super.money
Website:
super.money
Job details:
GRC Analyst / Engineer
Experience: 1–3 years | Location: Bengaluru/WFO | Type: Full-time
About the Role
We're looking for a GRC Analyst/Engineer to help build and mature our Governance, Risk, and Compliance program. You'll work across security, legal, and engineering teams to assess risks, manage compliance frameworks, and ensure we meet regulatory obligations as we scale.
Responsibilities
- Maintain and improve the GRC program across frameworks such as ISO 27001, SOC 2, PCI-DSS, and RBI guidelines
- Conduct risk assessments, gap analyses, and control evaluations; track remediation to closure
- Manage audit cycles coordinate evidence collection, respond to auditor queries, and drive findings resolution
- Own vendor/third-party risk assessments, including security questionnaires and due diligence reviews
- Maintain policy and control documentation; drive periodic reviews and updates
- Monitor the regulatory landscape for changes relevant to the business and translate requirements into actionable controls
- Support incident response from a compliance perspective; assist with regulatory notifications if required
- Build and run security awareness initiatives and training programs.
- Facilitate Security Champion program.
- Liaise with cross functional teams, group companies to achieve security goals and charters.
Requirements
- 1–3 years of hands-on GRC, information security, or IT audit experience
- Working knowledge of ISO 27001, PCI-DSS, and RBI Digital Lending Guidelines (DLG)
- Familiarity with fintech or BFSI regulatory expectations in the Indian context
- Experience with audit management or GRC tools (e.g., Sprinto, Scrut, Vanta, Drata)
- Familiarity with cloud environments (AWS/GCP/Azure) and SaaS security controls
- Strong documentation skills able to write clear policies, procedures, and risk registers
- Ability to work cross-functionally and communicate risk in business terms
Nice to Have
- Certifications: CISA, CRISC, CompTIA Security+, ISO 27001 Lead Implementer/Auditor
- Hands-on experience with GRC automation platforms such as Sprinto or Scrut Automation
- Exposure to data privacy regulations (DPDPA, GDPR)
- Familiarity with SISA, PCI assessments, or card data environments
- Prior experience with RBI-regulated products or digital lending workflows
What We Offer
- Competitive compensation
- Health Benefits, Reimbursements, Meals, etc
- Opportunity to shape GRC for one of India’s Top 5 UPI companies
- An exciting Fintech startup that has grown exponentially
Click on Apply to know more.