368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$20k – $50k per year (Estimated)
Location
In office (Bengaluru)
Seniority
Senior · 2+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
We are made up of unbelievably awesome teams that are synonymous with talent,ambition, smartness, passion, versatility and focus. Hyper-productivity and creativity is what we value most as we build a start-up environment where curiosity is expecte...

Swiggy is India’s leading on-demand delivery platform with a tech-first approach to logistics and a solution-first approach to consumer demands. With a presence in 700+ cities across India, partnerships with hundreds of thousands of restaurants, an employee base of over 5000, and a 2 lakh+ strong independent fleet of Delivery Executives, we deliver unparalleled convenience driven by continuous innovation.

Job Profile: Analyst II - Compliance & Audits

Location: Bangalore | Karnataka

Years of Experience: 2 to 4 years

About the Role & Team:

Swiggy is looking for an experienced Information Security Compliance & Audit professional to own and mature the organization’s security & audits program. This is a Level 5 (Analyst II) role for someone who is self-motivated and can operate independently across ISO 27001/22301/42001, PCI DSS, SOC 2, DPDP Act 2023, and CERT-In requirements, translate regulatory and contractual obligations into practical controls, and represent InfoSec confidently in front of internal leadership, external auditors, and third-party vendors. The role blends hands-on execution (running audits, managing risk registers, tracking remediation) with senior stakeholder engagement (vendor escalations, audit findings negotiation). This is increasingly a technical role as much as a governance one: the person must be equally comfortable auditing modern security architecture (cloud, EDR, CASB, application security) and using AI tools to accelerate audit and compliance workflows, while retaining the human judgment and accountability that final risk decisions require.

What will you get to do here?

1. Strategic Stakeholder Management

  • Executive Advisory: Act as the primary GRC point of contact for senior leadership; translate complex audit/risk findings into clear, decision-ready executive summaries.

  • Enablement & Escalation: Build cross-functional trust to drive compliant growth, manage pushback diplomatically, and negotiate realistic remediation timelines without sacrificing risk posture.

  • Control Ownership: Align cross-functional teams (Engineering, HR, Legal) to ensure every security policy and control has a dedicated, accountable owner.

2. Third-Party & Vendor Risk Management (TPRM)

  • Program Execution: Own end-to-end TPRM, including security questionnaires, risk assessments, and continuous monitoring for critical vendors.

  • Contractual Safeguards: Partner with Legal and Procurement to embed robust data protection clauses, breach notification SLAs, and right-to-audit terms in MSAs/SOWs.

  • Vendor Lifecycle: Maintain the central Vendor Risk Register, track re-assessment cycles, and drive offboarding or remediation for high-risk or non-compliant vendors.

3. End-to-End Audit Management

  • Framework Coverage: Own the audit calendar and readiness across ISO 27001, ISO 22301, ISO 42001 (AI Governance), PCI DSS, DPDP Act 2023, and CERT-In Directions 2022.

  • Audit Logistics & Evidence: Maintain current evidence repositories and lead field logistics, interview scheduling, and sample pulls to prevent audit fatigue.

  • Finding Resolution: Track audit findings to closure; formally flag overdue risks to leadership and document signoffs when extensions are required.

4. Auditor & Panel Management

  • Liaison & Negotiation: Serve as the main bridge for external certification bodies; negotiate audit scope, sampling, and timelines to remain proportionate and evidence based.

  • Internal Panel Oversight: Manage internal and outsourced audit panels, ensuring quality workpapers, professional dispute resolution, and auditor independence.

5. Governance, Risk & Framework Ownership

  • Enterprise Risk Management: Continuously mature an ISO 31000-aligned enterprise risk register and maintain the central policy framework.

  • Control Automation: Drive automation for evidence collection to minimize manual effort and enable real-time visibility into the organization’s compliance posture.

What qualities are we looking for?

  • 2 - 4 years of experience in Compliance, IT audit, risk management.

  • Strong technical understanding of modern security technologies and practices such as cloud security (CSPM), EDR, CASB, DLP, Zero Trust/SASE, and application security (secure SDLC, SAST/DAST/SCA, API security) with the ability to independently audit these controls rather than relying solely on vendor, IT, or engineering self-attestation.

  • Hands-on experience managing ISO 27001, ISO 27701, ISO 42001, PCI DSS, or equivalent certification programs end-to-end, including surviving at least 2-3 external audit/certification cycles.

  • Strong working knowledge of Indian regulatory requirements: DPDP Act 2023, CERT-In Directions 2022, IT Act 2000, and sector-specific regulations (RBI PA/PG, NPCI) where relevant.

  • Demonstrated experience managing third-party/vendor risk programs, including contractual security requirements and vendor assessments.

  • Excellent stakeholder management and communication skills, comfortable presenting to senior leadership, negotiating with auditors, and influencing without direct authority.

