
Information Security Compliance & Audits
Job Profile: Analyst II - Compliance & Audits
Location: Bangalore | Karnataka
Years of Experience: 5 to 8 years
About the Role & Team:
Swiggy is looking for an experienced Information Security Compliance & Audit professional to own and mature the organization’s security & audits program. This is a Level 5 (Analyst II) role for someone who is self-motivated and can operate independently across ISO 27001/22301/42001, PCI DSS, SOC 2, DPDP Act 2023, and CERT-In requirements, translate regulatory and contractual obligations into practical controls, and represent InfoSec confidently in front of internal leadership, external auditors, and third-party vendors. The role blends hands-on execution (running audits, managing risk registers, tracking remediation) with senior stakeholder engagement (vendor escalations, audit findings negotiation). This is increasingly a technical role as much as a governance one: the person must be equally comfortable auditing modern security architecture (cloud, EDR, CASB, application security) and using AI tools to accelerate audit and compliance workflows, while retaining the human judgment and accountability that final risk decisions require.
What will you get to do here?
1. Strategic Stakeholder Management
Executive Advisory: Act as the primary GRC point of contact for senior leadership; translate complex audit/risk findings into clear, decision-ready executive summaries.
Enablement & Escalation: Build cross-functional trust to drive compliant growth, manage pushback diplomatically, and negotiate realistic remediation timelines without sacrificing risk posture.
Control Ownership: Align cross-functional teams (Engineering, HR, Legal) to ensure every security policy and control has a dedicated, accountable owner.
2. Third-Party & Vendor Risk Management (TPRM)
Program Execution: Own end-to-end TPRM, including security questionnaires, risk assessments, and continuous monitoring for critical vendors.
Contractual Safeguards: Partner with Legal and Procurement to embed robust data protection clauses, breach notification SLAs, and right-to-audit terms in MSAs/SOWs.
Vendor Lifecycle: Maintain the central Vendor Risk Register, track re-assessment cycles, and drive offboarding or remediation for high-risk or non-compliant vendors.
3. End-to-End Audit Management
Framework Coverage: Own the audit calendar and readiness across ISO 27001, ISO 22301, ISO 42001 (AI Governance), PCI DSS, DPDP Act 2023, and CERT-In Directions 2022.
Audit Logistics & Evidence: Maintain current evidence repositories and lead field logistics, interview scheduling, and sample pulls to prevent audit fatigue.
Finding Resolution: Track audit findings to closure; formally flag overdue risks to leadership and document signoffs when extensions are required.
4. Auditor & Panel Management
Liaison & Negotiation: Serve as the main bridge for external certification bodies; negotiate audit scope, sampling, and timelines to remain proportionate and evidence based.
Internal Panel Oversight: Manage internal and outsourced audit panels, ensuring quality workpapers, professional dispute resolution, and auditor independence.
5. Governance, Risk & Framework Ownership
Enterprise Risk Management: Continuously mature an ISO 31000-aligned enterprise risk register and maintain the central policy framework.
Control Automation: Drive automation for evidence collection to minimize manual effort and enable real-time visibility into the organization’s compliance posture.
What qualities are we looking for?
5 - 8 years of experience in Compliance, IT audit, risk management.
Strong technical understanding of modern security technologies and practices such as cloud security (CSPM), EDR, CASB, DLP, Zero Trust/SASE, and application security (secure SDLC, SAST/DAST/SCA, API security) with the ability to independently audit these controls rather than relying solely on vendor, IT, or engineering self-attestation.
Hands-on experience managing ISO 27001, ISO 27701, ISO 42001, PCI DSS, or equivalent certification programs end-to-end, including surviving at least 2–3 external audit/certification cycles.
Strong working knowledge of Indian regulatory requirements: DPDP Act 2023, CERT-In Directions 2022, IT Act 2000, and sector-specific regulations (RBI PA/PG, NPCI) where relevant.
Demonstrated experience managing third-party/vendor risk programs, including contractual security requirements and vendor assessments.
Excellent stakeholder management and communication skills, comfortable presenting to senior leadership, negotiating with auditors, and influencing without direct authority.
Relevant certifications preferred: CISA, CRISC, ISO 27001 Lead Auditor/Implementer, CISSP, S+ or equivalent.
Practical familiarity with AI tools and techniques as applied to Compliance workflows (automated evidence collection, control testing, audit analytics, risk-pattern detection), combined with the judgment to know where AI assistance ends and human accountability begins, particularly relevant given Swiggy's own ISO/IEC 42001 AI governance program.
