Senior-AVP/ Information security at Rapidly growing fintech SaaS firm that propels business grow · Bangalore · 5 - 10 years · ₹15L - ₹30L / yr · Posted 1 Sep 2022

Senior-AVP/ Information security
at Rapidly growing fintech SaaS firm that propels business grow
What are we looking for?
An enthusiastic individual with the following skills. Please do not hesitate to apply if you do not match all of it. We are open to promising candidates who are passionate about their work and are team players.
Key Responsibilities & expectations from the candidate
- Must have strong experience in Information Security Management system(ISMS), creation of policy, procedures and implementation.
- Operates as a key contributor to the RFP, Third-Party Risk assessment, cloud security assessment etc.
- Lead the strategic and tactical development of information security framework, risk management and new compliance initiatives
- Subject matter expertise in ISO 27001, SOC2, CCPA, CPRA, GDPR, PCI DSS and HIPAA.
- Must have a strong experience in the documentation process and reviewing MSA, SCC, SLA & DPA.
- Good knowledge of BCP/DR, Incident response, VA/PT and Audit methodologies of various compliance frameworks.
- Good knowledge of Access management, Network, Application Security, Encryption, Backup, Physical Security, ISMS Training & Awareness etc..
- Ability to deal with the customers and vendors on Security and privacy matters.
- Knowledge of Core IT processes, SDLC, network infrastructure will be useful.
Personal Attributes
- Good written, oral, and interpersonal communication skills.
- Ability to conduct research into IT security issues
- Ability to present ideas in business-friendly and user-friendly language.
- Ability to effectively prioritize and execute tasks in a high-pressure environment.
- Highly self-motivated and hardworking.
Qualification and certification
- Bachelor’s/master's degree in Security, Computer Science, Management Information Systems, Engineering or related field.
- Should be at least ISO 27001 lead auditor or lead implementer.
- 3+ years of related work experience in information security governance, risk and compliance (GRC) or relevant compliance roles in the SaaS industry.
What can you look for?
A wholesome opportunity in a fast-paced environment that will enable you to juggle between concepts, yet maintain the quality of content, interact, and share your ideas and have loads of learning while at work. Work with a team of highly talented young professionals and enjoy the benefits of being here.
We are
It is a rapidly growing fintech SaaS firm that propels business growth while focusing on human motivation. Backed by Giift and Apis Partners Growth Fund II, Company offers a suite of three products - Plum, Empuls, and Compass. Company works with more than 2000 clients across 10+ countries and over 2.5 million users. Headquartered in Bengaluru, Company is a 300+ strong team with four global offices in San Francisco, Dublin, Singapore, New Delhi.
Way forward
We look forward to connecting with you. As you may take time to review this opportunity, we will wait for a reasonable time of around 3-5 days before we screen the collected applications and start lining up job discussions with the hiring manager. We however assure you that we will attempt to maintain a reasonable time window for successfully closing this requirement. The candidates will be kept informed and updated on the feedback and application status.

Similar jobs (3)
We are seeking an experienced Governance, Risk & Compliance (GRC) Lead to spearhead the
design, implementation, and maintenance of our ISO 27001 Information Security Management
System (ISMS). This is a hands-on leadership role responsible for establishing a robust security
governance framework, achieving ISO 27001 certification, and embedding a culture of
continuous security improvement across the organization.
Key Responsibilities
● ISMS Implementation & Certification: Lead end-to-end ISO 27001 implementation
from gap analysis through to successful Stage 1 and Stage 2 certification audits;
manage external auditor relationships
● Risk Management: Develop and operationalize the information security risk
management framework; conduct risk assessments, treatment planning, and risk
acceptance processes.
● Policy & Governance : Author, approve, and maintain the Statement of Applicability
(SoA), information security policies, standards, and procedures aligned with ISO 27001
Annex A controls.
● Control Implementation: Translate ISO 27001 Annex A controls into operational
security measures; coordinate with IT, Accounts, HR, Backoffice, and business units to
implement and validate controls.
● Compliance Monitoring: Establish continuous monitoring, internal audit programs, and
KPIs/KRIs to measure ISMS effectiveness; manage non-conformities and corrective
actions.
● Third-Party Risk: Oversee vendor security assessments and ensure supply chain
security controls meet organizational and ISO 27001 standards.
