As a member of the Information Security Team at Glomopay, you will own the entire information security
function — from policy and governance to hands-on implementation and regulatory compliance. Reporting
directly to the Head of Information Security, this is a strategic role for a security practitioner who can single-handedly stand up a mature InfoSec program for Glomo
Key Responsibilities
Security Governance & Compliance
Own the Information Security Management System (ISMS) — policy framework, risk assessments and control implementation aligned with ISO 27001, PCI DSS, and IFSCA Cyber Security and
Cyber Resilience Framework
Lead compliance with RBI outsourcing directions, IFSCA circulars, DPSC guidelines, and PCI SSF requirements applicable to payment service providers
Own third-party risk management — conduct due diligence audits on all technology partners and maintain records per regulatory requirements
Drive the internal IT audit program — plan, execute, engage external audit vendors, and track findings to closure
Establish the Information Classification framework, embedding it into DLP rules, employee training, and daily operations
Security Operations & Architecture (Hands-On)
Build and manage the SOC function — starting with MDR-augmented operations (CrowdStrike), progressively maturing toward hybrid capability
Own the SIEM strategy: integrate and monitor all critical log sources (application, infrastructure, database, identity, PAM) and build detection use-cases
Conduct threat modelling Manage Privileged Access Management (PAM) — session monitoring, password rotation,break-glass procedures, periodic user access reviews
Implement and manage DLP controls across endpoints, email, and cloud storage (Google Workspace DLP, CrowdStrike Device Control)
Own endpoint security — hardening SOPs against CIS benchmarks, approved software lists, full disk encryption
Drive network security posture — geo-fencing, firewall rule reviews, Cloud IDS tuning across GCP infrastructure
Oversee application security — integrate SAST/DAST into CI/CD pipelines, define security review thresholds, manage OWASP compliance
Incident Management & Business Continuity
Own the incident management lifecycle — severity classifications, closure SLAs, escalation
procedures, post-incident reviews
Establish a dedicated security incident reporting channel and ensure organization-wide awareness
Maintain and test the Business Continuity Plan covering office unavailability, power failure,
pandemic, and cloud provider disruption scenarios
Ensure DR drills meet RTO thresholds with proper segregation of duties
Serve as the primary point of contact during security incidents, coordinating response with banking partners and regulators per notification SLAs
Regulatory & Partner Interface
Serve as the primary security interface with banking partners, managing their Third Party Service provider Risk Assessments
Build the “Managed Security Transparency” program — scoped security reports, alert forwarding, incident summaries, and independent attestation for regulated entity partners
Coordinate with IFSCA, external auditors, and banking partner audit teams during inspections and certifications
Drive the SOC 2 Type II certification journey and maintain independent attestations (ISO 27001, PCI DSS)
Build and maintain a compliance resource center — audit reports, certifications, security
documentation available for partner due diligence on demand
What We're Looking For
Experience: 4 years in information security with at least 3 years in a hands-on security role, preferably in regulated financial services (fintech, banking, NBFC, payment processors)
Core Expertise:
Be part of the InfoSec program from the early stage, understand the GRC as well as the Security Function.
Deep working knowledge of PCI DSS, ISO 27001, SOC 2, and Indian financial regulatory frameworks (RBI, IFSCA)
Hands-on with experience with cloud security on GCP (strongly preferred) or AWS/Azure
Experience on both sides of third-party security assessments — being audited and auditing vendors
Practical expertise in PAM, SIEM, DLP, endpoint hardening, and network security.
The Right Person For This Role:
You should be able to make sense of SIEM detection rules and alerts and configure the same as well
Translates regulatory requirements into practical controls without over-engineering
Holds firm on security non-negotiables while being pragmatic with business constraints
Writes clean policy documents, audit responses, and regulatory submissions
Thrives solo in a fast-paced startup where compliance is a competitive advantage, not overhead
High integrity — this role has access to the most sensitive systems, data, and partner relationships
Ability to handle audits and provide right and logical justifications where appropriate.
Why Join Glomopay?
Direct Impact: Report directly to the Head of Information Security. Shape the security foundation of India's first IFSCA-authorized PSP, your actions and decisions define the ecosystem.
Full Ownership: You will be instrumental in building the entire security program and be a part of the team from scratch. No inherited mess, no bureaucracy — This gives you an opportunity to define the culture from scratch.
Regulatory Pioneer: You will help define the InfoSec playbook at the intersection of IFSCA, RBI, and global card network requirements.
Modern Stack: GCP, Terraform IaC, CrowdStrike, Teleport PAM — cloud-native infrastructure, not legacy systems.
Strategic Moat: Your security program becomes the reason banking partners choose Glomopay. Security here is a revenue enabler, not a cost center.
