Security Engineer (Governance Risk & Compliance)

About the Role

Flipkart is seeking a skilled, motivated, and collaborative Individual for the Designation of Information Security- Governance Risk & Compliance (GRC). In this role, you will be a key member in the Information Security team to move forward the Governance, Risk and Compliance practice by influencing business leaders across the Flipkart enterprise. You will serve as an expert and be a mentor to the information security core team. You will be a strong communicator and influencer, demonstrating curiosity to learn and understand the business

About the team

The Governance, Risk & Compliance team is a central part of the Information security department, with primary responsibility to provide robust metrics, data-driven insights, and effective technologies for information security risk management. We aim to provide a structured approach to align information security with business objectives, while effectively managing risk and meeting compliance requirements. And responsible for ensuring Flipkart is adhering to mandated statutory and industry infosec requirements

You are Responsible for

  • Governance, Risk & Compliance (GRC)
     
    • Develop, implement, and maintain information security policies, standards, and procedures.
    • Support security audits and ensure timely closure of findings.
    • Monitor compliance with frameworks/standards such as ISO 27001, NIST, CIS
    • Collaborate with security engineering and SOC teams on remediation of vulnerabilities, incident response, and security enhancements.
    • Contribute to cross-functional security initiatives requiring governance, technical, and operational alignment.
    • Provide training and awareness on security to drive security aware culture
       
  • Third-Party Risk Management (TPRM)
     
    • Conduct security assessments and due diligence for vendors, partners, and service providers.
    • Review and evaluate vendor security controls, certifications, and compliance posture.
    • Manage the third-party risk lifecycle, including onboarding, periodic reviews, and issue remediation.
      Work with procurement, legal, and business teams to integrate security requirements into contracts and agreements.

 

  • AI in GRC
    • Integrate AI-driven solutions for enhanced GRC processes, including automated risk assessments, continuous compliance monitoring, and predictive risk analytics.
    • Research and evaluate emerging AI technologies for potential application in information security and compliance.
    • Develop and implement strategies for leveraging AI to identify and mitigate security risks more effectively.

To succeed in this role – you should have the following

  • Bachelor’s degree in Computer Science or Information Security or related field
  • 3–4 years of experience in Information Security roles with focus on GRC and TPRM.
  • Strong understanding of security standards (ISO 27001, NIST, etc.).
  • Experience conducting risk assessments, vendor due diligence, and compliance reviews.
  • Excellent documentation, communication, and stakeholder management skills.
Back to blog

Other Jobs To Apply

No other job posts for this day.

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...