Head of Information Security

Posted Yesterday
Be an Early Applicant
Bengaluru, Karnataka, IND
In-Office
Expert/Leader
Fintech • Payments • Software • Financial Services
The Role
Own Vegapay’s organization-wide information security strategy, architecture, compliance, threat detection, incident response, and security automation. Build and lead the security team, strengthen identity and endpoint security, integrate DevSecOps across infrastructure and applications, and manage AWS security, vulnerability management, audits, regulators, and enterprise stakeholders. The role combines hands-on execution with strategic leadership in a regulated fintech environment.
Summary Generated by Built In
The Impact You'll Drive
We're looking for a Head of Information Security to own and scale Vegapay's end-to-end security posture across infrastructure, applications, and DevOps pipelines. You will set the security vision and strategy, build and lead a high-performing security team, drive compliance across global standards, and build robust systems to proactively detect, prevent, and respond to threats in a highly regulated fintech environment. This is a leadership role reporting into senior engineering/executive leadership, with direct accountability for the organization's security posture at a strategic and operational level.

The Hats You Will Wear
  • Define and own Vegapay's security strategy, roadmap, and architecture across infrastructure, applications, and data
  • Build, mentor, and lead a team of security engineers and analysts, establishing clear ownership and growth paths
  • Own and strengthen identity, access, and endpoint security across the organization (SSO, MFA, RBAC, least privilege, device controls)
  • Lead infrastructure and application security, including vulnerability assessments, penetration testing, secure coding practices, and DevSecOps integration across CI/CD pipelines
  • Build and operate real-time threat detection and response systems across cloud and endpoints, ensuring robust monitoring, alerting, and data protection standards
  • Design and scale security automation, including SIEM, incident response playbooks, and integrated alerting workflows across systems
  • Own end-to-end compliance across PCI DSS, ISO 27001, SOC 2, and CICRA, including audit readiness, risk management, and continuous compliance monitoring
  • Act as the primary point of contact for security matters with auditors, regulators, banking/NBFC partners, and enterprise customers
  • Lead security awareness initiatives, including phishing simulations and strengthening defenses against social engineering threats
  • Partner with engineering, product, and leadership to embed security into the culture and roadmap of the organization

The Perfect Fit
  • 10+ years of experience in information security, with at least 3-5 years in a leadership or team-management capacity
  • Strong experience with security tooling across SIEM, DevSecOps, cloud security, and vulnerability management
  • Hands-on expertise with AWS security ecosystem, IAM hardening, and infrastructure security
  • Proficiency in scripting (Python, Bash) and securing IaC (Terraform, Ansible)
  • Deep understanding of modern security frameworks and threat models (OWASP, MITRE ATT&CK, CIS)
  • Proven experience owning compliance programs for global security standards, including direct engagement with auditors and regulators
  • Demonstrated ability to build and scale a security function and team from the ground up
  • Ability to balance hands-on execution with strategic, org-wide ownership
Your Edge Over the Rest
  • Certifications like CISSP, OSCP, CISA, CEH, or CCSP
  • Experience in FinTech, SaaS, or regulated environments, ideally at leadership level
  • Prior experience as a Head of Security, CISO, or similar senior security leadership role
  • Strong stakeholder management and cross-functional collaboration skills, including with executive leadership and external regulators

The Problem We’re Solving
Financial institutions today are held back by legacy systems that are slow, rigid, and expensive to scale. Launching or evolving credit, lending, and UPI products often takes months, requires heavy engineering effort, and limits the ability to create personalized customer experiences.

At the same time, customer expectations have changed - speed, flexibility, and tailored financial products are no longer optional. Banks and fintechs need infrastructure that allows them to innovate quickly, adapt continuously, and scale without friction.

This is where we come in.

At Vegapay, we are building modern, configurable fintech infrastructure that enables banks, NBFCs, and enterprises to design, launch, and manage credit and payment programs with ease. Our platform brings together flexibility, speed, and control - helping our partners unlock new growth opportunities and deliver personalized banking experiences at scale.

The Opportunity Ahead
  • Play a pivotal role in defining and owning Vegapay's security architecture and practices as we build a category-defining fintech infrastructure company
  • Own security at a strategic, organization-wide level
  • Operate at the intersection of scale and regulation
  • Build, shape, and lead a high-performing security team
  • High ownership, high accountability environment with direct visibility to leadership

Skills Required

  • 10+ years of experience in information security
  • 3-5 years of leadership or team-management experience
  • Strong experience with SIEM, DevSecOps, cloud security, and vulnerability management tooling
  • Hands-on expertise with AWS security, IAM hardening, and infrastructure security
  • Proficiency in Python and Bash scripting
  • Experience securing infrastructure as code using Terraform and Ansible
  • Deep understanding of OWASP, MITRE ATT&CK, CIS, and modern threat models
  • Experience owning compliance programs for PCI DSS, ISO 27001, SOC 2, and CICRA
  • Demonstrated ability to build and scale a security function and team
  • CISSP, OSCP, CISA, CEH, or CCSP certification
  • Experience in FinTech, SaaS, or regulated environments
  • Prior experience as Head of Security, CISO, or similar senior security leader
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
60 Employees
Year Founded: 2022

What We Do

Vegapay is an Indian B2B fintech company providing software and tools for banks, NBFCs, and other financial institutions. It helps institutions launch flexible card and credit programs and modernize lending operations through a scalable, rapid-deployment platform. Its mission is to make personalized banking experiences and financial innovation more accessible regardless of institution size, while addressing the cost and implementation constraints of legacy systems.

Similar Jobs

Adyen Logo Adyen

Software Engineer

Fintech • Payments • Financial Services
Easy Apply
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
4771 Employees

LogicMonitor Logo LogicMonitor

Edwin GTM Engineer

Artificial Intelligence • Cloud • Information Technology • Machine Learning • Software
Easy Apply
Hybrid
Bangalore, Bengaluru Urban, Karnataka, IND
1100 Employees

Zscaler Logo Zscaler

Consultant

Cloud • Information Technology • Security • Software • Cybersecurity
Easy Apply
Hybrid
Bangalore, Bengaluru, Karnataka, IND
8697 Employees

ServiceNow Logo ServiceNow

Staff Software Engineer

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Hybrid
Bangalore, Bengaluru, Karnataka, IND
29000 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account