
Job Description
Ovii's Interpretation of the Role
As an Associate Compliance Manager you will own and drive Meesho’s security and privacy compliance program, handling ISO 27001, SOC 2, PCI DSS and DPDP initiatives. You will work cross‑functionally with engineering, legal, product and auditors to implement controls, manage third‑party risk and maintain audit evidence.
Role Snapshot
- Own ISO 27001:2022 certification cycle
- Lead SOC 2 Type II surveillance
- Design and test IT General Controls
- Manage full vendor risk lifecycle
- Operationalise DPDP privacy framework
- Maintain audit calendars and evidence repositories
- Drive security and privacy awareness programs
Must-Have Requirements
- ISO 27001:2022 implementation
- SOC 2 Type II implementation
- IT General Controls design and testing
- Third‑party risk management experience
- Cloud (AWS and/or GCP) knowledge
- security compliance
- IT audit
- GRC
- Location: Bangalore, Karnataka (onsite)
Nice-to-Have Signals
- DPDP Act 2023 / DPDP Rules 2025 implementation
- GDPR familiarity
- ISO 22301 Business Continuity Management experience
- PCI DSS v4.0.1 experience
- Hands‑on with GRC platforms (Sprinto, Vanta, OneTrust, ServiceNow, Archer)
- Exposure to RBI / SEBI / IRDAI sectoral compliance
- DPDP implementation
- PCI DSS
- ISO 22301
- privacy regulations
- ISO 27001 Lead Auditor / Lead Implementer
- CISA
- CIPP/E
- DCPP
Work Setup
- Location: Bangalore, India
- Work mode: ONSITE
- Employment type: Full-Time
Not Specified in JD
- Visa sponsorship
- Salary range
- Remote eligibility
- Education requirement
- Certifications
- Travel
What You'll Likely Work On
- Own certification and surveillance cycles for ISO 27001:2022 and SOC 2 Type II, coordinating with external auditors.
- Design, test, and continuously improve IT General Controls and conduct internal audits.
- Run the full vendor lifecycle – intake, security due diligence, contractual controls, monitoring and off‑boarding.
- Operationalise the DPDP Act and Rules, including DPIAs, consent flows, breach notification and Records of Processing Activity.
- Maintain business continuity plans aligned to ISO 22301 and execute annual disaster‑recovery testing.
- Run organisation‑wide security and privacy awareness programs, including phishing simulations and role‑based training.
Good Fit If You Have
- Strong stakeholder management with engineering, IT, legal and product teams.
- Excellent written communication for policies, audit responses and risk reports.
- Experience in SaaS, fintech, e‑commerce or payments environments is beneficial.
- Familiarity with GDPR or ISO 27701 is a plus.
Skills
- ISO 27001:2022 implementation
- SOC 2 Type II implementation
- PCI DSS v4.0.1
- DPDP Act & Rules 2025
- IT General Controls (access, change, ops, SDLC)
- Third‑party risk management (TPRM)
- Cloud platforms (AWS, GCP) shared‑responsibility model
- GRC tools (Sprinto, Vanta, OneTrust, ServiceNow, Archer)
- Risk assessment (RCSA, KRIs, risk register)
- Policy authoring and version control