What Success Looks Like
Measurable reduction in manual evidence-gathering effort through appropriate use of AI-assisted tooling, freeing up time for higher-judgment work like stakeholder negotiation and risk decisioning
Zero major nonconformities in external certification audits, with minor findings closed within agreed timelines.
A current, accurate enterprise risk register reviewed by leadership on a regular cadence.
Vendor risk assessments completed on schedule with no critical vendors operating on expired assessments.
Strong, trust-based relationships with auditors and stakeholders that keep audit cycles efficient rather than adversarial.
Visit our tech blogs to learn more about some of the challenging problem statements Swiggy works on:
- https://bytes.swiggy.com/engineering-challenges-at-swiggy-430dea6c86a3
- https://bytes.swiggy.com/the-swiggy-delivery-challenge-part-one-6a2abb4f82f6
- https://bytes.swiggy.com/what-serviceability-means-at-swiggy-c94c1aad352a
- https://bytes.swiggy.com/architecture-and-design-principles-behind-the-swiggys-delivery-partners-app-4db1d87a048a
- https://bytes.swiggy.com/swiggy-distance-service-9868dcf613f4
- https://bytes.swiggy.com/the-tech-that-brings-you-your-food-1a7926229886
We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, disability status, or any other characteristic protected by law.
We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, disability status, or any other characteristic protected by the law.
Similar roles
Senior Specialist, Data Stewardship
MSD·Hyderabad, India
This job is with MSD, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ business community. Please do not contact the recruiter directly. Job Description Senior Specialist, Data Stewardship The Opportunity Join a global biopharma company with a 130-year legacy and mission to achieve new milestones in healthcare. Be part of technology driven,…
- Full-time
Director – Head of Transition & Service Delivery
Domnic Lewis·India, Gambia
Senior Director – Head of Transition & Service Delivery with a leading multinational organization. Location: India (GCC - Outsourced Model) Level: Executive Leadership Vertical: Enterprise Services / Global Finance & Business Operations This role will lead the Transition, Service Delivery, GBS Governance, Digital Enablement and BPO Governance agenda across a global hybrid delivery model comprising captive GCCs and Tier-1 BPO…
- Full-time
Operations Co-ordinator_Supply Chain [T500-28385]
Guidant Global·India, Gambia
About Guidant Global: Guidant Global delivers dynamic, tailored workforce solutions that empower businesses to thrive in ever-evolving markets. Through our MSP, RPO, Direct Sourcing, Services Procurement and Consulting services, we help organisations find, engage, and manage the best permanent and contingent talent across the globe. Part of Impellam Group, we champion A Better Way, a people-first approach that integrates deep…
- Full-time
AI Architect
Dautom·India, Gambia
Client Introduction In this role, you will collaborate closely with one of our esteemed clients—a globally recognized leader in their industry, distinguished by their commitment to excellence, innovation, and delivering exceptional value. As a trusted IT consulting partner, Dautom is supporting their strategic initiatives by connecting them with exceptional talent to drive business growth and transformation. Job Role: AI Architect…
- Full-time
1st Line Service Desk Agent
Valsoft Corporation·Liverpool, United Kingdom
About us… We are passionate about delivering the latest software and tech to our growing customer base across the UK, Australia & the US. With our Insight Driven and Frictionless Commerce cloud-based applications serving an incredibly diverse range of Retailers, we have become one of the UK’s best innovators, winning numerous awards (including the IT Europa SaaS Awards & UK…
- Hybrid
- Full-time
Clinical Programmer
Statistics & Data Corporation (SDC)·Hyderabad, India
Clinical Programmer Statistics & Data Corporation (SDC), a specialized contract research organization (CRO) headquartered in Arizona, delivering top-tier clinical trial services to pharmaceutical, biologic, and medical device/diagnostic companies since 2005. SDC providing a technology enabled service offering to provide clients with both clinical services expertise, as well as the technology they need to be successful in their clinical trials. Job…
- Hybrid
- Full-time
Video Editor- Bengali
Lokal App·Bengaluru, India
ABOUT LOKAL In 2018, we began with a WhatsApp group with a simple hypothesis: people in tier-2/3 towns weren’t really using the internet meaningfully yet. We believed that if we started with local content in their own language, they’d come back every day; once there was a habit and trust, that same space could naturally grow into classifieds and, eventually,…
- Remote
- Contract
Staff Security Engineer
Ripple·London, Canada
<div class="content-intro"><p><span style="font-weight: 400;">At Ripple, we’re building a world where value moves like information does today. It’s big, it’s bold, and we’re already doing it. Through our crypto solutions for financial institutions, businesses, governments and developers, we are improving the global financial system and creating greater economic fairness and opportunity for more people, in more places around the world. And…
- On-site
- Full-time
- Express Entry — PR day one, no employer