GRC Analyst – Information Security & Compliance

WeRize

Bengaluru

On-site

INR 800,000 - 1,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

WeRize is seeking a GRC Analyst to join our Information Security & Compliance team. You will drive and maintain cybersecurity compliance programs, collaborating with internal teams and external auditors to meet regulatory requirements and adopt best practices.

You will implement controls, conduct audits, update policies, and coordinate with regulators, certifying bodies, and vendors to promote a culture of compliant risk management.

Qualifications

  • 2–4 years of experience in information security, compliance, or risk management.
  • Strong understanding of cybersecurity standards like ISO 27001 and other cybersecurity frameworks (SOC 2, NIST, and RBI Master Direction).
  • Hands-on experience with internal audits and risk assessments.
  • Clear communication and collaboration skills.
  • Detail-oriented and proactive in identifying and solving problems.

Responsibilities

  • Implement and maintain compliance with ISO 27001 and other cybersecurity frameworks (e.g., SOC 2, NIST, and RBI Master Direction).
  • Conduct internal audits, risk assessments, and gap analyses.
  • Create and update policies, procedures, and evidence logs.
  • Work with teams across the company to resolve compliance issues.
  • Coordinate with external auditors, certifying bodies, and regulators.
  • Track regulatory updates and assess their impact.
  • Lead security awareness and compliance training.
  • Maintain compliance systems such as ISMS (Information Security Management System) and GRC (Governance, Risk, and Compliance) tools.
  • Support vendor risk assessments and DPIAs (Data Protection Impact Assessments).
  • Promote a culture of compliance and informed risk management.

Skills

Information security
Compliance
Risk management
Internal audits
Policy development
DPIAs
ISO 27001
NIST
SOC 2
Vendor risk

Job description

Founded in 2019 by Vishal Chopra and Himanshu Gupta, WeRize is building India’s largest full stack fintech platform for 500 million underserved middle‑class customers who live in 5000+ small towns of India. WeRize (Wortgage technologies pvt ltd) also owns RBI registered NBFC subsidiary (Wortgage Finance pvt ltd). This customer segment is not served by private sector banks, Insurers and Mutual Fund companies due to their low ticket‑size and lifetime value and is dependent on PSU/Govt banks, PSU/Government banks rarely provide financial products beyond basic savings accounts and these customers lack access to unsecured loans, MSME loans, credit cards, affordable housing loans, loan against property, health and life insurance and investment products. WeRize manufactures innovative unsecured consumer credit, mortgages, loan against property, MSME loans, savings and insurance products designed for this customer base keeping in mind their needs, requirements and purchasing power, with a view to add a layer of financial security to their lives and enable access to credit.

While customers in these geographies use smartphones, they need proper guidance and support when purchasing the right financial products for themselves. So, a pure digital model doesn’t work for this segment. WeRize has innovated on this front through its ‘Finance ki online dukaan (Social Shopify of Finance)’, a first of its kind social distribution tech platform in the financial services space that educates and enables local financially literate freelancers across these small towns to source business through online and offline channels, recommend the right financial product(s) to customers as well as provide after sales support. These freelancers, who are located in more than 5000+ towns and cities, earn as much as INR 30,000 a month from WeRize in commissions.

Our social distribution platform supported by financially literate freelancers means exceptionally low cost of customer acquisition (CAC) and operations costs compared to both fully digital and on‑the‑ground financial services providers. Digital conversions among this target group are way lower when compared to upper income customers in metros and hence pure digital CAC doesn’t workfor this segment. While companies like LIC and Fino Bank also rely on freelancer distribution, they deploy local on‑field teams/branches to manage freelancers in every city. That results in very high CAC and operations costs for such companies. WeRize on the other hand, has been able to acquire, train and manage thousands of freelancers in 5000+ cities only through its tech platform and without any feet‑on‑street team of its own. This results in highly profitable business model for Werize.

To know more about the company, please visit: https://www.werize.com/

About the Role:

We are looking for a GRC (Governance, Risk, and Compliance) Analyst to join our Information Security & Compliance team. In this role, you will be responsible for driving and maintaining our cybersecurity compliance programs. You will work with internal teams and external auditors to ensure we meet regulatory requirements and follow best practices in information security.

Responsibilities:
  • Implement and maintain compliance with ISO 27001 and other cybersecurity frameworks (e.g., SOC 2, NIST, and RBI Master Direction).
  • Conduct internal audits, risk assessments, and gap analyses.
  • Create and update policies, procedures, and evidence logs.
  • Work with teams across the company to resolve compliance issues.
  • Coordinate with external auditors, certifying bodies, and regulators.
  • Track regulatory updates and assess their impact.
  • Lead security awareness and compliance training.
  • Maintain compliance systems such as ISMS (Information Security Management System) and GRC (Governance, Risk, and Compliance) tools.
  • Support vendor risk assessments and DPIAs (Data Protection Impact Assessments).
  • Promote a culture of compliance and informed risk management.
What We’re Looking For:
  • 2–4 years of experience in information security, compliance, or risk management.
  • Strong understanding of cybersecurity standards like ISO 27001 and other cybersecurity frameworks (e.g., SOC 2, NIST, and RBI Master Direction).
  • Hands‑on experience with internal audits and risk assessments.
  • Clear communication and collaboration skills.
  • Detail‑oriented and proactive in identifying and solving problems.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Infosec Analyst
Infosec Analyst

super.money • Bengaluru

On-site
INR 900,000 - 1,500,000
Competitive compensation
Shape GRC for a top UPI company in I
GRC Analyst
GRC Analyst

Security Brigade • Delhi, Mumbai

Hybrid
INR 60,000 - 80,000
Competitive salary aligned to experience
Hybrid + remote-friendly
Sponsorship for relevant certifications
+2
Security Compliance & GRC Lead
Security Compliance & GRC Lead

Cybrilla • Bengaluru

On-site
INR 2,400,000 - 4,200,000
GRC Lead / Security Compliance Lead
GRC Lead / Security Compliance Lead

Gnani Innovations Private Limited. • India

On-site
INR 350,000 - 600,000
Governance, Risk and Compliance (GRC) Specialist
Governance, Risk and Compliance (GRC) Specialist

Career Guideline • Pune District

On-site
INR 1,500,000 - 2,500,000
Required Skillset
Required Skillset

eProtect 360 • Mumbai

On-site
INR 2,000,000 - 3,500,000
GRC Manager/ GRC Lead
GRC Manager/ GRC Lead

Riskpro India Ventures • Mumbai

On-site
INR 1,000,000 - 1,500,000
Cybersecurity Specialist – Governance, Risk & Compliance (GRC)
Cybersecurity Specialist – Governance, Risk & Compliance (GRC)

TalaKunchi Networks Pvt Ltd • Mumbai

On-site
INR 800,000 - 1,200,000
Opportunity to shape InfoSec practices
Work on cutting-edge cybersecurity initiatives
Be part of a forward-thinking team
Senior Information Security Analyst-(Risk and Regulatory Tech Complainance)
Senior Information Security Analyst-(Risk and Regulatory Tech Complainance)

KreditBee • Bengaluru

On-site
INR 800,000 - 1,500,000
Compliance Analyst
Compliance Analyst

TRDFIN Support Services Pvt Ltd • Gurugram District

On-site
INR 800,000 - 1,000,000
Competitive compensation and benefits
Exposure to technology and financial compliance landscapes
Career growth in GRC and risk management