Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Information Security Associate

Glomo
CompanyGlomo
CategorySecurity
LocationBengaluru
RemoteOn-site (inferred)
EmploymentNot stated
LevelNot stated
SalaryNot stated by the employer
Posted11 Aug 2026
Last verified11 Aug 2026
SourceEmployer ATS (ashby)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
As a member of the Information Security Team at Glomopay, you will own the entire information security function — from policy and governance to hands-on implementation and regulatory compliance. Reporting directly to the Head of Information Security, this is a strategic role for a security practitioner who can single-handedly stand up a mature InfoSec program for Glomo Key Responsibilities Security Governance & Compliance - Own the Information Security Management System (ISMS) — policy framework, risk assessments and control implementation aligned with ISO 27001, PCI DSS, and IFSCA Cyber Security and - Cyber Resilience Framework - Lead compliance with RBI outsourcing directions, IFSCA circulars, DPSC guidelines, and PCI SSF requirements applicable to payment service providers - Own third-party risk management — conduct due diligence audits on all technology partners and maintain records per regulatory requirements - Drive the internal IT audit program — plan, execute, engage external audit vendors, and track findings to closure - Establish the Information Classification framework, embedding it into DLP rules, employee training, and daily operations Security Operations & Architecture (Hands-On) - Build and manage the SOC function — starting with MDR-augmented operations (CrowdStrike), progressively maturing toward hybrid capability - Own the SIEM strategy: integrate and monitor all critical log sources (application, infrastructure, database, identity, PAM) and build detection use-cases - Conduct threat modelling Manage Privileged Access Management (PAM) — session monitoring, password rotation,break-glass procedures, periodic user access reviews - Implement and manage DLP controls across endpoints, email, and cloud storage (Google Workspace DLP, CrowdStrike Device Control) - Own endpoint security — hardening SOPs against CIS benchmarks, approved software lists, full disk encryption - Drive network security posture — geo-fencing, firewall rule reviews, Cloud IDS tuning across GCP infrastructure - Oversee application security — integrate SAST/DAST into CI/CD pipelines, define security review thresholds, manage OWASP compliance Incident Management & Business Continuity - Own the incident management lifecycle — severity classifications, closure SLAs, escalation - procedures, post-incident reviews - Establish a dedicated security incident reporting channel and ensure organization-wide awareness - Maintain and test the Business Continuity Plan covering office unavailability, power failure, - pandemic, and cloud provider disruption scenarios - Ensure DR drills meet RTO thresholds with proper segregation of duties - Serve as the primary point of contact during security incidents, coordinating response with banking partners and regulators per notification SLAs Regulatory & Partner Interface - Serve as the primary security interface with banking partners, managing their Third Party Service provider Risk Assessments - Build the “Managed Security Transparency” program — scoped security reports, alert forwarding, incident summaries, and independent attestation for regulated entity partners - Coordinate with IFSCA, external auditors, and banking partner audit teams during inspections and certifications - Drive the SOC 2 Type II certification journey and maintain independent attestations (ISO 27001, PCI DSS) - Build and maintain a compliance resource center — audit reports, certifications, security - documentation available for partner due diligence on demand What We're Looking For Experience: 4 years in information security with at least 3 years in a hands-on security role, preferably in regulated financial services (fintech, banking, NBFC, payment processors) Core Expertise: - Be part of the InfoSec program from the early stage, understand the GRC as well as the Security Function. - Deep working knowledge of PCI DSS, ISO 27001, SOC 2, and Indian fin