  • Relevant certifications preferred: CISA, CRISC, ISO 27001 Lead Auditor/Implementer, CISSP, S+ or equivalent.

  • Practical familiarity with AI tools and techniques as applied to Compliance workflows (automated evidence collection, control testing, audit analytics, risk-pattern detection), combined with the judgment to know where AI assistance ends and human accountability begins, particularly relevant given Swiggy's own ISO/IEC 42001 AI governance program.

What Success Looks Like

  • Measurable reduction in manual evidence-gathering effort through appropriate use of AI-assisted tooling, freeing up time for higher-judgment work like stakeholder negotiation and risk decisioning

  • Zero major nonconformities in external certification audits, with minor findings closed within agreed timelines.

  • A current, accurate enterprise risk register reviewed by leadership on a regular cadence.

  • Vendor risk assessments completed on schedule with no critical vendors operating on expired assessments.

  • Strong, trust-based relationships with auditors and stakeholders that keep audit cycles efficient rather than adversarial.

Visit our tech blogs to learn more about some of the challenging problem statements Swiggy works on:

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, disability status, or any other characteristic protected by law.

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, disability status, or any other characteristic protected by the law.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Bengaluru
$55k – $135k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • Frankfurt am Main
AI/ML
EU AI Act
ISO 42001
NIST AI RMF
Cybersecurity
ISO 27001
Apply
$285k per year • Equity • Remote • Hanover
AI/ML
AI Agents
Cybersecurity
ISO 27001
SOC 2
Apply
Lead IAM Engineer 3 hours ago
$117k – $254k per year (Estimated) • In office • Full-Time • 10+ years exp • Jersey City
DevOps
AWS
Azure
Docker
GCP
IAM
Kubernetes
Cybersecurity
GDPR
HIPAA
Okta
Ping Identity
SOC 2
Zero Trust
Apply
Security GRC Analyst 3 hours ago
$119k – $268k per year (Estimated) • Remote/Hybrid • 4+ years exp • Bachelor's Degree • San Francisco
AI/ML
Ignite
PyTorch
Cybersecurity
ISO 27001
NIST CSF
SOC 2
Apply
$191k – $297k per year • In office • Full-Time • 12+ years exp • Bachelor's Degree • Seattle
AI/ML
AI Agents
DevOps
AWS
Azure
CI/CD
GCP
IAM
Platform Engineering
Cybersecurity
Least Privilege
Microsoft Entra ID
PCI DSS
Threat Modeling
Zero Trust
Apply
Product Manager I 6 hours ago
$28k – $64k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Bengaluru
AI/ML
AI Agents
Apply
$22k – $60k per year (Estimated) • Remote/Hybrid • Full-Time • 6+ years exp • Bengaluru
Go
Python
Databases
ElasticSearch
OpenSearch
AI/ML
Claude
Copilot
Cursor
LLM
Prompt Engineering
RAG
AI Agents
DevOps
AWS
Apply
Product Manager II 11 days ago
$26k – $61k per year (Estimated) • Remote/Hybrid • Full-Time • 4+ years exp • Bengaluru
Node JS
JavaScript
Node JS
PM2
Apply
Product Manager II 12 days ago
$26k – $60k per year (Estimated) • In office • Full-Time • 4+ years exp • Bengaluru
Analytics
A/B Testing
Apply
$34k – $71k per year (Estimated) • Remote/Hybrid • Full-Time • 6+ years exp • Bengaluru
Analytics
A/B Testing
Apply
$16k – $34k per year (Estimated) • Remote/Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • Mumbai • Bengaluru
JavaScript
PowerShell
SQL
C#
C#
.NET
Databases
Azure SQL Database
MS SQL
DevOps
Azure
Rest API
Cybersecurity
Microsoft Entra ID
QA
Postman
Swagger
Apply
$41k – $89k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bengaluru
C#
TypeScript
JavaScript
C#
.NET
Databases
Apache Kafka
AI/ML
Copilot
LLM
OpenAI
Frontend
Angular
GraphQL
DevOps
Azure
Azure AKS
Azure DevOps
CI/CD
Docker
GitHub
GitHub Actions
Grafana
Kubernetes
Prometheus
Rest API
Apply
$38k – $83k per year (Estimated) • In office • Full-Time • 12+ years exp • Bachelor's Degree • Bengaluru
Databases
Oracle
DevOps
AWS
Platform Engineering
Apply
Data Architect 3 hours ago
$38k – $91k per year (Estimated) • In office • Full-Time • 3+ years exp • Bengaluru • Pune
Node JS
Python
SQL
JavaScript
Databases
Databricks
MongoDB
Redis
Apply
$28k – $71k per year (Estimated) • In office • Full-Time • 5+ years exp • Bengaluru
DevOps
CI/CD
Platform Engineering
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.