Lead Security GRC Analyst

Falconfs

Gurugram District

On-site

INR 4,000,000 - 7,000,000

Full time

33 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Falconfs is seeking a Lead Security GRC Analyst to own and scale our information security governance, risk, and compliance function within a fast-growing AI-first fintech platform. You will lead PCI DSS and ISO 27001/SOC 2 programs and manage audits across issuing and regulatory engagements.

You will partner with Engineering, Risk, Internal Audit, and leadership to drive security and regulatory compliance for card, wallet, and UPI platforms while mentoring a small GRC team.

Qualifications

  • 7–10 years of information security governance, risk, and compliance experience in Indian fintech/payments.
  • Hands-on PCI DSS experience from issuer/issuer-processor side.
  • Hands-on ISO 27001 and SOC 2 compliance experience.
  • Strong knowledge of RBI and NPCI guidelines relevant to payments.
  • Proven experience owning and managing audits end-to-end.
  • Demonstrated ability to lead and mentor analysts and influence stakeholders.

Responsibilities

  • Define, own, and mature the GRC strategy, roadmap, and operating model in line with regulatory requirements and business goals.
  • Lead, mentor, and scale a GRC team of 1–2 analysts; establish standards and playbooks.
  • Own PCI DSS compliance across issuing/issuer-processor scope with data protection focus (PAN, PIN).
  • Own ISO 27001 and SOC 2 program implementation and maintenance; drive evidence and reviews.
  • Manage CERT-IN SAR/DLA compliance and regulatory engagements; liaison with regulators and partner banks.
  • Oversee enterprise information security risk program, risk assessments, and remediation tracking.
  • Direct internal and external audits (ISO 27001, PCI DSS, SOC 2, regulatory) end-to-end.
  • Own security policy framework, standards, and procedures; ensure governance and reporting.
  • Lead vendor risk assessments and security awareness initiatives across the organization.

Skills

GRC Leadership
PCI DSS
ISO 27001
SOC 2
RBI NPCI
Audit Management

Education

Professional Certifications (CISA/CISM/CRISC)

Tools

Cloud Platforms (AWS/Azure)

Job description

We are a fast-growing AI-first fintech platform enabling banks, NBFCs, and financial institutions to launch and scale next-generation credit products , including credit cards, credit lines, lending, and payment solutions. Our platforms process high-volume financial transactions and power business-critical customer journeys where reliability, performance, and security are non-negotiable.

We are looking for a Lead Security GRC Analyst who thrives in high-ownership environments, enjoys solving complex engineering challenges, and is passionate about building products that directly impact millions of users and financial institutions.

We are looking for an experienced Security GRC leader to own and scale our information security governance, risk, and compliance function. Reporting to the Security Architect, you will set the GRC strategy and roadmap, lead audits and regulatory engagements end-to-end, and manage a team of 1–2 GRC Analysts. This role is central to our position as a card issuer and issuer-processor, so a strong grounding in PCI DSS from the issuing side — and hands‑on experience within the Indian fintech and payments ecosystem — is essential. You will partner closely with Engineering, Product, Risk, Internal Audit, and senior leadership to drive security and regulatory compliance across our card, wallet, and UPI platforms, mentor and develop your team, and represent the security program to leadership, auditors, and regulators.

