Information Security Associate
Glomo
| Company | Glomo |
| Category | Security |
| Location | Bengaluru |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 11 Aug 2026 |
| Last verified | 11 Aug 2026 |
| Source | Employer ATS (ashby) |
Description
As a member of the Information Security Team at Glomopay, you will own the entire information security
function — from policy and governance to hands-on implementation and regulatory compliance. Reporting
directly to the Head of Information Security, this is a strategic role for a security practitioner who can single-handedly stand up a mature InfoSec program for Glomo
Key Responsibilities
Security Governance & Compliance
- Own the Information Security Management System (ISMS) — policy framework, risk assessments and control implementation aligned with ISO 27001, PCI DSS, and IFSCA Cyber Security and
- Cyber Resilience Framework
- Lead compliance with RBI outsourcing directions, IFSCA circulars, DPSC guidelines, and PCI SSF requirements applicable to payment service providers
- Own third-party risk management — conduct due diligence audits on all technology partners and maintain records per regulatory requirements
- Drive the internal IT audit program — plan, execute, engage external audit vendors, and track findings to closure
- Establish the Information Classification framework, embedding it into DLP rules, employee training, and daily operations
Security Operations & Architecture (Hands-On)
- Build and manage the SOC function — starting with MDR-augmented operations (CrowdStrike), progressively maturing toward hybrid capability
- Own the SIEM strategy: integrate and monitor all critical log sources (application, infrastructure, database, identity, PAM) and build detection use-cases
- Conduct threat modelling Manage Privileged Access Management (PAM) — session monitoring, password rotation,break-glass procedures, periodic user access reviews
- Implement and manage DLP controls across endpoints, email, and cloud storage (Google Workspace DLP, CrowdStrike Device Control)
- Own endpoint security — hardening SOPs against CIS benchmarks, approved software lists, full disk encryption
- Drive network security posture — geo-fencing, firewall rule reviews, Cloud IDS tuning across GCP infrastructure
- Oversee application security — integrate SAST/DAST into CI/CD pipelines, define security review thresholds, manage OWASP compliance
Incident Management & Business Continuity
- Own the incident management lifecycle — severity classifications, closure SLAs, escalation
- procedures, post-incident reviews
- Establish a dedicated security incident reporting channel and ensure organization-wide awareness
- Maintain and test the Business Continuity Plan covering office unavailability, power failure,
- pandemic, and cloud provider disruption scenarios
- Ensure DR drills meet RTO thresholds with proper segregation of duties
- Serve as the primary point of contact during security incidents, coordinating response with banking partners and regulators per notification SLAs
Regulatory & Partner Interface
- Serve as the primary security interface with banking partners, managing their Third Party Service provider Risk Assessments
- Build the “Managed Security Transparency” program — scoped security reports, alert forwarding, incident summaries, and independent attestation for regulated entity partners
- Coordinate with IFSCA, external auditors, and banking partner audit teams during inspections and certifications
- Drive the SOC 2 Type II certification journey and maintain independent attestations (ISO 27001, PCI DSS)
- Build and maintain a compliance resource center — audit reports, certifications, security
- documentation available for partner due diligence on demand
What We're Looking For
Experience: 4 years in information security with at least 3 years in a hands-on security role, preferably in regulated financial services (fintech, banking, NBFC, payment processors)
Core Expertise:
- Be part of the InfoSec program from the early stage, understand the GRC as well as the Security Function.
- Deep working knowledge of PCI DSS, ISO 27001, SOC 2, and Indian fin