Skip to main content

Information Security Compliance & Audits

Swiggy

  • Bengaluru, KA, India
  • full-time
  • Posted today

Company Description

Swiggy is India’s leading on-demand delivery platform with a tech-first approach to logistics and a solution-first approach to consumer demands. With a presence in 700+ cities across India, partnerships with hundreds of thousands of restaurants, an employee base of over 5000, and a 2 lakh+ strong independent fleet of Delivery Executives, we deliver unparalleled convenience driven by continuous innovation.

Job Description

Location: Bangalore | Karnataka

Years of Experience: 5 to 8 years

Swiggy is looking for an experienced Information Security Compliance & Audit professional to own and mature the organization’s security & audits program. This is a Level 5 (Analyst II) role for someone who is self-motivated and can operate independently across ISO 27001/22301/42001, PCI DSS, SOC 2, DPDP Act 2023, and CERT-In requirements, translate regulatory and contractual obligations into practical controls, and represent InfoSec confidently in front of internal leadership, external auditors, and third-party vendors. The role blends hands-on execution (running audits, managing risk registers, tracking remediation) with senior stakeholder engagement (vendor escalations, audit findings negotiation). This is increasingly a technical role as much as a governance one: the person must be equally comfortable auditing modern security architecture (cloud, EDR, CASB, application security) and using AI tools to accelerate audit and compliance workflows, while retaining the human judgment and accountability that final risk decisions require.

  • Executive Advisory: Act as the primary GRC point of contact for senior leadership; translate complex audit/risk findings into clear, decision-ready executive summaries.
  • Enablement & Escalation: Build cross-functional trust to drive compliant growth, manage pushback diplomatically, and negotiate realistic remediation timelines without sacrificing risk posture.
  • Control Ownership: Align cross-functional teams (Engineering, HR, Legal) to ensure every security policy and control has a dedicated, accountable owner.
  • Program Execution: Own end-to-end TPRM, including security questionnaires, risk assessments, and continuous monitoring for critical vendors.
  • Contractual Safeguards: Partner with Legal and Procurement to embed robust data protection clauses, breach notification SLAs, and right-to-audit terms in MSAs/SOWs.
  • Vendor Lifecycle: Maintain the central Vendor Risk Register, track re-assessment cycles, and drive offboarding or remediation for high-risk or non-compliant vendors.
  • Framework Coverage: Own the audit calendar and readiness across ISO 27001, ISO 22301, ISO 42001 (AI Governance), PCI DSS, DPDP Act 2023, and CERT-In Directions 2022.
  • Audit Logistics & Evidence: Maintain current evidence repositories and lead field logistics, interview scheduling, and sample pulls to prevent audit fatigue.
  • Finding Resolution: Track audit findings to closure; formally flag overdue risks to leadership and document signoffs when extensions are required.
  • Liaison & Negotiation: Serve as the main bridge for external certification bodies; negotiate audit scope, sampling, and timelines to remain proportionate and evidence based.
  • Internal Panel Oversight: Manage internal and outsourced audit panels, ensuring quality workpapers, professional dispute resolution, and auditor independence.
  • Enterprise Risk Management: Continuously mature an ISO 31000-aligned enterprise risk register and maintain the central policy framework.
  • Control Automation: Drive automation for evidence collection to minimize manual effort and enable real-time visibility into the organization’s compliance posture.

Qualifications

  • 5 - 8 years of experience in Compliance, IT audit, risk management.
  • Strong technical understanding of modern security technologies and practices such as cloud security (CSPM), EDR, CASB, DLP, Zero Trust/SASE, and application security (secure SDLC, SAST/DAST/SCA, API security) with the ability to independently audit these controls rather than relying solely on vendor, IT, or engineering self-attestation.
  • Hands-on experience managing ISO 27001, ISO 27701, ISO 42001, PCI DSS, or equivalent certification programs end-to-end, including surviving at least 2–3 external audit/certification cycles.
  • Strong working knowledge of Indian regulatory requirements: DPDP Act 2023, CERT-In Directions 2022, IT Act 2000, and sector-specific regulations (RBI PA/PG, NPCI) where relevant.
  • Demonstrated experience managing third-party/vendor risk programs, including contractual security requirements and vendor assessments.
  • Excellent stakeholder management and communication skills, comfortable presenting to senior leadership, negotiating with auditors, and influencing without direct authority.
  • Relevant certifications preferred: CISA, CRISC, ISO 27001 Lead Auditor/Implementer, CISSP, S+ or equivalent.
  • Practical familiarity with AI tools and techniques as applied to Compliance workflows (automated evidence collection, control testing, audit analytics, risk-pattern detection), combined with the judgment to know where AI assistance ends and human accountability begins, particularly relevant given Swiggy's own ISO/IEC 42001 AI governance program.

Additional Information

  • Measurable reduction in manual evidence-gathering effort through appropriate use of AI-assisted tooling, freeing up time for higher-judgment work like stakeholder negotiation and risk decisioning
  • Zero major nonconformities in external certification audits, with minor findings closed within agreed timelines.
  • A current, accurate enterprise risk register reviewed by leadership on a regular cadence.
  • Vendor risk assessments completed on schedule with no critical vendors operating on expired assessments.
  • Strong, trust-based relationships with auditors and stakeholders that keep audit cycles efficient rather than adversarial.
  • https://bytes.swiggy.com/engineering-challenges-at-swiggy-430dea6c86a3
  • https://bytes.swiggy.com/the-swiggy-delivery-challenge-part-one-6a2abb4f82f6
  • https://bytes.swiggy.com/what-serviceability-means-at-swiggy-c94c1aad352a
  • https://bytes.swiggy.com/architecture-and-design-principles-behind-the-swiggys-delivery-partners-app-4db1d87a048a
  • https://bytes.swiggy.com/swiggy-distance-service-9868dcf613f4
  • https://bytes.swiggy.com/the-tech-that-brings-you-your-food-1a7926229886

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, disability status, or any other characteristic protected by law.