Infosec Analyst

super.money

Bengaluru

On-site

INR 900,000 - 1,500,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive compensation
Shape GRC for a top UPI company in I

Job summary

super.money is seeking a GRC Analyst/Engineer to help build and mature our Governance, Risk, and Compliance program. You'll work across security, legal, and engineering teams to assess risks, manage compliance frameworks, and ensure we meet regulatory obligations as we scale.

Responsibilities include maintaining ISO 27001, SOC 2, PCI-DSS, RBI guidelines; conducting risk assessments and audit management; coordinating evidence collection, and driving remediation.

Qualifications

  • 1–3 years of hands-on GRC, information security, or IT audit experience.
  • Working knowledge of ISO 27001, PCI-DSS, and RBI Digital Lending Guidelines (DLG).
  • Familiarity with fintech or BFSI regulatory expectations in the Indian context.
  • Experience with audit management or GRC tools (e.g., Sprinto, Scrut, Vanta, Drata).
  • Familiarity with cloud environments (AWS/GCP/Azure) and SaaS security controls.
  • Strong documentation skills able to write clear policies, procedures, and risk registers.
  • Ability to work cross-functionally and communicate risk in business terms.

Responsibilities

  • Maintain and improve the GRC program across frameworks such as ISO 27001, SOC 2, PCI-DSS, and RBI guidelines.
  • Conduct risk assessments, gap analyses, and control evaluations; track remediation to closure.
  • Manage audit cycles coordinate evidence collection, respond to auditor queries, and drive findings resolution.
  • Own vendor/third-party risk assessments, including security questionnaires and due diligence reviews.
  • Maintain policy and control documentation; drive periodic reviews and updates.
  • Monitor the regulatory landscape for changes relevant to the business and translate requirements into actionable controls.
  • Support incident response from a compliance perspective; assist with regulatory notifications if required.
  • Build and run security awareness initiatives and training programs.
  • Facilitate Security Champion program.
  • Liaise with cross functional teams, group companies to achieve security goals and charters.

Skills

GRC operations
risk assessment
compliance frameworks
policy writing
audit management
vendor risk
cross-functional communication
security awareness

Tools

Sprinto
Scrut
Vanta
Drata

Job description

About the Role

We're looking for a GRC Analyst/Engineer to help build and mature our Governance, Risk, and Compliance program. You'll work across security, legal, and engineering teams to assess risks, manage compliance frameworks, and ensure we meet regulatory obligations as we scale.

Responsibilities
  • Maintain and improve the GRC program across frameworks such as ISO 27001, SOC 2, PCI-DSS, and RBI guidelines
  • Conduct risk assessments, gap analyses, and control evaluations; track remediation to closure
  • Manage audit cycles coordinate evidence collection, respond to auditor queries, and drive findings resolution
  • Own vendor/third-party risk assessments, including security questionnaires and due diligence reviews
  • Maintain policy and control documentation; drive periodic reviews and updates
  • Monitor the regulatory landscape for changes relevant to the business and translate requirements into actionable controls
  • Support incident response from a compliance perspective; assist with regulatory notifications if required
  • Build and run security awareness initiatives and training programs.
  • Facilitate Security Champion program.
  • Liaise with cross functional teams, group companies to achieve security goals and charters.
Requirements
  • 1–3 years of hands-on GRC, information security, or IT audit experience
  • Working knowledge of ISO 27001, PCI-DSS, and RBI Digital Lending Guidelines (DLG)
  • Familiarity with fintech or BFSI regulatory expectations in the Indian context
  • Experience with audit management or GRC tools (e.g., Sprinto, Scrut, Vanta, Drata)
  • Familiarity with cloud environments (AWS/GCP/Azure) and SaaS security controls
  • Strong documentation skills able to write clear policies, procedures, and risk registers
  • Ability to work cross-functionally and communicate risk in business terms
Nice to Have
  • Certifications: CISA, CRISC, CompTIA Security+, ISO 27001 Lead Implementer/Auditor
  • Hands-on experience with GRC automation platforms such as Sprinto or Scrut Automation
  • Exposure to data privacy regulations (DPDPA, GDPR)
  • Familiarity with SISA, PCI assessments, or card data environments
  • Prior experience with RBI-regulated products or digital lending workflows
What We Offer
  • Competitive compensation
  • Opportunity to shape GRC for one of India's Top 5 UPI companies
  • An exciting Fintech startup that has grown exponentially
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security GRC Analyst
Senior Security GRC Analyst

Kite • Gurugram District

On-site
INR 1,500,000 - 2,300,000
GRC Analyst
GRC Analyst

Security Brigade • Delhi, Mumbai

Hybrid
INR 60,000 - 80,000
Competitive salary aligned to experience
Hybrid + remote-friendly
Sponsorship for relevant certifications
+2
GRC Manager/ GRC Lead
GRC Manager/ GRC Lead

Riskpro India Ventures • Mumbai

On-site
INR 1,000,000 - 1,500,000
GRC Analyst – Information Security & Compliance
GRC Analyst – Information Security & Compliance

WeRize • Bengaluru

On-site
INR 800,000 - 1,200,000
Security Compliance & GRC Lead
Security Compliance & GRC Lead

Cybrilla • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Grc Analyst
Grc Analyst

Infoshare soft • Pune District

On-site
INR 1,200,000 - 1,800,000
Senior GRC Analyst
Senior GRC Analyst

Tetuan Valley • India

On-site
INR 900,000 - 1,200,000
Variable Compensation
Compliance Analyst
Compliance Analyst

TRDFIN Support Services Pvt Ltd • Gurugram District

On-site
INR 800,000 - 1,000,000
Competitive compensation and benefits
Exposure to technology and financial compliance landscapes
Career growth in GRC and risk management
Security Consultant - GRC
Security Consultant - GRC

IBM • Mumbai

On-site
INR 2,400,000 - 3,600,000
Associate Manager - Information Security and Compliance
Associate Manager - Information Security and Compliance

Finnable • Bengaluru

On-site
INR 800,000 - 1,200,000