Job Overview
We are looking for a detail-oriented and proactive Compliance Executive to manage and strengthen our Information Security, Governance, Risk, and Compliance (GRC) framework. In this role, you will play a key part in maintaining strict compliance standards, including PCI-DSS and ISO 27001, while supporting internal/external audits and risk management initiatives across our infrastructure.
Key Responsibilities
- PCI-DSS Compliance:
- Lead end-to-end PCI-DSS compliance requirements, scope definition, evidence collection, and Annual Attestation of Compliance (AoC) process.
- Work closely with engineering, DevOps, and IT security teams to ensure cardholder data environment (CDE) controls are implemented and continuously maintained.
- ISO 27001 & Framework Management:
- Support the maintenance and continuous improvement of the Information Security Management System (ISMS) in alignment with ISO/IEC 27001 standards.
- Conduct internal audits, gap analyses, and assist in third-party certification/surveillance audits.
- Governance, Risk & Compliance (GRC):
- Execute periodic risk assessments across IT, cloud, and operational operations; maintain and update the Enterprise Risk Register.
- Draft, review, and update information security policies, procedures, standard operating procedures (SOPs), and guidelines.
- Coordinate with cross-functional teams to track remediation plans for security vulnerabilities, audit findings, and compliance gaps.
- Vendor Risk & Regulatory Compliance:
- Perform Third-Party Risk Management (TPRM) assessments for vendors and key service providers.
- Track regulatory guidelines (e.g., RBI/local financial regulators, GDPR/Data Privacy laws) applicable to the business.
- Audit Support & Security Awareness:
- Serve as the main point of contact for external auditors, Qualified Security Assessors (QSAs), and clients during compliance reviews.
- Plan and deliver company-wide security awareness training programs and phishing simulation campaigns.
Qualifications & Key Requirements
- Experience: 25 years of hands‑on experience in GRC, Information Security Compliance, or Audit roles.
- Core Expertise: Deep understanding of PCI-DSS v4.0 standards and ISO/IEC 27001:2022 requirements.
- Technical Familiarity: Understanding of cloud security (AWS/Azure/GCP), network security, encryption standards, vulnerability management (VA/PT), and access controls.
Certifications (Preferred / Plus)
- ISO 27001 Lead Auditor / Lead Implementer