Skip to main content
Shubham MandalSM
Looking for a job

Shubham Mandal

@shubhammandal

GRC Analyst at EpiFi Technologies (Fi Money), managing regulatory audits and security assessments across fintech products.

India
Message

At EpiFi Technologies (Fi Money), I lead regulatory, statutory, and partner audits, including PSP, CIBIL, NPCI TPAP, PCI DSS, and DigiLocker audits. I also manage vendor risk assessments across business units.

I drive ongoing information security work, including access reviews, phishing simulations, SAST testing, and risk register reviews. I coordinate third-party penetration testing and source code reviews, then work with DevOps on patch fixes and validation.

Previously, I worked across GRC and information security roles at BrokenTusk Technologies (Setu), Juspay Technologies (JUSPAY), CyberCube Services (CyberCube), and Riversys Technologies (Scrut Automation). My work included regulatory compliance, security audits, risk assessments, and audit readiness across frameworks such as ISO 27001, SOC 2, PCI DSS, and HIPAA.

Experience

Work history, roles, and key accomplishments

EM
Current

Senior Analyst GRC

EpiFi Technologies (Fi Money)

Sep 2025 - Present (1 year 1 month)

Led and managed a wide range of regulatory, statutory, and partner audits, including PSP, CIBIL, NPCI TPAP, PCI DSS, DL SAR, DigiLocker, and OPV audits. Drove internal InfoSec activities including DLP, AV rule reviews, TPRMs, user access reviews, phishing simulations, SAST testing, and security awareness training.

BS

Associate - Audit & InfoSec

BrokenTusk Technologies (Setu)

Jun 2025 - Aug 2025 (2 months)

Planned and executed process-led internal, external, and Third-Party/Vendor Risk Assessments (TPRMs) for new product launches and partner integrations. Conducted quarterly user access reviews across critical environments including AWS IAM to validate least-privilege access.

JJ

GRC Analyst

Juspay Technologies (JUSPAY)

Jul 2024 - May 2025 (10 months)

Ensured organization-wide and platform-level compliance across multiple critical technology stacks in alignment with regulatory frameworks such as ISO/IEC 27001, SOC 2, RBI DL SAR, RBI CoFT, PCI DSS, and PCI 3DS. Executed quarterly internal security audits and program-managed 30+ statutory, regulatory, and TPRM assessments.

CC

Security Analyst

CyberCube Services (CyberCube)

Feb 2024 - Jun 2024 (4 months)

Performed independent third-party information security and compliance audits, including PCI DSS v4.0, ISO/IEC 27001:2022, SOC 2, and RBI DL SAR for 10+ external clients. Conducted gap assessments and maintained comprehensive audit evidence repositories.

RA

InfoSec Analyst Intern

Riversys Technologies (Scrut Automation)

Oct 2023 - Jan 2024 (3 months)

Led and executed end-to-end security and compliance audits for 12 US-based startups across ISO 27001, SOC 2, and HIPAA. Managed the complete audit lifecycle using Scrut Automation's GRC platform.

Education

Degrees, certifications, and relevant coursework

AU

Alliance University

Bachelor of Technology, Electronics & Communication Engineering

2013 - 2017

Pursued a Bachelor of Technology in Electronics & Communication Engineering.

Interested in hiring Shubham?

You can contact Shubham and 90k+ other talented remote workers on Himalayas.

Message Shubham

People also viewed

View all talent

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan