GRC Officer
ComplianceMumbai, IndiaFULL TIMEPosted 9/23/2026
About Fynd
Fynd is a frontier technology company. We started at the intersection of technology and retail because that is where technology was the least available. Over the years, we became one of India’s largest retail technology platforms. But retail was the entry point, not the boundary.
Today, Fynd builds intelligent software that runs business operations. Not tools that help people work faster, but systems that absorb entire functions: manufacturing, marketing, logistics, commerce, quality control. We sit inside our customers’ businesses, harvest deep domain context, and build AI systems that operate autonomously. We are expanding from retail into manufacturing, generative media, physical AI, and healthcare.
Role Overview
The GRC Officer will play a critical role in strengthening the organization’s governance, risk, and compliance posture across the business. This role ensures alignment with global security and data protection requirements, enabling the company to operate securely, meet regulatory obligations, and maintain trust with customers and stakeholders. Given approved system access, independently build and run repeatable checks, identify compliance gaps, map findings to controls and generate audit-ready evidence.
Responsibilities
- Develop, implement, and maintain governance, risk, and compliance (GRC) frameworks, policies, and procedures.
- Conduct regular risk assessments to identify control gaps, evaluate threats, and recommend mitigation actions.
- Monitor and ensure compliance with relevant standards and regulations, including ISO 27001, PCI-DSS, NIST, and data protection requirements.
- Support IT General Controls (ITGC) design, documentation, testing, and remediation activities.
- Coordinate internal and external audits, including evidence collection, remediation tracking, and issue resolution.
- Partner with cross-functional teams to embed security, privacy, and compliance controls into business processes and technology initiatives.
- Track regulatory changes and industry best practices to update compliance programs and risk management activities.
- Prepare and present GRC reports, metrics, and status updates to leadership and key stakeholders.
- Required skills: Python scripting, SQL, REST APIs/CLIs and Git, with practical knowledge of cloud, IAM, databases and logging. Move cloud knowledge from Preferred to Required and ask for demonstrated automation projects.
- Automation responsibilities: Build and maintain scheduled evidence collectors and control checks—for example, stale/excessive access, missing audit logging and insecure storage configurations. Report Pass/Fail/Unknown; inaccessible or incomplete data must remain explicit.
- Actionable findings: Record the affected asset, control, evidence source/time, business risk, owner and remediation; automate tracking and verify fixes. The expectation includes writing and debugging the checks, then validating their results.
- Retain GRC ownership: Keep risk assessments, ISO 27001/PCI-DSS/NIST control mapping, ITGC, policies, audit support and remediation follow-up.
Qualifications
Required
- Bachelor's degree in Information Security, Computer Science, or a related field
- 5+ years of experience in GRC, compliance, information security, or risk management
- Hands-on experience with ISO 27001, PCI-DSS, NIST, or similar security standards
- Experience conducting risk assessments and supporting compliance audits
- Working knowledge of IT General Controls and data protection requirements
Preferred
- Professional certification such as CISA, CISSP, CRISC, or ISO 27001 Lead Implementer/Lead Auditor
- Experience in a global technology or high-growth digital organization
- Exposure to privacy regulations and cross-border data protection requirements
- Experience building or maturing enterprise-wide GRC programs
- Familiarity with cloud security and third-party risk management
What do we offer?
Growth
At Fynd, growth is limitless. We nurture a culture that encourages innovation, embraces challenges, and supports continuous learning. As we expand into new product lines and global markets, we're seeking talented individuals eager to grow with us.
We believe in empowering our people to take ownership, lead with confidence, and shape their careers.
Learning Wallet: Enrol in external courses or certifications to upskill—we'll reimburse the costs to support your development.
Culture
We believe in building strong teams and lasting connections.
- Regular community engagement and team-building activities
- Biannual events to celebrate achievements, foster collaboration, and strengthen our workplace culture
Wellness
Your well-being is our priority. Comprehensive Mediclaim policy for you, your spouse, children, and parents.
Work Environment
We thrive on collaboration and creativity. Our teams work from the office five days a week to encourage open communication, teamwork, and innovation.
Join us to be part of a dynamic environment where your ideas make an impact!
What happens next?
- Check your email for application confirmation.
- The hiring team reviews your profile for the role.
- Watch your inbox for hiring updates and next steps.
Emails follow your notification preferences. Check spam or junk if needed.