Ovii Job Board

Senior Compliance Analyst

Signzy

Bangalore, India • Onsite - Bangalore, India • Full-Time • 3-6 years

Posted 2026-08-03 Corporate & Support

Apply on employer site

Job Description

Ovii's Interpretation of the Role

The Senior Compliance Analyst will lead security‑compliance programs, manage audits and third‑party risk, and maintain GRC frameworks for a digital banking platform.

Role Snapshot

  • Drive ISO 27001, SOC 2 & PCI‑DSS compliance
  • Lead third‑party risk and bank audits
  • Develop and maintain security policies
  • Coordinate internal & external audit artifacts
  • Manage vendor onboarding risk assessments
  • Produce security metrics and reports
  • Collaborate with engineering and business teams

Must-Have Requirements

  • information security, audit, compliance, risk assessment, management
  • hands‑on ISO 27001, PCI DSS, Data Localization, Bank Audits
  • security controls across all domains
  • security metrics and reporting
  • information security
  • audit/compliance
  • risk assessment

Nice-to-Have Signals

  • ISO27001 Lead Auditor/Implementer certification
  • CISA or CISM certification
  • basic automation/scripting (Python, SQL)
  • experience with SIEM/SOC outputs
  • knowledge of data governance/DLP tools
  • awareness of AI/ML governance
  • FinTech regulatory knowledge
  • automation scripting
  • ISO27001 Lead Auditor/Implementer
  • CISA
  • CISM

Work Setup

  • Location: Bangalore, India
  • Work mode: ONSITE
  • Employment type: Full-Time

Not Specified in JD

  • Visa sponsorship
  • Salary range
  • Remote eligibility
  • Education requirement
  • Certifications (required)
  • Relocation
  • Notice period
  • Travel
  • Security clearance
  • Coding test
  • Portfolio
  • GitHub
  • Writing sample
  • Cover letter

What You'll Likely Work On

  • Develop, implement and manage security policies, standards and procedures aligned to ISO 27001, SOC 2 and PCI‑DSS.
  • Lead third‑party risk management audits for banks and regulatory authorities.
  • Coordinate internal and external audits, gathering artifacts and responding to audit queries.
  • Oversee vendor/partner onboarding risk, including due‑diligence, contract compliance and continuous monitoring.
  • Maintain and evolve the enterprise GRC framework and risk registers.
  • Support operational, cyber and privacy risk assessments and produce actionable security metrics.
  • Conduct internal control testing, security control reviews and assist engineering with patch prioritization.
  • Provide clear audit guidance and expectations to security and engineering teams.

Good Fit If You Have

  • Familiarity with AI/ML governance and emerging regulatory trends.
  • Experience with CI/CD pipelines and IaC security scanning.
  • Relevant certifications such as ISO 27001 Lead Auditor, CISA or CISM.

Skills

  • ISO 27001 / SOC 2 / PCI‑DSS compliance
  • Risk assessment & GRC frameworks
  • Security controls (access, encryption, vulnerability, network)
  • Audit management & third‑party risk
  • Regulatory knowledge (SOX, GDPR, CCPA, NIST)
  • Python / SQL scripting for evidence collection
  • SIEM / SOC alert analysis
  • Data governance & DLP tools
  • Security metrics & reporting
  • Strong written & verbal communication