
Infosec GRC Associate II
Zeta · Bengaluru, Karnataka, India
- On site
- Full-time
- $95,000 / year
- Bengaluru, Karnataka, India
Job highlights
- Support PCI DSS, ISO 27001, SOC audits.
- Assess IT architecture for PCI compliance.
- Develop vendor risk management programs.
- Implement RBI and regulatory controls.
- Maintain ISMS framework and risk assessments.
About the role
About Us
Build The Future Of Banking.
Zeta is a next-generation banking technology company providing cloud-native, fully stackable processing and core banking platforms for issuers. With a focus on scalability, compliance, and innovation, Zeta empowers financial institutions to modernize their technology infrastructure and deliver secure, seamless digital banking experiences.
Our impact runs at real-world scale. Today, over 25 million cards are live on Zeta-powered platforms across 7 countries, supported by a passionate team of 1,700+ Zetanauts across India, the US, EMEA, and Asia. Backed by SoftBank Vision Fund, Mastercard, and other reputed strategic investors, we reached a valuation of $2 billion in 2025.
Our Focus Is On Establishing Product Lines That Focus On Key Outcomes By Addressing Real Customer Pain Points, Modernizing Legacy Systems, And Strengthening Core Fundamentals. As a Result, Our Systems And Platforms Support a Wide Range Of Banking And Payments Capabilities, Including:
- Tachyon, our cloud-native banking stack built for population-scale systems
- Cipher, our unified authentication platform for secure, high-volume banking environments
- Digital Credit as a Service, enabling banks to launch credit lines on UPI
- Elena, our intelligent and conversational AI platform for banking
- Pixel, India’s first digital-native credit card, launched in partnership with HDFC Bank, for whom we also revamped their PayZapp mobile app: Winner of the Celent Model Bank Award for Payments Innovation 2024
- Sparrow, the leading card experience for non-prime cardholders in the US
...and more across cards, payments, lending, and core banking.
We are an engineering-first organization that values ownership, bias for action, and long-term thinking. Together, we solve some of the hardest problems in banking tech. Our culture is built around trust, collaboration, and creating the conditions for you to drive impact proportionate to your potential. Reinforcing our commitment to creating an inclusive and supportive workplace, we have been consistently recognized as a Great Place to Work.
If you want to build cutting-edge banking tech that enables banks to serve millions reliably, securely, and at a population scale, Zeta is your playground.
If you would like to learn more about how we have grown and evolved over the years, watch our journey here. You can also explore our website and follow us on LinkedIn, Instagram, YouTube, and X.
Zeta is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We encourage applicants from all backgrounds, cultures, and communities to apply and believe that a diverse workforce is key to our success.
The Role
This role is part of the Information Security Process and Compliance Team of Zeta. The Sr. Associate of InfoSec Audit and compliance is responsible for preparing and supporting PCIDSS, ISO 27001 and SOC external Audits. Actively participate, strengthen and improve Internal Audit process and provide assurance on internal technology and process compliance. Collaborate with the Cloud and Product security team to drive Risk and compliance goals.
Responsibilities
- Work with internal and external stakeholders to assess the IT architecture or proposed IT architecture solutions to identify the risk areas with regards to PCI controls.
- Assess the network architecture and or reviews the Firewall rulesets, Network devices/appliances to see if they are aligned with the PCI control requirements and recommends compensatory controls where necessary.
- Execute operational activities to support audit and compliance activities including technical validation processes.
- Conduct PCI DSS scoping engagements, gap analysis and assessments related to securing the Cardholder Data Environment.
- Effectively multi-tasks on multiple assignments and deliverables.
- Actively accepts individual and team responsibilities to meet commitments. Takes responsibility for own performance and actions and demonstrates responsibility and teamwork towards overall team/department goals.
- Discuss the SOP document with all relevant stakeholders - right from process owner to the BU functional heads Detailed understanding of SOC reports (SOC2, Type 1, 2), ISMS reports and ability to relate the IT General Controls, IT Application Controls, Cyber Controls to the SOC framework.
- Develop and Maintain Vendor Risk Management /Third Party Risk Management Program including Vendor Onboarding Audit, Periodic Vendor Assessment, Maintain TPRM Database.
- Review and implement controls and policies as per RBI and other regulatory requirements.
- Maintain ISMS framework, evaluate effectiveness of implemented controls and provides recommendations for improvement.
- Facilitate Client Due - Diligence in collaboration with Business.
- Develop and Maintain Enterprise Risk Assessment framework.
