Source description
About the role
GRC Analyst Department: CISO Office Pillar 2: Cyber Governance, Risk & Compliance | Reports To: Head of Cyber GRC | Level: Mid (2-4 Years) | Type: Full Time | Location: Bengaluru (Bangalore), India About Credit Saison India Credit Saison India is a premier technology-led NBFC and one of India's fastest-growing financial institutions. As the Indian arm of Tokyo Stock Exchange-listed Credit Saison Co., Ltd., we blend 70+ years of Japanese financial expertise with cutting-edge proprietary technology to deliver wholesale, MSME, and consumer lending solutions. With an AAA credit rating and landmark international backing, we're driving financial inclusion through digital-first credit delivery. The Role Join the CISO Office's Cyber GRC Pillar ("The Compass") as a GRC Analyst and own regulatory compliance across a high-velocity fintech operation. You'll be the operational backbone of our compliance mandatetranslating RBI Master Directions and DPDP Act requirements into actionable controls, coordinating security audits, managing fintech partner and vendor risks, and keeping our regulatory and cyber risk posture visible to leadership and the board. This is hands-on work: policy development, audit evidence collection, risk quantization and board reporting, third-party assessments, and partnering with engineering and operations teams to close security gaps and maintain airtight compliance. What You'll Do - Coordinate internal and external audits with third-party firms; own the audit lifecycle from planning through evidence collection and remediation tracking - Ensure regulatory compliance across IT Act 2000, DPDP Act, CERT-In, and RBI Master Directions; map requirements in GRC platforms (Vanta, Drata, Sprinto, OneTrust, ServiceNow) and train teams on obligations - Manage fintech partner and vendor risks (cloud providers, co-lenders, DSAs, data processors); assess security posture, negotiate contracts, monitor compliance, and escalate findings - Develop and maintain security policies (incident response, data privacy, access control, vendor management) aligned to regulatory mandates and audit findings - Quantify cyber risk for the board translate technical findings into business impact; deliver quarterly compliance dashboards and risk summaries to executive leadership - Own audit evidence repository ensure 100% completeness and accessibility for external auditors and regulatory inspections - Champion compliance culture lead cross-functional working groups, mentor team members, and build organizational understanding of regulatory requirements. You'll Need - 2-4 years hands-on in GRC, compliance, audit, or risk management - Deep knowledge of Indian cybersecurity law and how it shapes your daily work - Analytical mindset comfortable building frameworks, tracking metrics, and spotting compliance gaps - Technical fluency you work comfortably with data, dashboarding tools, and cloud platforms (AWS, Azure, GCP) - Clear communicator can translate regulatory jargon for engineers and executives alike - Ownership mentality you drive things to completion, not just flag issues Nice-to-Haves: - CISA, ISO 27001 Lead Auditor, or DISA certification - Fintech, NBFC, or banking sector experience - Incident response planning background What You'll Get - Direct impact: Shape our security and compliance posture; enable safe financial services for millions - Career growth: Work closely with CISO and executive leadership on strategic initiatives - Learning culture: Certifications, training, and mentorship from experienced security leaders - Fast-paced environment: High-velocity fintech; you'll see your work deployed quickly - Inclusive team: Diverse, collaborative, values innovation and continuous improvement
More at Credit Saison India