Information Security Associate
Job description
About the role
You will own the entire information security function at Glomo, covering policy design, governance, risk management, and hands-on implementation across a regulated payments environment. You will serve as the internal authority on information security, driving maturity from foundational controls to advanced threat detection and compliance assurance. This role requires you to independently manage the full lifecycle of the Information Security Management System while interfacing directly with banking partners and regulators. You will translate complex regulatory expectations into operational controls that the business can execute without friction. You will act as the primary security strategist and operator, responsible for building resilient processes and technologies from the ground up. You will be the single point of accountability for information security outcomes across the organization.
Key facts
What you'll do
- Establish and own the Information Security Management System (ISMS), including policy framework, risk assessments, and control implementation aligned with ISO 27001, PCI DSS, and the IFSCA Cyber Security and Cyber Resilience Framework.
- Lead compliance with RBI outsourcing directions, IFSCA circulars, DPSC guidelines, and PCI SSF requirements applicable to payment service providers, ensuring audit-ready evidence and timely remediation.
- Own third-party risk management by conducting due diligence audits on all technology partners and maintaining records per regulatory and internal requirements.
- Drive the internal IT audit program, planning assessments, engaging external audit vendors, and tracking findings to closure while improving audit coverage and efficiency.
- Establish the Information Classification framework and embed it into DLP rules, employee training, and day-to-day operations to ensure data handling matches risk and regulatory obligations.
- Build and manage the Security Operations Center function, starting with MDR-augmented operations using CrowdStrike and progressively maturing toward hybrid in-house and outsourced capabilities.
- Own the SIEM strategy by integrating and monitoring all critical log sources, including applications, infrastructure, databases, identity, and privileged access management, and by building measurable detection use-cases.
- Conduct threat modeling exercises across the technology stack and payment flows to identify, rank, and mitigate risks before they impact customers or regulators.
- Manage Privileged Access Management at scale, including session monitoring, automated password rotation, break-glass procedures, and periodic user access reviews for privileged accounts.
- Implement and manage Data Loss Prevention controls across endpoints, email, and cloud storage such as Google Workspace DLP and CrowdStrike Device Control to prevent unauthorized data exfiltration.
- Own endpoint security by defining hardening SOPs against CIS benchmarks, maintaining approved software lists, and enforcing full disk encryption and related configuration standards.
- Drive network security posture through geo-fencing, firewall rule reviews, and Cloud IDS tuning across GCP infrastructure to reduce exposure and detect suspicious traffic patterns.
- Oversee application security by integrating SAST and DAST into CI/CD pipelines, defining security review thresholds, and managing OWASP compliance across customer and internal applications.
- Own the incident management lifecycle, including severity classifications, closure SLAs, escalation procedures, post-incident reviews, and the establishment of a dedicated security incident reporting channel.
- Maintain and test the Business Continuity Plan for scenarios such as office unavailability, power failure, pandemic, and cloud provider disruption, ensuring DR drills meet defined RTO thresholds with appropriate segregation of duties.
- Serve as the primary point of contact during security incidents, coordinating response with banking partners and regulators in accordance with notification SLAs and regulatory timelines.
- Act as the primary security interface with banking partners, managing their Third Party Service provider Risk Assessments and ensuring consistent, high-quality security evidence.
- Build the "Managed Security Transparency" program, producing scoped security reports, alert forwarding, incident summaries, and independent attestation for regulated entity partners.
- Coordinate with IFSCA, external auditors, and banking partner audit teams during inspections and certifications, ensuring timely responses and technically sound justifications.
- Drive the SOC 2 Type II certification journey and maintain independent attestations such as ISO 27001 and PCI DSS through continuous control monitoring and evidence collection.
- Build and maintain a compliance resource center that houses audit reports, certifications, and security documentation for on-demand partner due diligence.
Requirements
- Bring 4 years of information security experience with at least 3 years in a hands-on security role, preferably within regulated financial services such as fintech, banking, NBFC, or payment processors.
- Demonstrate full ownership of the InfoSec program, including GRC and Security Function responsibilities, with a track record of delivering measurable security outcomes independently.
- Show deep working knowledge of PCI DSS, ISO 27001, SOC 2, and Indian financial regulatory frameworks enforced by RBI and IFSCA, including control interpretation and audit readiness.
- Possess hands-on experience with cloud security on Google Cloud Platform, with strong preference for proven implementation in production environments.
- Have direct experience on both sides of third-party security assessments, having undergone audits as a vendor and conducted audits of third-party providers.
- Show practical expertise in Privileged Access Management, SIEM platforms, Data Loss Prevention, endpoint hardening, and network security controls.
- Hold firm on essential security non-negotiables while remaining pragmatic when balancing security requirements against business velocity and constraints.
- Produce clean, precise policy documents, audit responses, regulatory submissions, and technical artifacts that withstand scrutiny from regulators and expert reviewers.
- Thrive in a fast-paced startup environment where security is treated as a competitive advantage rather than a compliance overhead, working effectively with minimal direct supervision.
- Demonstrate high integrity, given access to the most sensitive systems, data, and strategic partner relationships, with consistent judgment under pressure.
- Possess the ability to understand, challenge, and justify technical and regulatory decisions during audits and assessments with clear, logical reasoning.
Nice to have
- Preferred exposure to managed security service providers and security awareness training platforms.
- Familiarity with security architecture for payment processing systems and fraud detection workflows.
Practical notes
- This is a full-time position based at the Bengaluru headquarters.
- The role may require travel to meet banking partners, regulators, and audit teams as well as occasional attendance at industry conferences.
- Candidates must be eligible to work in India without visa sponsorship for this role.
- The position reports directly to the Head of Information Security and operates within a structured yet agile compliance environment.