Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Xpentra in Mumbai is seeking a detail-oriented GRC & Information Security Executive to support governance, risk, compliance and information security initiatives. The role bridges technical execution and regulatory requirements to keep processes secure and audit-ready.
You'll draft IT policies, support audits, conduct risk assessments and collaborate with IT teams and external auditors to close findings. A strong foundation in IT infrastructure and security controls is essential, with ISO 27001,
GRC & InfoSec Executive
Mumbai
Full-time
Monday to Friday
We are looking for a highly detailed-oriented and technically aware IT GRC and Information Security Executive to support Q2Pay Technologies governance, risk, compliance and information security initiatives.
This role is ideal for an ambitious professional with foundational experience in IT infrastructure, InfoSec controls and IT documentation who wants to play a key role in safeguarding our technology landscape. You will bridge the gap between technical execution and regulatory compliance, ensuring our processes remain secure, robust and audit-ready.
Draft, implement and maintain critical IT artifacts, including IT Operations policies, Information Security Policies, Standard Operating Procedures (SOPs), process documents and control descriptions.
Support internal and external audits by proactively preparing evidence collections, tracking remediation progress and closing audit findings. Identify vulnerabilities or missing links in current IT controls and documentation suggesting concrete measures to fix them.
Assist in IT Infrastructure risk identification, assessment and systematic tracking to mitigate potential vulnerabilities before they affect operations.
Partner with core technical teams to implement and verify basic information security controls, including access management, backup verifications and endpoint security controls.
Act as a central point of contact, working closely with IT Infrastructure, Developers, Application teams and external auditors to track open compliance tasks and ensure timely closure.
Core Technical Knowledge: A strong foundational understanding of IT Infrastructure (Operating Systems, Databases, Networks, Applications and Hardware) alongside core Information Security principles.
Compliance Frameworks: Deep familiarity with industry-standard security frameworks such as ISO 27001, SOC 2, NIST and local regulations like DPDP.
Documentation Excellence: Exceptional technical and process documentation skills with a sharp eye for detail. You excel at spotting "what is missing" in a process or workflow.
Communication & Drive: Strong written and verbal communication skills, paired with a proactive mindset to take ownership of compliance trackers.
Bachelor's or Master's Degree in IT, Computer Science, Cyber Security or a closely related field.
Hands-on experience or familiarity with cloud computing platforms, particularly AWS, is a distinct advantage.
Industry certifications such as ISO 27001 Lead Implementer/Auditor, CompTIA Security+ or CISA are highly preferred but not mandatory.
Fast-Track to Engineering Management: This role is designed with a clear career growth trajectory, offering a structured path to transition into an IT GRC Manager or Information Security Manager.
You will work directly with cross-functional engineering and infrastructure teams giving you a holistic view of the company's tech ecosystem and a direct hand in securing it.
Dive deep into cutting-edge cloud security environments and complex regulatory compliance frameworks within a fast-growing technology space.