- Perform Internal Assessment against various Standards to ensure the established policies are being followed and prepare internal reports.
- Contract review and providing responses to client Request for Proposal (RFP)
Skills
- Good Understanding of Technology Risk Assessment Frameworks and Application risk Assessment.
- Good Understanding and hands on experience on PCI DSS Standard and various PCI compliance is must.
- Experience of working in the Banking or Payment sector is preferred.
- Hands-on experience with various Audits and Standards Such as ISMS, SSAE 18, ISO 27001,ISO 31000, ISO 22301, CSA Star, NIST Risk framework, PCI DSS, PCI 3DS, PCI PA-DSS/SSF, PCI S3 etc.
- Good to have Information Security Certifications like CISA, CISM, CISSP etc.
- Experience of Vendor Risk Assessment and responding to client Request for Proposal(RFP).
- Excellent written and oral communication and penchant for technical documentation
Experience And Qualifications
- 3 - 5 years of experience in Information Security and Compliance in medium to large-sized companies.
- Bachelor of Technology (BE/ B.Tech ), M.Tech or ME in Computer Science, MCA or equivalent.
Zeta is an equal opportunity employer
At Zeta, we are committed to equal employment opportunities regardless of job history, disability, gender identity, religion, race, marital/parental status, or another special status. We are proud to be an equitable workplace that welcomes individuals from all walks of life if they fit the roles and responsibilities.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Key skills/competency
- Information Security
- GRC
- Compliance Audits
- PCI DSS
- ISO 27001
- SOC Audits
- Risk Assessment
- Vendor Risk Management
- Regulatory Compliance
- Technology Risk
Skills & topics
- Information Security
- GRC
- Compliance
- Audits
- PCI DSS
- ISO 27001
- SOC
- Risk Management
- Technology
- Banking
- Infosec
- IT Audit
- Cybersecurity
- Regulatory Compliance
- SSAE 18
- ISO 31000
- ISO 22301
- CSA Star
- NIST
- CISA
- CISM
- CISSP
- RFP
- B.Tech
- MCA
How to get hired
- Tailor your resume: Highlight Information Security, GRC, PCI DSS, and ISO 27001 experience.
- Showcase compliance expertise: Detail your involvement in audits and risk assessments.
- Quantify achievements: Use numbers to demonstrate impact in previous roles.
- Prepare for technical questions: Be ready to discuss risk frameworks and standards.
- Emphasize banking sector experience: If applicable, highlight your work in this domain.
Technical preparation
Behavioral questions
Frequently asked questions
- What are the key compliance standards for the Infosec GRC Associate role at Zeta?
- For the Infosec GRC Associate role at Zeta, the key compliance standards you'll be working with include PCI DSS, ISO 27001, and SOC (SOC2 Type 1 and 2) reports. Familiarity with these is crucial for success in this position.
- Is experience in the banking or payment sector required for this Infosec GRC Associate position at Zeta?
- While experience in the banking or payment sector is preferred for the Infosec GRC Associate role at Zeta, it is not strictly required. However, a strong understanding of technology risk assessment frameworks and PCI DSS compliance is a must.
- What kind of technical documentation is expected from an Infosec GRC Associate at Zeta?
- An Infosec GRC Associate at Zeta is expected to have excellent written communication skills and a penchant for technical documentation. This includes documenting assessments, controls, policies, and responses to RFPs.
- Does Zeta use AI in its hiring process for the Infosec GRC Associate role?
- Yes, Zeta may use AI tools to assist with parts of the hiring process, such as reviewing applications and analyzing resumes for roles like the Infosec GRC Associate. However, final hiring decisions are always made by humans.
- What are the educational qualifications for the Infosec GRC Associate II position at Zeta?
- The educational qualifications for the Infosec GRC Associate II position at Zeta include a Bachelor of Technology (BE/B.Tech), M.Tech, or ME in Computer Science, or an MCA, or an equivalent degree.
- What is the primary focus of the Information Security Process and Compliance Team at Zeta?
- The Information Security Process and Compliance Team at Zeta focuses on preparing and supporting external audits like PCI DSS, ISO 27001, and SOC. They also work to strengthen internal audit processes, ensure technology and process compliance, and collaborate on risk and compliance goals.
- What specific responsibilities does the Infosec GRC Associate have regarding PCI DSS at Zeta?
- The Infosec GRC Associate at Zeta is responsible for assessing IT architecture for PCI control risks, evaluating network architecture and firewall rulesets against PCI requirements, and conducting PCI DSS scoping, gap analysis, and assessments for the Cardholder Data Environment.