
Senior Information Security Engineer- GRC
24 hours ago
About IDfy
IDfy is an Integrated Identity Platform offering products and solutions for KYC, KYB, Background Verifications, Risk Assessment, and Digital Onboarding. We establish trust while delivering a frictionless experience for you, your employees, customers and partners.
Only IDfy combines enterprise-grade technology with business understanding and has the widest breadth of offerings in the industry. With more than 12+ years of experience and 2 million verifications per day, we are pioneers in this industry.
Our clients include HDFC Bank, Induslnd Bank, Zomato, Amazon, PhonePe, Paytm, HUL and many others.
We have successfully raised $27M from Elev8 Venture Partners, KB Investments & Tenacity Ventures
We work fully onsite on all 5 days of the week from our office in Andheri East, Mumbai
About the Role
As an Information Security Engineer at IDfy, you'll be the go-to guardian of our security and compliance framework. You'll own everything from ISO 27001 and SOC 2 audits (Internal and External) to Customer third-party risk assessments, customer security requests, and internal ISMS management.
You'll work across product, engineering, and legal teams to ensure we're not just compliant—but secure by design. If you're someone who knows how to manage an audit without breaking a sweat and gets a kick out of spotting gaps in security systems, this one's for you.
We Are the Perfect Match If You…
- Speak fluent ISO 27001, SOC 2, and ISMS for 3-6 years
- Have experience owning and running end-to-end compliance audits
- Experienced in handling ISMS management end to end
- Responding to customer third party risk assessments questionnaires and facing customer Audits
- Can guide control owners like a boss (and not just with fancy dashboards)
- Enjoy writing and updating InfoSec policies (yes, we know that's rare)
- Know how to communicate security stuff to non-security folks
- Have worked in a SaaS environment or want to secureone now
- Love working across multiple teams and hate working in silos
- Have strong knowledge of cloud platforms (GCP preferred, others okay too)
- Hold one or more certifications (mandatory) : ISO 27001 Lead Auditor, CISA, CISSP
Here's What Your Day Will Look Like…
- Maintain and manage IDfy's ISMS as per ISO 27001 and SOC 2 standards
- Coordinate and lead internal and external audits
- Oversee annual policy renewals, updates, documentation and ISMS activities
- Face third-party/vendor risk assessments from our customer
- Respond to security questionnaires from customers and partners
- Track and close compliance deliverables with internal stakeholders
- Identify gaps in technical or procedural controls and work with teams to fix them
- Train internal teams on compliance expectations and workflows
- Monitor and improve security metrics across the org
- Stay up to date with industry trends and frameworks
What's it like working at IDfy?
We build products that detect and prevent fraud. With billions of transactions flowing through our pipes, InfoSec is not just important, it's critical. You'll have the space to take ownership, challenge the status quo, and build security systems that scale with our growth. And yes, we love memes, chai, and debating compliance checklists over lunch.
Thanks to our problem-centric approach, one in which we find the right technology to solve a problem rather than the other way around, you will always be working on the latest technologies.
We work hard and party hard. There are weekly sessions on emerging technologies. Work weeks are usually capped off with board games, poker, karaoke, and other fun activities.
-
Information Security GRC Engineer
2 days ago
Mumbai, Maharashtra, India ECL Finance Full time ₹ 9,00,000 - ₹ 12,00,000 per yearPosition: Information Security GRC EngineerJob Description: We are seeking a dedicated and talented Security GRC Engineer to join our Information Security Team. He / She will be responsible for ensuring that our organization adheres to relevant regulations, standards and internal policies related to information security and data privacy. The ideal candidate...
-
Information Security GRC
2 days ago
Mumbai, Maharashtra, India Flywings Hr Services Full time US$ 80,000 - US$ 1,00,000 per yearLooking for a smart GRC specialist in Information security, with strong experience in ISO27001 Lead Auditor, RBI Compliance. Immediate Joiner - Ready to join in 10 days. Budget - 8LPA - 10 LPA. Location:- Kurla West, Mumbai.
-
Cyber Security GRC
2 days ago
Mumbai, Maharashtra, India Forvis Mazars Full time ₹ 1,04,000 - ₹ 1,30,878 per yearJob Title: Manager/Senior Mnager Information Security (GRC)Location: Mumbai Experience: 8+ yearsRole OverviewWe are looking for an Information Security Manager with strong expertise in Governance, Risk, and Compliance (GRC). The role involves implementing security frameworks, managing audits, leading compliance initiatives, and driving cross-functional...
-
Senior GRC specialist
2 days ago
Mumbai, Maharashtra, India Headsnminds Consultants Full time US$ 1,50,000 - US$ 2,00,000 per yearRole & responsibilitiesis searching for a senior Information Security professional to be part of global security Governance, Risk, and Compliance (GRC) function within the global CISO Team. The candidate will support to the global Security Head of GRC to enhance the unified risk and control framework (CRI) that is mapped across NIST 2.0 and multiple global...
-
Senior GRC Consultant
4 days ago
Mumbai, Maharashtra, India VaporVM Full timeWe are seeking a highly skilled Senior Security Engineer (GRC & Advisory) to join our Cybersecurity & Advisory Services team. The ideal candidate will play a pivotal role in driving security governance, risk management, and compliance initiatives, while providing strategic advisory services to clients. This role requires a mix of deep technical...
-
Information Security Manager
7 days ago
Mumbai, Maharashtra, India Burns Mcdonnell Full timeJob DescriptionWe are seeking an experienced Information Security Manager to lead our India Information Security department. This role is a vital part of our Global Information Security Directorate. You will be responsible for managing day-to-day operations, ensuring the enforcement of security policies, and mitigating risks to our digital assets. The ideal...
-
Information Security Engineer
4 weeks ago
Mumbai, Maharashtra, India Wave HR and Advisory Pvt Ltd Full timeThe person will be responsible to maintain Governance, Risk and Compliance (GRC) - Information and Cyber Security and BCP for the AMC.Key Responsibilities in the role :- Ensure compliance to SEBI and regulatory circulars and requirements released time to time.- Ensure ISO certifications are maintained for BCP and information and Cyber security.- To review...
-
GRC Analyst
20 hours ago
Mumbai, Maharashtra, India PINKVILLA Full timePinkvilla is seeking a dynamic Information Security professional, who will play a key role in driving compliance programs, managing audits, supporting data protection initiatives, and ensuring third-party security risks are effectively identified and mitigated.Key ResponsibilitiesGovernance, Risk & Compliance (GRC)- Develop, implement, and maintain...
-
GRC Analyst
2 days ago
Mumbai, Maharashtra, India PINKVILLA Full time ₹ 1,04,000 - ₹ 1,30,878 per yearPinkvilla is seeking a dynamic Information Security professional, who will play a key role in driving compliance programs, managing audits, supporting data protection initiatives, and ensuring third-party security risks are effectively identified and mitigated.Key ResponsibilitiesGovernance, Risk & Compliance (GRC)Develop, implement, and maintain information...
-
Network Security Engineer
5 days ago
Mumbai, Maharashtra, India ServQual Full timeCompany Description Serv Qual Security specializes in Cyber Security Discovery Workshops, Enterprise Security Transformations, and GRC automation through our AI-powered platform, SUSAN.SUSAN bridges the gap between cybersecurity leadership and engineering teams by enabling continuous GRC, automated risk assessments, and real-time control validation, with 90%...