GRC Officer
Mumbai, India · On-site · Full-time
- Posted 2w ago
- From Fynd’s careers page
- Location
- Mumbai, India
- Work mode
- On-site
- Type
- Full-time
- Level
- Senior
- Experience
- 5+ years
- Department
- Legal and Compliance
Opens the listing on hiring.fynd.com
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
Role Overview
The GRC Officer will play a critical role in strengthening the organization’s governance, risk, and compliance posture across the business. This role ensures alignment with global security and data protection requirements, enabling the company to operate securely, meet regulatory obligations, and maintain trust with customers and stakeholders.
Responsibilities
- Develop, implement, and maintain governance, risk, and compliance (GRC) frameworks, policies, and procedures.
- Conduct regular risk assessments to identify control gaps, evaluate threats, and recommend mitigation actions.
- Monitor and ensure compliance with relevant standards and regulations, including ISO 27001, PCI-DSS, NIST, and data protection requirements.
- Support IT General Controls (ITGC) design, documentation, testing, and remediation activities.
- Coordinate internal and external audits, including evidence collection, remediation tracking, and issue resolution.
- Partner with cross-functional teams to embed security, privacy, and compliance controls into business processes and technology initiatives.
- Track regulatory changes and industry best practices to update compliance programs and risk management activities.
- Prepare and present GRC reports, metrics, and status updates to leadership and key stakeholders.
Qualifications
Required
- Bachelor's degree in Information Security, Computer Science, or a related field
- 5+ years of experience in GRC, compliance, information security, or risk management
- Hands-on experience with ISO 27001, PCI-DSS, NIST, or similar security standards
- Experience conducting risk assessments and supporting compliance audits
- Working knowledge of IT General Controls and data protection requirements
Preferred
- Professional certification such as CISA, CISSP, CRISC, or ISO 27001 Lead Implementer/Lead Auditor
- Experience in a global technology or high-growth digital organization
- Exposure to privacy regulations and cross-border data protection requirements
- Experience building or maturing enterprise-wide GRC programs
- Familiarity with cloud security and third-party risk management
Skills they ask for
Pick one to see other roles that ask for it.
About Fynd
AI commerce platform for businessesFynd provides an AI-powered commerce platform for websites, marketplaces, retail operations, and commerce automation.
See all 65 roles at FyndMore roles at Fynd
See all 65- Software Development EngineerMumbai · On-siteSoftware Development · On-siteMumbai, India1d
- Revenue ArchitectMumbai · On-siteBusiness Operations · On-siteMumbai, India1d
- Computer Vision and Machine Learning ResearcherMumbai · On-siteResearch and Development (R&D) · On-siteMumbai, India2d
- Fabric Sourcing MerchandiserMumbai · On-siteSupply Chain / Logistics / Procurement · On-siteMumbai, India2d
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.