The Role
Own and advance Vegapay’s security program across application, cloud, operations, and compliance. Lead VAPT and secure design reviews, harden cloud and container environments, operate detection and incident response, and support PCI DSS, ISO 27001, SOC 2, and other audits. Mentor security staff, establish technical standards, review architectures and code, manage security risks, and partner with engineering, product, and regulated financial-services stakeholders.
Summary Generated by Built In
The Impact You’ll Drive
We're looking for an experienced GRC professional to build and scale our governance, risk, and compliance function. As a fintech infrastructure provider processing sensitive financial data on behalf of banks and NBFCs, we operate under significant regulatory scrutiny - this role will own the frameworks, certifications, and controls that keep Vegapay compliant, secure, and trusted by our regulated BFSI partners. You’ll work closely with Security, Engineering, Legal, Product, and leadership to embed governance and risk management into how we build and operate, while being the primary point of contact for client and auditor assurance.
The Hats You Will Wear
Governance & Policy Management
- Design, implement, and maintain information security and compliance policies, standards, and procedures aligned to ISO 27001, SOC 2, PCI-DSS, and RBI guidelines
- Establish and run governance forums (risk council, policy reviews) with leadership and cross-functional stakeholders
- Own and maintain the organization’s risk register, control framework, and compliance calendar
- Conduct periodic enterprise and IT risk assessments, identifying gaps and driving remediation with process and engineering owners
- Define and track key risk indicators (KRIs) and key control indicators (KCIs) across the business
- Support risk-based decision-making for new products, partnerships, and vendor relationships
Risk Management
- Ensure ongoing compliance with RBI guidelines, payment ecosystem regulations (NPCI, card network mandates), and data protection requirements including the DPDPA
- Track regulatory and industry changes impacting fintech/BFSI operations and translate them into actionable requirements
- Liaise with regulators, external auditors, and banking/NBFC partners on compliance matters as needed
- Own and coordinate RBI-related audits and regulatory inspections, including evidence submission, query resolution, and remediation tracking
Information Security Compliance & Audits
- Own end-to-end delivery of ISO 27001, SOC 2 Type II, PCI-DSS, and other certification audits — including evidence collection, auditor coordination, and remediation tracking
- Partner with Engineering and Security to embed controls into product and infrastructure design
- Drive closure of audit findings and monitor control effectiveness over time
Vendor & Third-Party Risk Management
- Design and operate a vendor/third-party risk assessment program covering onboarding due diligence, periodic reviews, and offboarding
- Review vendor contracts and SLAs for risk, security, and compliance clauses in partnership with Legal
Client & Stakeholder Assurance
- Respond to security and compliance due-diligence questionnaires and audits from banking and NBFC clients
- Represent Vegapay’s GRC posture in client and partner conversations, building trust with regulated BFSI customers
- Prepare compliance dashboards, risk reports, and leadership/board updates
The Perfect Fit
- Bachelor’s degree in Engineering, Technology, Business, or a related field; advanced degree is a plus
- 6–8 years of experience in Governance, Risk & Compliance, Information Security Compliance, IT Audit, or related roles — preferably within fintech, BFSI, SaaS, or payments
- Hands-on experience implementing and managing ISO 27001, SOC 2, and PCI-DSS programs, including leading external audits to closure
- Working knowledge of RBI regulations, payment ecosystem guidelines, and data protection laws (DPDPA/GDPR)
- Experience building and operating vendor/third-party risk management programs
- Strong stakeholder management skills, with the ability to work across Security, Engineering, Legal, and business teams
- Excellent written and verbal communication skills, including policy writing and executive-level reporting
Your Edge Over the Rest
- Professional certifications such as CISA, CRISC, CISSP, CISM, or ISO 27001 Lead Auditor/Implementer
- Prior experience in a regulated financial services, payments, or banking technology environment
- Exposure to cloud security governance (AWS/GCP) and DevSecOps practices
- Experience setting up or scaling a GRC function from the ground up in a startup environment
- Familiarity with GRC tooling and compliance automation platforms
The Problem We’re Solving
Financial institutions today are held back by legacy systems that are slow, rigid, and expensive to scale. Launching or evolving credit, lending, and UPI products often takes months, requires heavy engineering effort, and limits the ability to create personalized customer experiences.
At the same time, customer expectations have changed - speed, flexibility, and tailored financial products are no longer optional. Banks and fintechs need infrastructure that allows them to innovate quickly, adapt continuously, and scale without friction.
This is where we come in.
At Vegapay, we are building modern, configurable fintech infrastructure that enables banks, NBFCs, and enterprises to design, launch, and manage credit and payment programs with ease. Our platform brings together flexibility, speed, and control - helping our partners unlock new growth opportunities and deliver personalized banking experiences at scale.
The Opportunity Ahead
- Lead and shape high-impact engineering teams building real-world fintech infrastructure
- Drive both technical direction and team growth - with real ownership and decision-making authority
- Work on complex, scalable systems that directly power banking, credit, and payments
- Collaborate with strong product and leadership teams in a fast-moving, execution-first environment
Skills Required
- 6+ years of experience in information security
- Depth in at least two areas: application security, cloud security, security operations, or GRC
- Hands-on VAPT experience across web, mobile, API, and network environments
- Ability to identify and exploit complex business-logic vulnerabilities
- Knowledge of OWASP Top 10, MITRE ATT&CK, and CIS Benchmarks
- Proficiency with Burp Suite, OWASP ZAP, Metasploit, Nessus, Qualys, Snyk, SonarQube, Trivy, and Wazuh
- Experience with security monitoring, incident response, SIEM/XDR tools, detection tuning, and investigations
- Cloud security experience with AWS, GCP, or Azure
- Experience securing IAM, S3, load balancers, Kubernetes, and Docker
- Experience running or significantly contributing to PCI DSS, ISO 27001, SOC 2, CICRA, NIST, or RBI compliance programs
- Experience interacting directly with auditors
- Understanding of OAuth 2.0, OIDC, and SAML
- Ability to read and review Java code
- Ability to script in Python or Bash
- Familiarity with securing infrastructure as code using Terraform or Ansible
- Ability to communicate security risks to technical and non-technical stakeholders
- Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field
- Industry-recognized certification such as OSCP, CISSP, CISA, CEH, CCSP, or AWS Security Specialty
- Experience in FinTech, SaaS, or another regulated environment
- Experience with card, lending, or UPI systems
- Experience mentoring security engineers or leading multi-team security initiatives
- Exceptional communication and documentation skills
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Vegapay is an Indian B2B fintech company providing software and tools for banks, NBFCs, and other financial institutions. It helps institutions launch flexible card and credit programs and modernize lending operations through a scalable, rapid-deployment platform. Its mission is to make personalized banking experiences and financial innovation more accessible regardless of institution size, while addressing the cost and implementation constraints of legacy systems.
.png)






