Swiggy is India’s leading on-demand delivery platform with a tech-first approach to logistics and a solution-first approach to consumer demands. With a presence in 700+ cities across India, partnerships with hundreds of thousands of restaurants, an employee base of over 5000, and a 2 lakh+ strong independent fleet of Delivery Executives, we deliver unparalleled convenience driven by continuous innovation.
Job DescriptionJob Profile: Analyst II - Compliance & Audits
Location: Bangalore | Karnataka
Years of Experience: 2 to 4 years
About the Role & Team:
Swiggy is looking for an experienced Information Security Compliance & Audit professional to own and mature the organization’s security & audits program. This is a Level 5 (Analyst II) role for someone who is self-motivated and can operate independently across ISO 27001/22301/42001, PCI DSS, SOC 2, DPDP Act 2023, and CERT-In requirements, translate regulatory and contractual obligations into practical controls, and represent InfoSec confidently in front of internal leadership, external auditors, and third-party vendors. The role blends hands-on execution (running audits, managing risk registers, tracking remediation) with senior stakeholder engagement (vendor escalations, audit findings negotiation). This is increasingly a technical role as much as a governance one: the person must be equally comfortable auditing modern security architecture (cloud, EDR, CASB, application security) and using AI tools to accelerate audit and compliance workflows, while retaining the human judgment and accountability that final risk decisions require.
What will you get to do here?
1. Strategic Stakeholder Management
Executive Advisory: Act as the primary GRC point of contact for senior leadership; translate complex audit/risk findings into clear, decision-ready executive summaries.
Enablement & Escalation: Build cross-functional trust to drive compliant growth, manage pushback diplomatically, and negotiate realistic remediation timelines without sacrificing risk posture.
Control Ownership: Align cross-functional teams (Engineering, HR, Legal) to ensure every security policy and control has a dedicated, accountable owner.
2. Third-Party & Vendor Risk Management (TPRM)
Program Execution: Own end-to-end TPRM, including security questionnaires, risk assessments, and continuous monitoring for critical vendors.
Contractual Safeguards: Partner with Legal and Procurement to embed robust data protection clauses, breach notification SLAs, and right-to-audit terms in MSAs/SOWs.
Vendor Lifecycle: Maintain the central Vendor Risk Register, track re-assessment cycles, and drive offboarding or remediation for high-risk or non-compliant vendors.
3. End-to-End Audit Management
Framework Coverage: Own the audit calendar and readiness across ISO 27001, ISO 22301, ISO 42001 (AI Governance), PCI DSS, DPDP Act 2023, and CERT-In Directions 2022.
Audit Logistics & Evidence: Maintain current evidence repositories and lead field logistics, interview scheduling, and sample pulls to prevent audit fatigue.
Finding Resolution: Track audit findings to closure; formally flag overdue risks to leadership and document signoffs when extensions are required.
4. Auditor & Panel Management
Liaison & Negotiation: Serve as the main bridge for external certification bodies; negotiate audit scope, sampling, and timelines to remain proportionate and evidence based.
Internal Panel Oversight: Manage internal and outsourced audit panels, ensuring quality workpapers, professional dispute resolution, and auditor independence.
5. Governance, Risk & Framework Ownership
Enterprise Risk Management: Continuously mature an ISO 31000-aligned enterprise risk register and maintain the central policy framework.
Control Automation: Drive automation for evidence collection to minimize manual effort and enable real-time visibility into the organization’s compliance posture.
Qualifications
What qualities are we looking for?
2 - 4 years of experience in Compliance, IT audit, risk management.
Strong technical understanding of modern security technologies and practices such as cloud security (CSPM), EDR, CASB, DLP, Zero Trust/SASE, and application security (secure SDLC, SAST/DAST/SCA, API security) with the ability to independently audit these controls rather than relying solely on vendor, IT, or engineering self-attestation.
Hands-on experience managing ISO 27001, ISO 27701, ISO 42001, PCI DSS, or equivalent certification programs end-to-end, including surviving at least 2–3 external audit/certification cycles.
Strong working knowledge of Indian regulatory requirements: DPDP Act 2023, CERT-In Directions 2022, IT Act 2000, and sector-specific regulations (RBI PA/PG, NPCI) where relevant.
Demonstrated experience managing third-party/vendor risk programs, including contractual security requirements and vendor assessments.
Excellent stakeholder management and communication skills, comfortable presenting to senior leadership, negotiating with auditors, and influencing without direct authority.
