
Senior Information Security Engineer- GRC
2 weeks ago
About IDfy
IDfy is an Integrated Identity Platform offering products and solutions for KYC, KYB, Background Verifications, Risk Assessment, and Digital Onboarding. We establish trust while delivering a frictionless experience for you, your employees, customers and partners.
Only IDfy combines enterprise-grade technology with business understanding and has the widest breadth of offerings in the industry. With more than 12+ years of experience and 2 million verifications per day, we are pioneers in this industry.
Our clients include HDFC Bank, Induslnd Bank, Zomato, Amazon, PhonePe, Paytm, HUL and many others.
We have successfully raised $27M from Elev8 Venture Partners, KB Investments & Tenacity Ventures
We work fully onsite on all 5 days of the week from our office in Andheri East, Mumbai
About the Role
As an Information Security Engineer at IDfy, you'll be the go-to guardian of our security and compliance framework. You'll own everything from ISO 27001 and SOC 2 audits (Internal and External) to Customer third-party risk assessments, customer security requests, and internal ISMS management.
You'll work across product, engineering, and legal teams to ensure we're not just compliant—but secure by design. If you're someone who knows how to manage an audit without breaking a sweat and gets a kick out of spotting gaps in security systems, this one's for you.
We Are the Perfect Match If You...
- Speak fluent ISO 27001, SOC 2, and ISMS for 3-6 years
- Have experience owning and running end-to-end compliance audits
- Experienced in handling ISMS management end to end
- Responding to customer third party risk assessments questionnaires and facing customer Audits
- Can guide control owners like a boss (and not just with fancy dashboards)
- Enjoy writing and updating InfoSec policies (yes, we know that's rare)
- Know how to communicate security stuff to non-security folks
- Have worked in a SaaS environment or want to secureone now
- Love working across multiple teams and hate working in silos
- Have strong knowledge of cloud platforms (GCP preferred, others okay too)
- Hold one or more certifications (mandatory) : ISO 27001 Lead Auditor, CISA, CISSP
Here's What Your Day Will Look Like...
- Maintain and manage IDfy's ISMS as per ISO 27001 and SOC 2 standards
- Coordinate and lead internal and external audits
- Oversee annual policy renewals, updates, documentation and ISMS activities
- Face third-party/vendor risk assessments from our customer
- Respond to security questionnaires from customers and partners
- Track and close compliance deliverables with internal stakeholders
- Identify gaps in technical or procedural controls and work with teams to fix them
- Train internal teams on compliance expectations and workflows
- Monitor and improve security metrics across the org
- Stay up to date with industry trends and frameworks
What's it like working at IDfy?
We build products that detect and prevent fraud. With billions of transactions flowing through our pipes, InfoSec is not just important, it's critical. You'll have the space to take ownership, challenge the status quo, and build security systems that scale with our growth. And yes, we love memes, chai, and debating compliance checklists over lunch.
Thanks to our problem-centric approach, one in which we find the right technology to solve a problem rather than the other way around, you will always be working on the latest technologies.
We work hard and party hard. There are weekly sessions on emerging technologies. Work weeks are usually capped off with board games, poker, karaoke, and other fun activities.
-
Senior Information Security Manager
2 weeks ago
Mumbai, Maharashtra, India beBeeInformationSecurityLeader Full time ₹ 2,50,00,000 - ₹ 4,00,00,000Job Title: Senior Information Security LeaderWe are seeking a seasoned information security professional to lead our global CISO team's Governance, Risk, and Compliance (GRC) initiatives.About the Role:As the primary liaison, you will ensure regional regulatory requirements are met, external/internal audits are conducted, and risk registers are effectively...
-
Information Security GRC Manager
2 weeks ago
Navi Mumbai, Maharashtra, India Jio Full time ₹ 5,00,000 - ₹ 8,00,000 per yearJob Description Information Security GRC ManagerWork Location: Navi MumbaiKey Focus Area: Information Security GRCKey Responsibilities: Policy Development and Enforcement: Develop, implement and maintain Information Security policies, procedures, standards, frameworks, and associated plans based on industry best practices such as ISO...
-
Senior GRC Consultant
2 weeks ago
Mumbai, Maharashtra, India VaporVM Full timeJob DescriptionWe are seeking a highly skilled Senior Security Engineer (GRC & Advisory) to join our Cybersecurity & Advisory Services team. The ideal candidate will play a pivotal role in driving security governance, risk management, and compliance initiatives, while providing strategic advisory services to clients. This role requires a mix of deep...
-
Information Security Leadership Position
2 weeks ago
Mumbai, Maharashtra, India beBeeCybersecurity Full time ₹ 20,00,000 - ₹ 25,00,000Senior Cybersecurity Specialist PositionWe're seeking a seasoned professional to lead our security initiatives. The ideal candidate will have extensive experience in implementing and auditing Information Security Management Systems (ISMS) based on ISO 27001 standards.The successful Senior Cybersecurity Specialist will be responsible for leading the...
-
Senior GRC Consultant
3 weeks ago
Mumbai, Maharashtra, India VaporVM Full timeWe are seeking a highly skilled Senior Security Engineer (GRC & Advisory) to join our Cybersecurity & Advisory Services team. The ideal candidate will play a pivotal role in driving security governance, risk management, and compliance initiatives, while providing strategic advisory services to clients. This role requires a mix of deep technical...
-
Mumbai, Maharashtra, India Xanika Infotech Full time ₹ 15,00,000 - ₹ 25,00,000 per yearJob Description Information Security GRC Specialist (4year experience) Sector:NBFCWork location: MumbaiExperience:4+YearsJob Description:4+ years of experience in Information Security GRC within the NBFC sector.Strong knowledge of RBI guidelines, ISO 27001, NIST, DPDP frameworks, and submission requirements.Expertise in regulatory compliance, audit...
-
Information Security Manager
3 weeks ago
Mumbai, Maharashtra, India Burns Mcdonnell Full timeJob DescriptionWe are seeking an experienced Information Security Manager to lead our India Information Security department. This role is a vital part of our Global Information Security Directorate. You will be responsible for managing day-to-day operations, ensuring the enforcement of security policies, and mitigating risks to our digital assets. The ideal...
-
GRC Analyst
3 weeks ago
Mumbai, Maharashtra, India PINKVILLA Full timePinkvilla is seeking a dynamic Information Security professional, who will play a key role in driving compliance programs, managing audits, supporting data protection initiatives, and ensuring third-party security risks are effectively identified and mitigated.Key ResponsibilitiesGovernance, Risk & Compliance (GRC)- Develop, implement, and maintain...
-
GRC Analyst
2 weeks ago
Mumbai, Maharashtra, India PINKVILLA Full timePinkvilla is seeking a dynamic Information Security professional, who will play a key role in driving compliance programs, managing audits, supporting data protection initiatives, and ensuring third-party security risks are effectively identified and mitigated. Key Responsibilities Governance, Risk & Compliance (GRC) Develop, implement, and maintain...
-
Manager - IT GRC (BFSI, FinTech)
2 days ago
Mumbai, Maharashtra, India N53 Tech Full time ₹ 12,00,000 - ₹ 36,00,000 per yearOne of our leading Financial Services clients is looking to strengthen its Governance, Risk, and Compliance (GRC) practice and is looking for talented professionals at two levels:Manager – GRC (L2): 7–9 years of experience, leading GRC initiatives and audits, working with senior stakeholders, and driving regulatory compliance.In this role, you will work...