Security Engineer (Governance Risk & Compliance)
About the Role
Flipkart is seeking a skilled, motivated, and collaborative Individual for the Designation of Information Security- Governance Risk & Compliance (GRC). In this role, you will be a key member in the Information Security team to move forward the Governance, Risk and Compliance practice by influencing business leaders across the Flipkart enterprise. You will serve as an expert and be a mentor to the information security core team. You will be a strong communicator and influencer, demonstrating curiosity to learn and understand the business
About the team
The Governance, Risk & Compliance team is a central part of the Information security department, with primary responsibility to provide robust metrics, data-driven insights, and effective technologies for information security risk management. We aim to provide a structured approach to align information security with business objectives, while effectively managing risk and meeting compliance requirements. And responsible for ensuring Flipkart is adhering to mandated statutory and industry infosec requirements
You are Responsible for
-
Governance, Risk & Compliance (GRC)
- Develop, implement, and maintain information security policies, standards, and procedures.
- Support security audits and ensure timely closure of findings.
- Monitor compliance with frameworks/standards such as ISO 27001, NIST, CIS
- Collaborate with security engineering and SOC teams on remediation of vulnerabilities, incident response, and security enhancements.
- Contribute to cross-functional security initiatives requiring governance, technical, and operational alignment.
-
Provide training and awareness on security to drive security aware culture
-
Third-Party Risk Management (TPRM)
- Conduct security assessments and due diligence for vendors, partners, and service providers.
- Review and evaluate vendor security controls, certifications, and compliance posture.
-
Manage the third-party risk lifecycle, including onboarding, periodic reviews, and issue remediation.
Work with procurement, legal, and business teams to integrate security requirements into contracts and agreements.
-
AI in GRC
- Integrate AI-driven solutions for enhanced GRC processes, including automated risk assessments, continuous compliance monitoring, and predictive risk analytics.
- Research and evaluate emerging AI technologies for potential application in information security and compliance.
- Develop and implement strategies for leveraging AI to identify and mitigate security risks more effectively.
To succeed in this role – you should have the following
- Bachelor’s degree in Computer Science or Information Security or related field
- 3–4 years of experience in Information Security roles with focus on GRC and TPRM.
- Strong understanding of security standards (ISO 27001, NIST, etc.).
- Experience conducting risk assessments, vendor due diligence, and compliance reviews.
- Excellent documentation, communication, and stakeholder management skills.