As a member of the Information Security Team at Glomopay, you will own the entire information security
function — from policy and governance to hands-on implementation and regulatory compliance. Reporting
directly to the Head of Information Security, this is a strategic role for a security practitioner who can single-handedly stand up a mature InfoSec program for Glomo
Key Responsibilities
Security Governance & Compliance
- Own the Information Security Management System (ISMS) — policy framework, risk assessments and control implementation aligned with ISO 27001, PCI DSS, and IFSCA Cyber Security and
- Cyber Resilience Framework
- Lead compliance with RBI outsourcing directions, IFSCA circulars, DPSC guidelines, and PCI SSF requirements applicable to payment service providers
- Own third-party risk management — conduct due diligence audits on all technology partners and maintain records per regulatory requirements
- Drive the internal IT audit program — plan, execute, engage external audit vendors, and track findings to closure
- Establish the Information Classification framework, embedding it into DLP rules, employee training, and daily operations
Security Operations & Architecture (Hands-On)
- Build and manage the SOC function — starting with MDR-augmented operations (CrowdStrike), progressively maturing toward hybrid capability
- Own the SIEM strategy: integrate and monitor all critical log sources (application, infrastructure, database, identity, PAM) and build detection use-cases
- Conduct threat modelling Manage Privileged Access Management (PAM) — session monitoring, password rotation,break-glass procedures, periodic user access reviews
- Implement and manage DLP controls across endpoints, email, and cloud storage (Google Workspace DLP, CrowdStrike Device Control)
- Own endpoint security — hardening SOPs against CIS benchmarks, approved software lists, full disk encryption
- Drive network security posture — geo-fencing, firewall rule reviews, Cloud IDS tuning across GCP infrastructure
- Oversee application security — integrate SAST/DAST into CI/CD pipelines, define security review thresholds, manage OWASP compliance
Incident Management & Business Continuity
- Own the incident management lifecycle — severity classifications, closure SLAs, escalation
- procedures, post-incident reviews
- Establish a dedicated security incident reporting channel and ensure organization-wide awareness
- Maintain and test the Business Continuity Plan covering office unavailability, power failure,
- pandemic, and cloud provider disruption scenarios
- Ensure DR drills meet RTO thresholds with proper segregation of duties
- Serve as the primary point of contact during security incidents, coordinating response with banking partners and regulators per notification SLAs
Regulatory & Partner Interface
- Serve as the primary security interface with banking partners, managing their Third Party Service provider Risk Assessments
- Build the “Managed Security Transparency” program — scoped security reports, alert forwarding, incident summaries, and independent attestation for regulated entity partners
- Coordinate with IFSCA, external auditors, and banking partner audit teams during inspections and certifications
- Drive the SOC 2 Type II certification journey and maintain independent attestations (ISO 27001, PCI DSS)
- Build and maintain a compliance resource center — audit reports, certifications, security
- documentation available for partner due diligence on demand
What We're Looking For
Experience: 4 years in information security with at least 3 years in a hands-on security role, preferably in regulated financial services (fintech, banking, NBFC, payment processors)
Core Expertise:
- Be part of the InfoSec program from the early stage, understand the GRC as well as the Security Function.
- Deep working knowledge of PCI DSS, ISO 27001, SOC 2, and Indian financial regulatory frameworks (RBI, IFSCA)
- Hands-on with experience with cloud security on GCP (strongly preferred) or AWS/Azure
- Experience on both sides of third-party security assessments — being audited and auditing vendors
- Practical expertise in PAM, SIEM, DLP, endpoint hardening, and network security.
The Right Person For This Role:
- You should be able to make sense of SIEM detection rules and alerts and configure the same as well
- Translates regulatory requirements into practical controls without over-engineering
- Holds firm on security non-negotiables while being pragmatic with business constraints
- Writes clean policy documents, audit responses, and regulatory submissions
- Thrives solo in a fast-paced startup where compliance is a competitive advantage, not overhead
- High integrity — this role has access to the most sensitive systems, data, and partner relationships
- Ability to handle audits and provide right and logical justifications where appropriate.
Why Join Glomopay?
- Direct Impact: Report directly to the Head of Information Security. Shape the security foundation of India's first IFSCA-authorized PSP, your actions and decisions define the ecosystem.
- Full Ownership: You will be instrumental in building the entire security program and be a part of the team from scratch. No inherited mess, no bureaucracy — This gives you an opportunity to define the culture from scratch.
- Regulatory Pioneer: You will help define the InfoSec playbook at the intersection of IFSCA, RBI, and global card network requirements.
- Modern Stack: GCP, Terraform IaC, CrowdStrike, Teleport PAM — cloud-native infrastructure, not legacy systems.
- Strategic Moat: Your security program becomes the reason banking partners choose Glomopay. Security here is a revenue enabler, not a cost center.