Information Security Compliance & Audits
SWIGGY
Make my CV for this job, freeView job and applyYour CV, rewritten for this role using only your real experience. Sign in with Google and upload your CV. Nothing to install.
Skills named in this job
Read from the description itself, not inferred.
This role on the market
222 open information roles across 106 companies are on ApplySarthi right now, most of them in Hyderabad (15), Bengaluru (14), Pune (7).
- Senior Information Security AnalystCirrus
- Tech Risk and Control Lead, Information SecurityJPMorgan
- Manager - Information TechnologyMaersk
- Junior Consultant Information Security (m/f/d)Dataguard
- Responsable Systèmes d'Information & Outils internes H/FN2JSoft
What information roles keep asking for: SaaS (18%), GCP (12%) — counted across their open postings here.
SWIGGY has 131 open roles listed here.
- Content Executive - Events and Partnershipsmumbai
- Operation Managerbengaluru
- Senior Account managerdelhi ncr
- Assistant Manager - Warehousemumbai
- Manager - Learning & Development (Frontline Capability Development)bengaluru
Counted across 14 company job boards, updated as roles open and close.
Preparing for this interview
Interviews for information roles keep coming back to SaaS, GCP. Practise those questions before you sit with SWIGGY.
Questions you are likely to be asked
- Why do you want to join SWIGGY?
- What is your experience with Stakeholder management? Tell me one thing you learned the hard way.
- How would you cut the cloud bill of a system without hurting it?
- How do you keep secrets and access safe in your infrastructure?
- Walk me through how code gets from a commit to production where you work.
Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.
Practise the Information Security Compliance & Audits at SWIGGY interview free →Job Profile: Analyst II - Compliance & Audits Location: Bangalore | Karnataka Years of Experience: 2 to 4 years About the Role & Team: Swiggy is looking for an experienced Information Security Compliance & Audit professional to own and mature the organization’s security & audits program. This is a Level 5 (Analyst II) role for someone who is self-motivated and can operate independently across ISO 27001/22301/42001, PCI DSS, SOC 2, DPDP Act 2023, and CERT-In requirements, translate regulatory and contractual obligations into practical controls, and represent InfoSec confidently in front of internal leadership, external auditors, and third-party vendors. The role blends hands-on execution (running audits, managing risk registers, tracking remediation) with senior stakeholder engagement (vendor escalations, audit findings negotiation). This is increasingly a technical role as much as a governance one: the person must be equally comfortable auditing modern security architecture (cloud, EDR, CASB, application security) and using AI tools to accelerate audit and compliance workflows, while retaining the human judgment and accountability that final risk decisions require. What will you get to do here? 1. Strategic Stakeholder Management Executive Advisory: Act as the primary GRC point of contact for senior leadership; translate complex audit/risk findings into clear, decision-ready executive summaries. Enablement & Escalation: Build cross-functional trust to drive compliant growth, manage pushback diplomatically, and negotiate realistic remediation timelines without sacrificing risk posture. Control Ownership: Align cross-functional teams (Engineering, HR, Legal) to ensure every security policy and control has a dedicated, accountable owner. 2. Third-Party & Vendor Risk Management (TPRM) Program Execution: Own end-to-end TPRM, including security questionnaires, risk assessments, and continuous monitoring for critical vendors. Contractual Safeguards: Partner with Legal and Procurement to embed robust data protection clauses, breach notification SLAs, and right-to-audit terms in MSAs/SOWs. Vendor Lifecycle: Maintain the central Vendor Risk Register, track re-assessment cycles, and drive offboarding or remediation for high-risk or non-compliant vendors. 3. End-to-End Audit Management Framework Coverage: Own the audit calendar and readiness across ISO 27001, ISO 22301, ISO 42001 (AI Governance), PCI DSS, DPDP Act 2023, and CERT-In Directions 2022. Audit Logistics & Evidence: Maintain current evidence repositories and lead field logistics, interview scheduling, and sample pulls to prevent audit fatigue. Finding Resolution: Track audit findings to closure; formally flag overdue risks to leadership and document signoffs when extensions are required. 