Fynd is an AI-native unified commerce platform headquartered in Mumbai, India. We help enterprise retailers and large store networks bring together what typically sits in silos: online commerce, in-store operations, and logistics, into one modular, scalable stack.Trusted by 300+ enterprise retailers and supporting 20,000+ stores, Fynd powers end-to-end retail execution: build and run high-performance websites, sell across marketplaces, modernize store experiences, and automate logistics and supply chain workflows. Our platform is designed for speed, accuracy, and scale, so teams can launch faster, operate smarter, and deliver more consistent customer experiences across every channel.Backed by Reliance Retail Ventures Limited, Fynd is expanding across GCC, Africa, and Southeast Asia to enable next-generation retail experiences
We are seeking a highly skilled Data Protection Officer (DPO) / GRC Officer responsible for ensuring compliance with global security and data protection regulations. The ideal candidate will oversee governance, risk, and compliance (GRC) programs, implement security frameworks, and safeguard sensitive data across the organization.
What will you do at Fynd ?
1. Governance, Risk, and Compliance (GRC):
-
Develop, implement, and maintain GRC frameworks to align with regulatory and industry standards.
-
Establish risk assessment methodologies and ensure mitigation strategies are in place.
-
Conduct IT General Controls (ITGC) assessments to ensure effective security controls and processes.
-
Oversee third-party risk assessments, ensuring vendors comply with security policies.
2. Data Protection & Privacy Compliance:
-
Implement and oversee compliance with DPDP (Digital Personal Data Protection Act, India) and GDPR regulations.
-
Act as the point of contact for data protection authorities and internal privacy matters.
-
Conduct Data Protection Impact Assessments (DPIAs) and privacy risk assessments.
-
Develop and enforce privacy policies, data retention, and protection measures.
3. Information Security Compliance & Certifications:
-
Lead and maintain compliance with ISO 27001, ensuring policies and controls meet certification requirements.
-
Manage SOC 2 compliance efforts, including security, availability, processing integrity, confidentiality, and privacy principles.
-
Oversee PCI-DSS compliance for handling cardholder data securely.
-
Ensure alignment with NIST security frameworks for risk management and cybersecurity resilience.
4. Business Continuity & Incident Management:
-
Develop and maintain a Business Continuity Management (BCM) program, including disaster recovery plans.
-
Lead security incident response and investigations to mitigate data breaches and cybersecurity threats.
-
Conduct regular tabletop exercises and audits to test resilience and readiness.
Some Specific Requirements
-
Bachelor’s/Master’s degree in Information Security, Cybersecurity, Compliance, or a related field.
-
Professional certifications such as CIPP/E, CIPM, CISSP, CISM, CISA, ISO 27001 Lead Auditor, or CRISC are highly preferred.
-
5+ years of experience in Data Protection, Compliance, GRC, or Cybersecurity roles.
-
Strong knowledge of regulatory frameworks (SOC2, ISO27001, GDPR, DPDP, PCI-DSS, NIST, ITGC, Third-Party Risk Management).
-
Experience in implementing GRC tools and automating compliance processes.
-
Excellent stakeholder management skills with the ability to work cross-functionally.
-
Strong analytical, problem-solving, and decision-making skills.
What do we offer?
Growth
At Fynd, growth is limitless. We nurture a culture that encourages innovation, embraces challenges, and supports continuous learning. As we expand into new product lines and global markets, we’re seeking talented individuals eager to grow with us.
We believe in empowering our people to take ownership, lead with confidence, and shape their careers.
-
Flex University: Access in-house learning sessions and workshops designed to enhance your professional and personal growth.
-
Learning Wallet: Enrol in external courses or certifications to upskill—we’ll reimburse the costs to support your development.
Culture
We believe in building strong teams and lasting connections.
-
Regular community engagement and team-building activities
-
Biannual events to celebrate achievements, foster collaboration, and strengthen our workplace culture
Wellness
Your well-being is our priority. Comprehensive Mediclaim policy for you, your spouse, children, and parents
Work Environment
We thrive on collaboration and creativity. Our teams work from the office five days a week to encourage open communication, teamwork, and innovation.
Join us to be part of a dynamic environment where your ideas make an impact!