Meesho

e-commerce

AssociateComplianceManager

Bangalore, Karnataka, India FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Mid candidates.

The Brief

“Associate Compliance Manager at Meesho. Skills: ISO 27001, SOC 2, ITGC, TPRM. Own certification and surveillance cycle for ISO 27001: 2022 and SOC 2. Act as single point of contact for external auditors”

What You'll Achieve.

Safeguard a platform; Drive every external certification; Shape how Meesho earns trust; Operationalise India's DPDP Rules 2025; Achieve ISO 27001: 2022 certification; Achieve SOC 2 Type II certification; Reduce PCI DSS v4. 0. 1 scope; Improve IT General Controls; Reduce risk; Ensure vendor compliance; Ensure data privacy compliance; Maintain business continuity; Improve security awareness; Respond to inquiries; Maintain Trust Center

Industry & Context.

e commerce

What They're Looking For.

Must Have

4–6 years in security compliance, IT audit, or GRC at a product company, Hands-on experience driving ISO 27001: 2022 end-to-end, Hands-on experience driving SOC 2 Type II end-to-end, ITGC experience: access, change, ops, and SDLC control design and testing, TPRM experience across the full vendor lifecycle, Working knowledge of cloud (AWS and/or GCP), Demonstrated stakeholder management with Engineering, IT, Legal, Product, and external auditors, Excellent written communication

Nice to Have

DPDP Act 2023 / DPDP Rules 2025 implementation, familiarity with GDPR or ISO 27701, Hands-on with a GRC platform: Sprinto, Vanta, Drata, OneTrust, AuditBoard, MetricStream, ServiceNow GRC, or Archer, ISO 22301 BCMS experience, Exposure to RBI / SEBI / IRDAI sectoral compliance, PCI DSS v4. 0. 1 experience

What You'll Do.

Own certification and surveillance cycle for ISO 27001: 2022 and SOC 2

Act as single point of contact for external auditors

Plan and execute readiness assessments

Maintain audit calendars

evidence repositories

Drive PCI DSS v4. 0. 1 scope-reduction

Maintain ISMS aligned to ISO 27001: 2022

version-control security policies

Map controls across frameworks

test IT General Controls

Plan and execute internal audits

Track findings to closure

Build and maintain enterprise risk

Run full vendor lifecycle

Partner with Legal and Procurement

Conduct on-site / virtual vendor audits

Operationalise DPDP Act 2023 + DPDP Rules 2025

Prepare for Significant Data Fiduciary obligations

Maintain BCP and DR aligned to ISO 22301

Run organisation-wide security and privacy awareness

partner and enterprise security inquiries

Maintain the Trust Center and security collateral

How You'll Work.

Team & Collaboration

Work directly with Engineering, IT, Legal, Product, and external auditors; Stakeholder management with Engineering, IT, Legal, Product, and external auditors; Partner with Legal and Procurement; Track findings to closure with engineering and IT; Risk treatment plans and residual-risk acceptance with leadership

Communication Scope

Excellent written communication; Author policies, audit responses, and risk reports

Process & Methodology

Manage audit calendars, Manage evidence repositories, Manage vendor lifecycle, Manage risk treatment plans

Full Job Description

## Description About the Team  Meesho's Security & Compliance team safeguards a platform that 5% of Indian households shop with - millions of orders, billions of data points, zero downtime as a baseline. We own the Information Security Management System, drive every external certification, and shape how Meesho earns trust with sellers, buyers, partners and regulators. We move fast, default to automation, and obsess over evidence.   About the Role This is a hands-on individual contributor role for someone who wants to drive - not just oversee - a multi-framework compliance program. You'll be the DRI for ISO 27001:2022 and SOC 2 Type II, run end-to-end ITGC and TPRM cycles, and help operationalise India's DPDP Rules 2025 across a product organisation that processes data at meaningful scale. You'll work directly with Engineering, IT, Legal, Product, and external auditors.         ## What you will do Certifications & external audits Own the certification and surveillance cycle for ISO 27001:2022 and SOC 2 Type II; act as the single point of contact for external auditors. Plan and execute readiness assessments, gap closure, evidence collection, control walkthroughs, and management responses. Maintain audit calendars, evidence repositories, and bridge letters between audit windows. Drive PCI DSS v4.0.1 scope-reduction and assessment activities for in-scope environments. ISMS, policies & frameworks Maintain Meesho's ISMS aligned to ISO 27001:2022 - all 93 Annex A controls mapped across Organizational, People, Physical and Technological themes, with named owners and live evidence. Author, review, version-control and socialise security policies, standards, and procedures. Map controls across frameworks: ISO 27001:2022, SOC 2 TSC, PCI DSS v4.0.1, NIST CSF 2.0, CIS Controls v8, DPDP. ITGC & internal audits Design, test and continuously improve IT General Controls: access management, change management, IT operations, and SDLC. Plan and execute internal audits; track findings to

Free ATS check

Applying for this Associate Compliance Manager role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Lever

  • Lever uses a streamlined one-page form — apply in under 5 minutes.
  • LinkedIn import works well; review parsed data before submitting.
  • The cover letter field is optional but visible to reviewers — use it to differentiate.
  • Referral codes from employees can significantly boost visibility of your application.

ANONYMOUS · UNFILTERED

What do employees actually say about Meesho?

Real rants from real employees. Read before you apply.

Read Company Rants →