06 Aug
|
Slice
|
Bengaluru
ABOUT THE ROLE: We are looking for an Information Security & GRC Analyst with 1–3 years of experience to join the Information Security team at slice. As part of the InfoSec team, you will be responsible for supporting and executing key activities across security governance, audits, regulatory compliance, risk management, third-party risk management and GRC operations. You will coordinate with Technology, Engineering, Risk, Compliance, Internal
Audit and other business teams to drive audit and regulatory requirements,
maintain evidence readiness, track security risks and observations, and ensure
Information Security action items are taken through to closure. This role is ideal for someone with early-career experience in Information
Security, IT Audit, Cyber Security or GRC, particularly with exposure to PCI
DSS, ISO 27001 or security/regulatory audits, who wants to build deeper expertise within an Information Security function WHAT YOU WILL DO:
Information Security Audits & Compliance Support Information Security and IT audits, including PCI DSS, ISO 27001, VAPT, application/API security assessments and regulatory audits.
Coordinate audit evidence collection, validation and submission across internal stakeholders.
Assist in tracking periodic security assessments and compliance activities against defined timelines.
Regulatory
Compliance & Gap Assessments Support assessment and implementation of applicable RBI, CERT-In, NPCI and other regulatory/security requirements.
Track new regulatory advisories, circulars and guidelines relevant to Information Security and Cyber Security.
Maintain regulatory compliance trackers with requirements, owners, timelines, evidence and remediation actions.
Support preparation and validation of Information Security inputs for regulatory submissions. Governance, Risk & Control Management Support Information Security risk assessments and maintain security risk registers.
Track risk mitigation plans, security exceptions and risk acceptances through closure or expiry.
Assist in periodic control assessments and monitoring of control effectiveness.
Support governance forums by preparing security metrics, dashboards, action trackers and supporting information.
Track decisions and action items arising from governance and management reviews. Third-Party Risk Management Support Third-Party/Vendor Risk Management (TPRM/VRM) activities.
Perform initial reviews of vendor security questionnaires and supporting evidence.
Coordinate with vendors and internal stakeholders for clarification and closure of identified gaps.
Maintain vendor risk assessment records, observations, remediation plans and supporting evidence. Policy & GRC Operations Support the Information Security policy and SOP lifecycle, including periodic reviews, version control, approvals and publication.
Maintain policies, SOPs, standards, risk registers, compliance trackers and other GRC documentation.
Support mapping of policies and controls against applicable regulatory requirements and security frameworks.
Identify opportunities to reduce manual GRC activities through better workflows, standardization and automation.
Support implementation and adoption of GRC platforms and automated compliance workflows.
WHAT YOU WILL NEED: Must Have 1–3 years of experience in Information Security, Cyber Security, IT Risk, IT Audit or GRC.
Exposure to Information Security/IT audits such as PCI DSS, ISO 27001, VAPT or similar security assessments.
Understanding of audit lifecycle activities including evidence collection, control testing, observation tracking and remediation.
Basic understanding of risk assessments, security controls, policy management and regulatory compliance.
Familiarity with security frameworks and standards such as ISO 27001, PCI DSS and NIST CSF.
Good analytical and documentation skills with strong attention to detail.
Ability to coordinate across multiple teams and follow up consistently to drive actions to closure.
Good working knowledge of Excel and PowerPoint.
Strong written and verbal communication skills. Nice to Have Experience in banking, fintech, financial services or another regulated environment.
Exposure to RBI, CERT-In and NPCI Information Security/Cyber Security requirements.
Experience supporting PCI DSS certification/compliance or ISO 27001 certification/surveillance audits.
Exposure to Third-Party Risk Management (TPRM/VRM).
Experience maintaining risk registers, audit trackers, regulatory compliance trackers or evidence repositories.
Familiarity with GRC platforms, workflow automation or compliance management solutions.
Relevant certifications or training in ISO 27001, PCI DSS, Security+, CEH or similar areas would be an advantage. What We’re Looking For Someone who is structured, curious and execution-focused.
You should be comfortable working with auditors, engineers, security teams, compliance teams and business stakeholders. You should be able to understand a requirement, identify the evidence needed, track gaps and follow through until closure.
You don’t need to know everything on day one, but you should have a strong interest in Information Security, audits, risk and regulatory compliance,
and be willing to learn how these functions operate at scale in a regulated fintech environment.
LIFE AT SLICE: Life so good, you’d think we’re kidding:
Competitive salaries. Period.
An extensive medical insurance that looks out for our employees & their dependents. We’ll love you and take care of you, our promise.
Flexible working hours. Just don’t call us at 3AM, we like our sleep schedule.
Tailored vacation & leave policies so that you enjoy every important moment in your life.
A reward system that celebrates hard work and milestones throughout the year. Expect a gift coming your way anytime you kill it here.
Learning and upskilling opportunities. Seriously, not kidding.
Good food, games, and a cool office to make you feel like home. An environment so good, you’ll forget the term “colleagues can’t be your friends”. We believe in equality. Period. At slice, we are committed to building a diverse and talented workforce. We never discriminate on the basis of race, sex, religion, colour, national origin,
gender, gender identity, sexual orientation, age, marital status, veteran status, medical condition, disability, or any other class or characteristic protected by the applicable law. We consider all qualified job-seekers with criminal histories in a manner consistent with the applicable law. Additionally, we are committed to providing reasonable accommodations to qualified individuals with physical or mental disabilities in order to participate in the job application or interview process, perform essential job functions, and receive other benefits and privileges of employment.
Come join our crew!
ABOUT SLICE: [https://slice.bank.in/] slice A new bank for a new India slice’s purpose is to make the world better at using money and time, with a major focus on building the best consumer experience for your money. We’ve all felt how slow, confusing, and complicated banking can be. So, we’re reimagining it. We’re building every product from scratch to be fast, transparent, and feel valuable, because we believe that the best products transcend demographics, like how great music touches most of us.
Our cornerstone products and services: slice savings account, slice UPI credit card, slice UPI, and slice business are designed to be simple, rewarding, and completely in your control. At slice, you’ll get to build things you’d use yourself and shape the future of banking in India. We tailor our working experience with the belief that the present moment is the only real thing in life.
And we have harmony in the present the most when we feel happy and successful together. We’re backed by some of the world’s leading investors, including Tiger Global,
Insight Partners, Advent International, Blume Ventures, and Gunosy Capital.
📌 Engineer 1 - IS Compliance (Bengaluru)
🏢 Slice
📍 Bengaluru