SCC, CloudTrail, IAM Analyzer).

Demonstrated stakeholder management with Engineering, IT, Legal, Product, and external auditors.

Excellent written communication – you'll author policies, audit responses, and risk reports read by senior leadership.

Nice to have

DPDP Act 2023 / DPDP Rules 2025 implementation experience; familiarity with GDPR or ISO 27701.

Hands‑on with a GRC platform: Sprinto, Vanta, Drata, OneTrust, AuditBoard, MetricStream, ServiceNow GRC, or Archer.

ISO 22301 BCMS experience.

Exposure to RBI / SEBI / IRDAI sectoral compliance.

PCI DSS v4.0.1 experience.

Certifications

CISA

CIPP/E or DCPP (privacy)

Equal Opportunity

At Meesho, we are committed to creating an inclusive and accessible workplace where every individual can thrive. In compliance with the Rights of Persons with Disabilities Act, 2016, we uphold the following principles:

  • Equal Opportunity: We ensure that employment opportunities are never denied on the grounds of disability if the candidate is otherwise competent to perform the job.
  • Accessible Workplace: Our facilities are designed to be fully accessible, with amenities and assistive devices provided to support differently abled individuals in their work.
  • Inclusive Hiring Process: We adopt a transparent and non‑discriminatory selection process, including providing application forms in alternate formats and offering reasonable accommodations during interviews upon request.
  • Career Growth: We provide adequate training post‑recruitment and pre‑promotion, with training materials available in accessible formats to enable equal career progression.
  • Support & Confidentiality: A dedicated liaison officer/committee addresses concerns and grievances, while maintaining strict confidentiality of disability‑related information.
  • Awareness & Inclusion: We conduct awareness programs to promote a culture of inclusivity across the organization.

Meesho welcomes applicants and employees of all abilities and is dedicated to fostering an environment where differently abled persons can achieve their full potential.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Associate Compliance Manager
Associate Compliance Manager

B Capital • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Inclusive workplace
Career growth opportunities
Associate Director - Commerce Platform Commerce Platform Bangalore, Karnataka
Associate Director - Commerce Platform Commerce Platform Bangalore, Karnataka

meesho • Bengaluru

Hybrid
INR 4,000,000 - 7,000,000
Associate Director - Commerce Platform
Associate Director - Commerce Platform

Meesho • Bengaluru

Hybrid
INR 3,500,000 - 7,000,000
Assistant Manager - Business Finance Finance, Legal & PR Bangalore, Karnataka
Assistant Manager - Business Finance Finance, Legal & PR Bangalore, Karnataka

meesho • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Health insurance
Equity-based compensation
Flexible benefits
+1
AM/ Manager - Risk & Decision Science
AM/ Manager - Risk & Decision Science

Meesho • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Medical insurance
MeeCare wellness
Leave policies
+2
Software Development Engineer III -Backend Tech Bangalore, Karnataka
Software Development Engineer III -Backend Tech Bangalore, Karnataka

meesho • Bengaluru

On-site
INR 4,000,000 - 6,500,000
Senior Associate / Assistant Manager - Program Ops (Fulfilment & Experience)
Senior Associate / Assistant Manager - Program Ops (Fulfilment & Experience)

B Capital • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Medical insurance for employees and my
Parental support
Learning & development support
+1
Senior Manager - Commerce Platform
Senior Manager - Commerce Platform

B Capital • Bengaluru

On-site
INR 3,500,000 - 5,200,000
Program Manager AI Services Bangalore, Karnataka
Program Manager AI Services Bangalore, Karnataka

meesho • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Head of Meesho Foundation
Head of Meesho Foundation

Meesho • Bengaluru

On-site
INR 6,000,000 - 9,000,000
Medical insurance for employees and
Relocation assistance
Learning and development support
+1