GRC and Vendor Risk Management

Whatfix
Whatfix

Bengaluru, Karnataka, India

Posted on Aug 27, 2026

Who are we?

Founded in 2014 by Khadim Batti and Vara Kumar, Whatfix is a leading global B2B SaaS provider and the largest pure-play enterprise digital adoption platform (DAP). Whatfix empowers companies to maximize the ROI of their digital investments across the application lifecycle, from ideation to training to the deployment of software. Driving user productivity, ensuring process compliance, and improving user experience of internal and customer-facing applications.

Spearheading the category with serial innovation and unmatched customer-centricity, Whatfix is the only DAP innovating beyond the category, positioning itself as a comprehensive suite for GenAI-powered digital adoption, analytics, and application simulation. Whatfix product suite consists of 3 products - DAP, Product Analytics, and Mirror. This product suite helps businesses accelerate ROI on digital investments by streamlining application deployment across its lifecycle.

Whatfix has seven offices across the US, India, UK, Germany, Singapore, and Australia and a presence across 40+ countries.

Customers: 700+ enterprise customers, including over 80 Fortune 500 companies such as Shell, Microsoft, Schneider Electric, and UPS Supply Chain Solutions.

Investors: Raised a total of ~$270 million. Most recently Series E round of $125 Million led by Warburg Pincus with participation from existing investor SoftBank Vision Fund 2. Other investors include Cisco Investments, Eight Roads Ventures (A division of Fidelity Investments), Dragoneer Investments, Peak XV Partners, and Stellaris Venture Partners.

  • With over 45% YoY sustainable annual recurring revenue (ARR) growth, Whatfix is among the “Top 50 Indian Software Companies” as per G2 Best Software Awards.

  • Recognized as a “Leader” in the digital adoption platforms (DAP) category for the past 4+ years by leading analyst firms like Gartner, Forrester, IDC, and Everest Group.

  • The only vendor recognized as a Customers’ Choice in the 2024 Gartner® Voice of the Customer for Digital Adoption Platforms has once again earned the Customers’ Choice distinction in 2025. We also boast a star rating of 4.6 on G2 Crowd, 4.5 on Gartner Peer Insights, and a high CSAT of 99.8%

  • Highest-Ranking DAP on 2023 Deloitte Technology Fast 500™ North America for Fourth Consecutive Year

  • Won the Silver for Stevie's Employer of the Year 2023 – Computer Software category and also recognized as Great Place to Work 2022-2023

  • Only DAP to be among the top 35% companies worldwide in sustainability excellence with EcoVadis Bronze Medal

On the G2 peer review platform, Whatfix has received 77 Leader badges across all market segments, including Small, Medium, and Enterprise, in 2024, among numerous other industry recognitions.


Role Summary:

We are looking for an Information Security – GRC Engineer to support and drive Whatfix's multi-framework compliance program across Information Security, Data Privacy, AI Governance, and Third-Party Risk Management (TPRM).

A key responsibility of this role will be to manage and operate the organization's end-to-end TPRM program, including vendor onboarding, risk assessments, due diligence, periodic reassessments, risk tracking, remediation, offboarding, and continuous improvement of the TPRM framework.


Roles & Resposblities:

Third-Party Risk Management

  • Manage and operate the end-to-end Third-Party Risk Management (TPRM) program, including vendor onboarding, risk classification, due diligence, security and privacy assessments, periodic reassessments, remediation tracking, and offboarding.

  • Conduct and coordinate third-party information security, privacy, compliance, and AI risk assessments.

  • Review vendor-provided evidence and artefacts, including security questionnaires, certifications, audit reports, policies, and other assurance documentation.

  • Identify, assess, document, and track risks associated with third-party relationships and follow up on mitigation and remediation actions.

  • Maintain accurate vendor inventories, assessment records, risk ratings, findings, exceptions, and reassessment schedules.

  • Manage and continuously monitor the vendor/TPRM management platform and related trackers to ensure records remain complete and up to date.

  • Coordinate with internal stakeholders and vendors throughout the third-party lifecycle.

  • Maintain and continuously improve TPRM policies, procedures, SOPs, risk assessment methodologies, and reporting.

GRC, Compliance & AI Governance

  • Support the implementation, maintenance, and continual improvement of compliance programs, including (but not limited to) ISO 27001, ISO 27701, ISO 42001, CSA STAR, TISAX, Cyber Essentials Plus, GDPR, DPDP, HIPAA, and other applicable requirements.

  • Manage day-to-day compliance activities, including GRC platforms, evidence collection, compliance trackers, stakeholder follow-ups, and SOPs.

  • Support internal and external audits, including audit preparation, evidence management, stakeholder coordination, and tracking observations and corrective actions.

  • Assist in conducting information security, privacy, compliance, and AI risk and impact assessments.

  • Support the organization's AI governance program, including maintaining the AI inventory and supporting AI risk assessments and governance activities.

  • Support periodic review and maintenance of Information Security, Privacy, AI, and other GRC-related policies and procedures.

  • Assist with security, privacy, and AI awareness initiatives.

  • Monitor relevant regulatory, security, privacy, and AI developments and support continuous improvement of GRC processes.

  • Manage and coordinate customer due-diligence requests, including security, privacy, compliance, and AI questionnaires, evidence requests, and stakeholder coordination.

  • Review information security, data privacy, and AI-related contractual requirements in customer and vendor agreements, including DPAs, security addendum, and other contractual obligations.

Functional Competencies:

  • Strong understanding of Third-Party Risk Management, including vendor lifecycle management, due diligence, risk assessments, evidence review, risk rating, remediation, and periodic reassessments.

  • Working knowledge of Information Security GRC, risk management, audits, and compliance management.

  • Familiarity with relevant standards and regulations, including ISO 27001, ISO 27701, ISO 42001, CSA STAR, TISAX, Cyber Essentials Plus, GDPR, DPDP, and HIPAA.

  • Understanding of AI governance, responsible AI, and AI risk/impact assessments.

  • Strong analytical, documentation, stakeholder management, communication, and follow-up skills.

  • Ability to manage multiple vendors, stakeholders, compliance activities, and deadlines with strong attention to detail.