Relevant certifications preferred: CISA, CRISC, ISO 27001 Lead Auditor/Implementer, CISSP, S+ or equivalent.
Practical familiarity with AI tools and techniques as applied to Compliance workflows (automated evidence collection, control testing, audit analytics, risk-pattern detection), combined with the judgment to know where AI assistance ends and human accountability begins, particularly relevant given Swiggy's own ISO/IEC 42001 AI governance program.
What Success Looks Like
Measurable reduction in manual evidence-gathering effort through appropriate use of AI-assisted tooling, freeing up time for higher-judgment work like stakeholder negotiation and risk decisioning
Zero major nonconformities in external certification audits, with minor findings closed within agreed timelines.
A current, accurate enterprise risk register reviewed by leadership on a regular cadence.
Vendor risk assessments completed on schedule with no critical vendors operating on expired assessments.
Strong, trust-based relationships with auditors and stakeholders that keep audit cycles efficient rather than adversarial.
Visit our tech blogs to learn more about some of the challenging problem statements Swiggy works on:
- https://bytes.swiggy.com/engineering-challenges-at-swiggy-430dea6c86a3
- https://bytes.swiggy.com/the-swiggy-delivery-challenge-part-one-6a2abb4f82f6
- https://bytes.swiggy.com/what-serviceability-means-at-swiggy-c94c1aad352a
- https://bytes.swiggy.com/architecture-and-design-principles-behind-the-swiggys-delivery-partners-app-4db1d87a048a
- https://bytes.swiggy.com/swiggy-distance-service-9868dcf613f4
- https://bytes.swiggy.com/the-tech-that-brings-you-your-food-1a7926229886
We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, disability status, or any other characteristic protected by law.
We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, disability status, or any other characteristic protected by the law.
Skills Required
- 2–4 years of experience in compliance, IT audit, or risk management
- Strong technical understanding of cloud security, including CSPM
- Experience with EDR, CASB, DLP, Zero Trust/SASE, and application security controls
- Ability to independently audit security controls rather than relying solely on vendor, IT, or engineering self-attestation
- Hands-on experience managing ISO 27001, ISO 27701, ISO 42001, PCI DSS, or equivalent certification programs end to end
- Experience completing at least 2–3 external audit or certification cycles
- Working knowledge of DPDP Act 2023, CERT-In Directions 2022, and IT Act 2000
- Knowledge of sector-specific regulations such as RBI PA/PG and NPCI where relevant
- Experience managing third-party or vendor risk programs, including contractual security requirements and vendor assessments
- Excellent stakeholder management and communication skills
- Ability to present to senior leadership, negotiate with auditors, and influence without direct authority
- Practical familiarity with AI tools for automated evidence collection, control testing, audit analytics, and risk-pattern detection
- CISA, CRISC, ISO 27001 Lead Auditor/Implementer, CISSP, Security+, or equivalent certification
Swiggy Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Swiggy and has not been reviewed or approved by Swiggy.
-
Equity Value & Accessibility — Equity grants and recurring liquidity events are ongoing, and feedback suggests office employees value this as part of total compensation. These programs provide a meaningful wealth‑creation lever by India tech standards.
-
Parental & Family Support — Gender‑neutral parental policies were expanded with extended leave, flexible/part‑time options, bonding leave, fertility/adoption support, and structured re‑entry. Feedback suggests these updates are viewed as progressive and supportive for caregiving.
-
Healthcare Strength — Company‑paid accident insurance for delivery partners includes hospitalization and OPD cover with extensions to family members. This safety net is notable within the gig‑economy context.
Swiggy Insights
What We Do
Swiggy is India’s leading on-demand delivery platform with a tech-first approach to logistics and a solution-first approach to consumer demands. With a presence in 500 cities across India, partnerships with hundreds of thousands of restaurants, an employee base of over 5000, a 2 lakh+ strong independent fleet of Delivery Executives, we deliver unparalleled convenience driven by continuous innovation. Built on the back of robust ML technology and fuelled by terabytes of data processed every day, Swiggy offers a fast, seamless and reliable delivery experience for millions of customers across India. From starting out as a hyperlocal food delivery service in 2014, to becoming a logistics hub of excellence today, our capabilities result not only in lightning-fast delivery for customers, but also in a productive and fulfilling experience for our employees. With Swiggy’s New Supply and the recent launches of Swiggy Instamart, Swiggy Genie, and Guiltfree, we are consistently making waves in the market, while continually growing the opportunities we offer our people. *We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, disability status, or any other characteristic protected by the law.
.png)







