Senior Security GRC Analyst

Kite

Gurugram District

On-site

INR 1,500,000 - 2,300,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Kite is seeking a hands-on Senior Security GRC Analyst to own governance, risk, and compliance across card, wallet, and UPI platforms. You will collaborate with Engineering, Product, Risk, and Internal Audit to ensure regulatory and security compliance in a fintech environment.

Responsibilities include maintaining ISO 27001 ISMS, supporting PCI DSS, SOC 2 Type 2, CERT‑IN, and regulatory tracking. Strong risk assessment, audit management, and stakeholder communication are essential.

Qualifications

  • 4–5 years of experience in Information Security Governance, Risk and Compliance in BFSI/fintech.
  • Hands-on with ISO 27001, SOC 2 and PCI DSS compliance.
  • Knowledge of RBI/NPCI guidelines relevant to payments and wallets.
  • Experience in risk assessments, control frameworks, and audit management.
  • Strong communication, documentation and stakeholder management.

Responsibilities

  • Maintain ISO 27001 ISMS, risk registers, SOA, policies and evidence.
  • Support PCI DSS compliance for card platforms including PIN data protection.
  • Assist SOC 2 Type 2 controls implementation and audits.
  • Coordinate CERT-IN SAR/DLA compliance with auditors.
  • Monitor RBI/NPCI regulations and translate to internal controls.
  • Conduct risk assessments and track remediation and closure.
  • Coordinate internal/external audits and governance reviews.
  • Develop, review and maintain security policies and procedures.
  • Perform vendor security assessments and drive awareness programs.
  • Prepare dashboards and reports for leadership and regulators.

Skills

Information Security
GRC Management
Regulatory compliance
Risk assessment
Audit management
Stakeholder management
Documentation

Education

CISA
CISM
CRISC
ISO 27001 LA/LI

Tools

GRC tools

Job description

4-5

Gurgaon

Full-Time

Senior Security GRC Analyst

Experience: 4–5 years

Industry: Fintech (Payments, Cards, Lending, UPI)

Role Overview

We are looking for a hands‑on Security GRC professional to own our information security governance, risk, and compliance programs. You will work closely with Engineering, Product, Risk, and Internal Audit teams to ensure regulatory and security compliance across our card, wallet, and UPI platforms.

Key Responsibilities
  • ISMS & Standards: Maintain, monitor, and improve the ISO 27001 Information Security Management System, including risk registers, SOA, policies, and control evidence.
  • PCI DSS Compliance: Support PCI DSS compliance for the credit card platform, including HSM-based protection of PIN data (PCI PTS HSM), scope reduction, and audit readiness.
  • SOC 2 Type 2: Support the implementation and audit of SOC 2 Type 2 controls.
  • CERT-IN / SAR DLA: Manage and coordinate SAR (System Audit Report) and DLA (Data Localisation Audit) compliance with CERT‑IN empaneled auditors.
  • Regulatory Tracking: Monitor RBI, NPCI, and other applicable regulations; translate requirements into internal controls and roadmaps.
  • Risk Management: Conduct risk assessments, control gap analysis, and treatment tracking across the organization.
  • Audits & Assessments: Coordinate internal and external audits, including ISO 27001, PCI DSS, SOC 2, and regulatory audits; track remediation and closure.
  • Policy & Process: Develop, review, and maintain security policies, standards, procedures, and guidelines.
  • Vendor Risk: Perform security assessments of third‑party vendors and partners.
  • Security Awareness: Drive security awareness, training, and phishing simulation programs.
  • Reporting: Prepare dashboards and reports for leadership, auditors, and regulators.
Required Qualifications
  • 4–5 years of experience in Information Security Governance, Risk, and Compliance within BFSI, fintech, or payments.
  • Hands‑on experience with ISO 27001, SOC 2, and PCI DSS compliance.
  • Knowledge of RBI and NPCI guidelines relevant to payments, wallets, and card platforms.
  • Experience with risk assessments, control frameworks, and audit management.
  • Strong understanding of HSM concepts and key management for PCI DSS.
  • Excellent communication, documentation, and stakeholder management skills.
  • Relevant certifications such as CISA, CISM, CRISC, CGRC, ISO 27001 LA/LI are preferred.
Good‑to‑Have
  • Knowledge of the Digital Personal Data Protection (DPDP) Act 2023.
  • Exposure to AI security and AI governance frameworks.
  • PCI QSA / ISA or similar audit credentials.
  • Experience working in cloud environments (AWS, Azure, GCP).
What You Will Work On
  • Securing and governing a regulated payments ecosystem spanning credit cards, prepaid cards, wallets, and UPI credit lines.
  • Driving compliance maturity across ISO 27001, SOC 2 Type 2, PCI DSS, and CERT‑IN requirements.
  • Building a scalable GRC function that aligns with RBI and NPCI expectations.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Infosec Analyst
Infosec Analyst

super.money • Bengaluru

On-site
INR 900,000 - 1,500,000
Competitive compensation
Shape GRC for a top UPI company in I
Senior Manager - Information Security (GRC)
Senior Manager - Information Security (GRC)

Sampoorna Consultants • Mumbai

On-site
INR 2,500,000 - 4,500,000
Cybersecurity GRC Consultant(PCI DSS)
Cybersecurity GRC Consultant(PCI DSS)

Atos SE • Mumbai

On-site
INR 1,500,000 - 2,200,000
Senior GRC Analyst
Senior GRC Analyst

3M HEALTHCARE • Hyderabad

On-site
INR 1,500,000 - 2,200,000
GRC Manager/ GRC Lead
GRC Manager/ GRC Lead

Riskpro India Ventures • Mumbai

On-site
INR 1,000,000 - 1,500,000
Security Consultant - GRC
Security Consultant - GRC

IBM • Mumbai

On-site
INR 2,400,000 - 3,600,000
Lead GRC
Lead GRC

Ashley Global Capability Center • Chennai District

On-site
INR 1,200,000 - 1,800,000
Technical Manager
Technical Manager

Incedo Inc. • Gurugram District

On-site
INR 2,500,000 - 5,000,000
Grc Analyst
Grc Analyst

Infoshare soft • Pune District

On-site
INR 1,200,000 - 1,800,000
Infosec GRC Associate II
Infosec GRC Associate II

Zeta • Bengaluru

On-site
INR 800,000 - 1,200,000