Source description
About the role
Description - Role Overview We are looking for a dynamic and driven Information Security professional (GRC-focused) to support and strengthen the organizations Governance, Risk, and Compliance (GRC) function. This role will work closely with the InfoSec Lead/CISO to execute the organization’s security strategy by driving risk management, audit readiness, regulatory compliance, and third-party security assessments. The ideal candidate will bring strong expertise in cybersecurity governance and compliance, preferably within the financial services domain, along with familiarity with RBI guidelines and certification processes. Responsibilities Develop, implement and maintain information security policies, standards, and procedures aligned with regulatory and industry standards. Execute security risk management activities, including conducting regular risk assessments, maintaining the risk register, performing control mapping, and tracking remediation efforts. Collaborate with Compliance and Risk teams to conduct third-party/vendor risk assessments (TPRA), ensuring vendor security controls align with company requirements and relevant regulatory standards as part of the onboarding process. Assist in internal and external audits, including regulatory audits (RBI, ISO 27001, etc.). Manage and drive audit evidence collection, documentation, and audit tracking. Ensure adherence to information security requirements under ISO 27001, RBI guidelines, DPDP Act, and other applicable regulations. Work with IT, Legal, and Compliance teams to integrate security controls into business and technology processes. Track and follow up on audit findings, risk remediation, and compliance gaps Support implementation and monitoring of security controls across systems, applications, and infrastructure Contribute to security awareness and training initiatives. Act as a point of contact for security-related queries from internal stakeholders and auditors. Provide inputs and reports on security risk posture and compliance status to the Management & InfoSec leadership. Basic Qualifications Bachelor's degree in computer science, Information Security, or a related field 2+ years of experience in Information Security with a focus on GRC Strong understanding of ISO 27001, RBI guidelines, DPDP Act, and NIST (or equivalent frameworks) Hands-on experience in risk assessments, risk tracking, and audit coordination Experience in third-party/vendor risk management (TPRA) Good understanding of information security controls and compliance requirements Strong communication and stakeholder management skills Preferred Qualifications Master's degree in information security or a related field Experience in financial services or fintech domain Experience supporting regulatory audits (RBI, ISO 27001 certification, etc.) Working knowledge of application security practices, including SAST, SCA, API security testing, and remediation of common vulnerabilities Professional certifications such as CISSP, CISM, CRISC, ISO 27001 LA/LI Nice to Have (Application Security): Exposure to SAST and SCA tools Experience with conducting application and API security testing Familiarity with DevSecOps practices and CI/CD security
More at Benchire