Senior Security GRC Analyst
falcon· Software Development
About this role
Senior Security GRC Analyst
Experience: 4–5 years
Industry: Fintech (Payments, Cards, Lending, UPI)
About Us
We are a fast-growing AI-first fintech platform enabling banks, NBFCs, and financial institutions to launch and scale next-generation credit products, including credit cards, credit lines, lending, and payment solutions. Our platforms process high-volume financial transactions and power business-critical customer journeys where reliability, performance, and security are non-negotiable.
We are looking for a Lead React Native Developer who thrives in high-ownership environments, enjoys solving complex engineering challenges, and is passionate about building products that directly impact millions of users and financial institutions.
Role Overview
We are looking for a hands-on Security GRC professional to own our information security governance, risk, and compliance programs. You will work closely with Engineering, Product, Risk, and Internal Audit teams to ensure regulatory and security compliance across our card, wallet, and UPI platforms.
Key Responsibilities
- ISMS & Standards: Maintain, monitor, and improve the ISO 27001 Information Security Management System, including risk registers, SOA, policies, and control evidence.
- PCI DSS Compliance: Support PCI DSS compliance for the credit card platform, including HSM-based protection of PIN data (PCI PTS HSM), scope reduction, and audit readiness.
- SOC 2 Type 2: Support the implementation and audit of SOC 2 Type 2 controls.
- CERT-IN / SAR DLA: Manage and coordinate SAR (System Audit Report) and DLA (Data Localisation Audit) compliance with CERT-IN empaneled auditors.
- Regulatory Tracking: Monitor RBI, NPCI, and other applicable regulations; translate requirements into internal controls and roadmaps.
- Risk Management: Conduct risk assessments, control gap analysis, and treatment tracking across the organization.
- Audits & Assessments: Coordinate internal and external audits, including ISO 27001, PCI DSS, SOC 2, and regulatory audits; track remediation and closure.
- Policy & Process: Develop, review, and maintain security policies, standards, procedures, and guidelines.
- Vendor Risk: Perform security assessments of third-party vendors and partners.
- Security Awareness: Drive security awareness, training, and phishing simulation programs.
- Reporting: Prepare dashboards and reports for leadership, auditors, and regulators.
Required Qualifications
- 4–5 years of experience in Information Security Governance, Risk, and Compliance within BFSI, fintech, or payments.
- Hands-on experience with ISO 27001, SOC 2, and PCI DSS compliance.
- Knowledge of RBI and NPCI guidelines relevant to payments, wallets, and card platforms.
- Experience with risk assessments, control frameworks, and audit management.
- Strong understanding of HSM concepts and key management for PCI DSS.
- Excellent communication, documentation, and stakeholder management skills.
- Relevant certifications such as CISA, CISM,CRISC, CGRC,ISO 27001 LA/LI are preferred.
Good-to-Have
- Knowledge of the Digital Personal Data Protection (DPDP) Act 2023.
- Exposure to AI security and AI governance frameworks.
- PCI QSA / ISA or similar audit credentials.
- Experience working in cloud environments (AWS, Azure, GCP).
What You Will Work On
- Securing and governing a regulated payments ecosystem spanning credit cards, prepaid cards, wallets, and UPI credit lines.
- Driving compliance maturity across ISO 27001, SOC 2 Type 2, PCI DSS, and CERT-IN requirements.
- Building a scalable GRC function that aligns with RBI and NPCI expectations.
Frequently Asked Questions
Is the salary disclosed for the Senior Security GRC Analyst position at falcon?
The salary for this Senior Security GRC Analyst role at falcon is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Senior Security GRC Analyst position at falcon located?
This Senior Security GRC Analyst role at falcon is based in Gurugram, HR, India. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Senior Security GRC Analyst role at falcon full-time or part-time?
This is listed as a FULL TIME position. It is posted as a Senior Security GRC Analyst role in the Software Development department at falcon.
Which team or department does the Senior Security GRC Analyst at falcon belong to?
This Senior Security GRC Analyst position is part of the Software Development department at falcon. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Senior Security GRC Analyst position at falcon?
Click the "Apply Now" button on this page. You will be redirected to falcon's official application portal hosted on keka where you can submit your application directly.
When was the Senior Security GRC Analyst job at falcon posted?
This Senior Security GRC Analyst position at falcon was posted on Jul 13, 2026. Apply as soon as possible — early applications are often reviewed first.
Senior Security GRC Analyst
falcon
You'll be redirected to falcon's official application page on keka.