- Development, implementation, and management of security policies, standards, guidelines, and procedures to ensure the ongoing improvement and maintenance of security posture in line with ISO 27001, SOC2 Type 2, PCI DSS etc.,
- Understand technical implementation details necessary to assess general and situational Information Security risk.
- Coordinate with multiple teams across the organization for the Audits
- Lead the Third Party Risk Management audits conducted by Banks and other Authorities
- Closely interact and work with Clients[Banks, Fintechs etc] in ensuring smooth audit process and TPRM
- Coordinate internal and external audits, ensuring timely collection of artifacts and responses.
- Manage the end-to-end vendor/partner onboarding risk process - due diligence, risk assessment, contract compliance, and continuous monitoring.
- Maintain and improve the enterprise GRC framework aligned to ISO 27001/27701, SOC 2, PCI-DSS
- Support risk assessments (operational, cyber, privacy) and maintain risk registers.
- Design, implement, maintain, and improve programs to address key company risks and prepare internal teams for independent assessments against a wide variety of regulatory and compliance frameworks.
- Demonstrated experience with common compliance frameworks (SOX, GDPR, CCPA, PCI, ISO27000, NIST Cybersecurity Framework, NIST SP800-53)
- Understanding of security best practices (Password security, device security etc) in the context of Security Training and Awareness
- Conduct internal control testing and compliance reviews across infrastructure, applications, and processes.
- Establishing appropriate levels of security controls, systems monitoring, and security audits.
- Assisting in the security engineering team with prioritizing patches and security fixes.
- Improve controls for internal systems, processes, and policies.
- Support the execution of multiple audit programs internally and externally.
- Provide clear expectations and direction to security and engineering teams on audit requirements.
- 3+ years of proven experience in information security, audit, compliance, risk assessment, and management.
- Hands-on experience in managing and driving security compliance mainly ISO 27001, PCI DSS, Data Localization and Bank Audits
- Ability to prioritise, manage, and deliver on multiple projects simultaneously and partner with management in support of key initiatives and projects.
- Knowledge of pragmatic security controls across all security domains such as access management, encryption methods, vulnerability management, network security, etc.
- Experience developing and producing security metrics and reports that are meaningful and actionable across various audiences.
- In-depth understanding of the regulatory requirements and trends in the FinTech domain.
- Ability to communicate to management, technical, and non-technical persons about the risk associated with the business.
- Defining and maintaining the policies as per ISMS framework
- Monitor third-party risk assessments and assist in performing internal risk assessments.
- Certifications such as ISO27001 Lead Auditor/Implementer
- CISA/CISM certification would be a plus
- Ability to use basic automation/scripting (Python, SQL) for evidence collection.
- Experience with SIEM/SOC outputs to validate alerts as audit evidence.
- Knowledge of data governance/DLP tools.
- Awareness of AI/ML governance and evolving regulatory frameworks.
- Skills in continuous compliance (CI/CD, IaC scanning).
- Well-versed with data security and data privacy.
- Strong team player, but can work and execute independently
- Brilliant written, verbal communication, and interpersonal skills
Skills Required
- 3+ years of proven experience in information security, audit, compliance, risk assessment, and management.
- Hands-on experience in managing and driving security compliance (ISO 27001, PCI DSS), data localization, and bank audits.
- Ability to prioritise, manage, and deliver on multiple projects and partner with management on key initiatives.
- Knowledge of pragmatic security controls across domains: access management, encryption, vulnerability management, network security.
- Experience developing and producing meaningful, actionable security metrics and reports for varied audiences.
- In-depth understanding of regulatory requirements and trends in the FinTech domain.
- Ability to communicate risk to management, technical, and non-technical stakeholders.
- Defining and maintaining policies as per ISMS framework.
- Monitor third-party risk assessments and assist in performing internal risk assessments.
- ISO27001 Lead Auditor/Implementer certification.
- CISA or CISM certification.
- Ability to use basic automation/scripting (Python, SQL) for evidence collection.
- Experience using SIEM/SOC outputs to validate alerts as audit evidence.
- Knowledge of data governance and DLP tools.
- Awareness of AI/ML governance and evolving regulatory frameworks.
- Skills in continuous compliance (CI/CD, IaC scanning).
- Well-versed with data security and data privacy.
- Strong team player who can also work independently; excellent written and verbal communication skills.
What We Do
Signzy is a market-leading platform that is redefining the speed, accuracy, and experience of how financial institutions are onboarding customers and businesses - using the digital medium. The company’s award-winning no-code GO platform delivers seamless, end-to-end, and multi-channel onboarding journeys while offering totally customizable workflows. It gives these players access to an aggregated marketplace of 240+ bespoke APIs that can be easily added to any workflow with simple widgets. Signzy is enabling 10 million+ end customer and business onboardings every month at a success rate of 99% while reducing the speed to market from 6 months to 3-4 weeks. It works with over 240+ FIs globally including the 4 largest banks in India, a Top 3 acquiring Bank in the US, and has a strong global partnership with Mastercard and Microsoft. The company’s product team is based out of Bengaluru and it has a strong presence in Mumbai, New York, and Dubai.