4. Auditor & Panel Management Liaison & Negotiation: Serve as the main bridge for external certification bodies; negotiate audit scope, sampling, and timelines to remain proportionate and evidence based. Internal Panel Oversight: Manage internal and outsourced audit panels, ensuring quality workpapers, professional dispute resolution, and auditor independence. 5. Governance, Risk & Framework Ownership Enterprise Risk Management: Continuously mature an ISO 31000-aligned enterprise risk register and maintain the central policy framework. Control Automation: Drive automation for evidence collection to minimize manual effort and enable real-time visibility into the organization’s compliance posture. What qualities are we looking for? 2 - 4 years of experience in Compliance, IT audit, risk management. Strong technical understanding of modern security technologies and practices such as cloud security (CSPM), EDR, CASB, DLP, Zero Trust/SASE, and application security (secure SDLC, SAST/DAST/SCA, API security) with the ability to independently audit these controls rather than relying solely on vendor, IT, or engineering self-attestation. Hands-on experience managing ISO 27001, ISO 27701, ISO 42001, PCI DSS, or equivalent certification programs end-to-end, including surviving at least 2–3 external audit/certification cycles. Strong working knowledge of Indian regulatory requirements: DPDP Act 2023, CERT-In Directions 2022, IT Act 2000, and sector-specific regulations (RBI PA/PG, NPCI) where relevant. Demonstrated experience managing third-party/vendor risk programs, including contractual security requirements and vendor assessments. Excellent stakeholder management and communication skills, comfortable presenting to senior leadership, negotiating with auditors, and influencing without direct authority. Relevant certifications preferred: CISA, CRISC, ISO 27001 Lead Auditor/Implementer, CISSP, S+ or equivalent. Practical familiarity with AI tools and techniques as applied to Compliance workflows (automated evidence collection, control testing, audit analytics, risk-pattern detection), combined with the judgment to know where AI assistance ends and human accountability begins, particularly relevant given Swiggy's own ISO/IEC 42001 AI governance program. What Success Looks Like Measurable reduction in manual evidence-gathering effort through appropriate use of AI-assisted tooling, freeing up time for higher-judgment work like stakeholder negotiation and risk decisioning Zero major nonconformities in external certification audits, with minor findings closed within agreed timelines. A current, accurate enterprise risk register reviewed by leadership on a regular cadence. Vendor risk assessments completed on schedule with no critical vendors operating on expired assessments. Strong, trust-based relationships with auditors and stakeholders that keep audit cycles efficient rather than adversarial. Visit our tech blogs to learn more about some of the challenging problem statements Swiggy works on: https://bytes.swiggy.com/engineering-challenges-at-swiggy-430dea6c86a3 https://bytes.swiggy.com/the-swiggy-delivery-challenge-part-one-6a2abb4f82f6 https://bytes.swiggy.com/what-serviceability-means-at-swiggy-c94c1aad352a https://bytes.swiggy.com/architecture-and-design-principles-behind-the-swiggys-delivery-partners-app-4db1d87a048a https://bytes.swiggy.com/swiggy-distance-service-9868dcf613f4 https://bytes.swiggy.com/the-tech-that-brings-you-your-food-1a7926229886 We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, disability status, or any other characteristic protected by law. We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, disability status, or any other characteristic protected by the law.
Match this job to your CV
ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.
Check my match →Similar open roles
- Staff Data ScientistSWIGGY · bengaluru
- Sales Manager ISWIGGY · hyderabad
- Sales Manager ISWIGGY
- Software Dev Engineer II SWIGGY · bengaluru
- Legal Counsel ISWIGGY · bengaluru
- Sales ManagerSWIGGY · hyderabad
- Software Development Engineer III - BackendSWIGGY · bengaluru
- Assistant Manager - SupplySWIGGY · bengaluru
Need answers during your interview? Try Live Sarthi.
Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.
- Hidden from supported screen sharingThe overlay stays out of supported Windows screen captures.
- Answers start in about 1.5 secondsResponse time varies with your connection and model.
- From your own CVYour projects and your experience, not a generic script.
- 30 minutes freeThen ₹99 for a 2-day pass with unlimited calls — you pay for the days you are interviewing, not a subscription.
A Windows app, from the same team as ApplySarthi.
Listed on smartrecruiters · posted 2026-08-26. ApplySarthi collects openings and links to application pages; the role is advertised by SWIGGY, not by us.