Key Responsibilities:
  • GRC Strategy & Program Ownership: Define, own, and continuously mature the organization’s security GRC strategy, roadmap, and operating model, aligned with business objectives and the regulatory landscape.
  • Team Leadership: Manage, mentor, and develop a team of 1–2 GRC Analysts; establish standards, playbooks, and ways of working; and build a scalable, repeatable GRC function.
  • PCI DSS Compliance (Issuer / Issuer-Processor): Own and lead PCI DSS compliance from the card issuer and issuer-processor perspective — protecting cardholder data (PAN) and PIN data across the issuance and processing flows, including HSM-based key management (PCI PTS HSM), CDE scope definition and reduction, and end‑to‑end audit readiness. (This role is focused on the issuing side, not the merchant/acquirer or payment-application / PA‑DSS perspective.)
  • ISMS & Standards: Own and continually improve the ISO 27001 Information Security Management System, including risk registers, SOA, policies, and control evidence; drive management reviews and continual‑improvement cycles.
  • SOC 2 Type 2: Own the implementation, operation, and audit of SOC 2 Type 2 controls.
  • CERT-IN / SAR / DLA: Lead and own SAR (System Audit Report) and DLA (Data Localisation Audit) compliance, managing relationships with CERT-IN empanelled auditors.
  • Regulatory Engagement: Monitor RBI, NPCI, and other applicable regulations; translate requirements into internal controls and roadmaps; and serve as a key liaison for regulatory and partner‑bank engagements.
  • Risk Management: Own the enterprise information security risk program — risk assessments, control gap analysis, risk treatment, and reporting of residual risk to leadership.
  • Audits & Assessments: Lead internal and external audits end‑to‑end, including ISO 27001, PCI DSS, SOC 2, and regulatory audits; drive remediation, track closure, and act as the primary escalation point.
  • Policy & Process: Own the security policy framework — develop, review, approve, and maintain security policies, standards, procedures, and guidelines.
  • Vendor Risk: Own the third‑party/vendor risk management program and lead security assessments of vendors and partners.
  • Security Awareness: Own and drive security awareness, training, and phishing simulation programs across the organization.
  • Reporting & Governance: Prepare and present dashboards and reports for leadership, the board, auditors, and regulators; drive governance forums and risk committees.
Required Qualifications:
  • 7–10 years of experience in Information Security Governance, Risk, and Compliance, with mandatory, hands‑on experience in the Indian fintech / payments ecosystem (RBI/NPCI‑regulated card, wallet, or UPI businesses), including experience leading GRC programs and/or teams.
  • Hands‑on PCI DSS experience from the card issuer / issuer‑processor side — securing PAN and PIN data across issuance and processing — as opposed to a purely merchant/acquirer or payment‑application (PA‑DSS) background.
  • Hands‑on, in‑depth experience with ISO 27001 and SOC 2 compliance.
  • Strong, practical knowledge of RBI and NPCI guidelines relevant to payments, wallets, and card platforms.
  • Proven experience owning and managing audits end‑to‑end across risk assessments, control frameworks, and remediation.
  • Strong understanding of HSM concepts and key management for PCI DSS in an issuing environment.
  • Demonstrated ability to lead and mentor analysts and influence cross‑functional and senior stakeholders.
  • Excellent communication, documentation, and executive stakeholder management skills.
  • Relevant certifications such as CISA, CISM, CRISC, CGRC, ISO 27001 LA/LI are preferred.
Good-to-Have:
  • Working knowledge of the Digital Personal Data Protection (DPDP) Act 2023.
  • Exposure to AI security and AI governance frameworks.
  • PCI QSA / ISA or similar audit credentials.
  • Experience working in cloud environments (AWS, Azure, GCP).
What You Will Work On:
  • Securing and governing a regulated payments ecosystem spanning credit cards, prepaid cards, wallets, and UPI credit lines — from a card issuer and issuer‑processor standpoint.
  • Driving and owning compliance maturity across ISO 27001, SOC 2 Type 2, PCI DSS (issuing side), and CERT-IN requirements.
  • Building and leading a scalable GRC function and team that aligns with RBI and NPCI expectations.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security GRC Analyst
Senior Security GRC Analyst

Kite • Gurugram District

On-site
INR 1,500,000 - 2,300,000
GRC Lead / Security Compliance Lead
GRC Lead / Security Compliance Lead

Gnani Innovations Private Limited. • India

On-site
INR 350,000 - 600,000
Lead GRC
Lead GRC

Ashley Global Capability Center • Chennai District

On-site
INR 1,200,000 - 1,800,000
GRC Lead
GRC Lead

Baldor Technologies • Mumbai

On-site
INR 300,000 - 600,000
Compliance Executive
Compliance Executive

Plutos One • Dadri

On-site
INR 1,200,000 - 1,800,000
Cybersecurity GRC Consultant(PCI DSS)
Cybersecurity GRC Consultant(PCI DSS)

Atos SE • Mumbai

On-site
INR 1,500,000 - 2,200,000
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

844 Altera Semiconductor Technology India Pvt. Ltd. • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Senior GRC Analyst
Senior GRC Analyst

3M HEALTHCARE • Hyderabad

On-site
INR 1,500,000 - 2,200,000
Senior - Information Security & Privacy
Senior - Information Security & Privacy

National Payments Corporation of India • Mumbai

On-site
INR 3,500,000 - 7,000,000
Insurance & Wellness
Annual Wellness Bouquet
Parental Leave
+1
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

Altera • Bengaluru

On-site
INR 3,000,000 - 4,500,000