● Stakeholder Management: Report ISMS performance, risks, and compliance status to
senior leadership and the board; act as primary liaison for external auditors and
regulators.
Required Qualifications
● 5+ years of experience in information security governance, risk, and compliance
● Proven track record of leading at least one full ISO 27001:2022 certification cycle (gap
analysis → certification)
● Deep expertise in ISO 27001:2022 standard, Annex A controls, and ISMS
documentation requirements
● Strong understanding of risk assessment methodologies (e.g., ISO 27005, NIST RMF,
OCTAVE, FAIR)
● Familiarity with internal audit practices and managing external certification bodies
● Excellent stakeholder management and ability to influence across technical and non-
technical teams
● Strong documentation and communication skills — able to translate complex standards
into actionable guidance
Preferred Qualifications
● Experience implementing ISMS in fintech, healthcare, or regulated industries
● Experience with SOC 2, GDPR, NIST CSF, PCI-DSS, or other compliance frameworks
● Background in cloud security (AWS, Azure, GCP) and DevSecOps environments
● Knowledge of automation for compliance evidence collection and control testing
● Certifications: CISM, CRISC, CISA, ISO 27001 Lead Auditor, or ISO 27001 Lead
Implementer
Why Join Us
● Opportunity to build the security governance function from the ground up
● High-visibility role with direct impact on customer trust and market differentiation
● Collaborative environment that values security as a business enabler, not a blocker
Company Profile:
We are a one-stop financial services shop, widely known for quality of its advice, personalized
service and cutting-edge technology. We started our journey in 2008. Currently we are serving
more than 50,000 investors with a team of 100 members. Our core product offering is mutual
fund, FD, Govt. Bonds, Debenture, etc.
Job Summary
We are looking for a Senior Compliance Analyst to manage and support cybersecurity compliance, GRC, risk assessments, audits, and client engagements. The candidate will evaluate security controls, identify compliance gaps, review evidence, and provide practical recommendations.
Key Responsibilities
- Conduct Compliance Audits, Gap Assessments, and Risk Assessments.
- Assess controls against ISO 27001, SOC 2, PCI DSS, ISO 27701, ISO 42001, HIPAA, GDPR, DPDP, etc.
- Review policies, procedures, controls, and audit evidence.
- Identify gaps, risks, observations, and recommend remediation.
- Prepare Risk Registers, SoA, Control Matrices, Audit Reports, and Compliance Reports.
- Support clients during certification, surveillance, and external audits.
- Conduct client meetings, interviews, and control walkthroughs.
- Coordinate evidence collection and remediation tracking.
- Develop and review information security policies and procedures.
- Stay updated with cybersecurity standards, regulations, and best practices.
Required Skills
- Strong understanding of Information Security, GRC, Risk & Compliance.
- Good knowledge of ISO 27001:2022 and SOC 2.
- Understanding of cybersecurity controls, IT infrastructure, cloud security, IAM, vulnerability management, and security operations.
- Strong analytical, documentation, communication, and report-writing skills.
- Ability to independently manage client engagements.
Qualifications
- Bachelor's degree in Cybersecurity, IT, Computer Science, or related field.
- 2–6 years of relevant experience in GRC, IT Audit, Cybersecurity Compliance, or Consulting.
- Certifications such as ISO 27001 LA/LI, CISA, CISSP, CRISC, or relevant GRC certifications are preferred.
About Nerve Solutions
Nerve Solutions is a team of engineers building products for real-time risk management and surveillance in financial markets. Our solutions enable market participants to identify, monitor, and quantify risks and anomalies in live markets, allowing them to take corrective action at sub-second speeds.
We also develop products for automated trading and have become a trusted technology partner to some of the largest financial services organizations in the region.
About the Role
We are looking for a proactive and detail-oriented IT & Information Security Engineer to manage and maintain the organization's IT infrastructure while ensuring the security, availability, and reliability of our systems. The role involves providing technical support, administering hardware and software, strengthening cybersecurity practices, monitoring network activities, and implementing security controls to safeguard organizational assets.
The ideal candidate should have strong infrastructure knowledge, a security-first mindset, and the ability to troubleshoot technical issues while continuously improving the organization's IT environment.
Roles & Responsibilities
- Manage and maintain the organization's IT infrastructure, including hardware, software, servers, and network systems.
- Provide technical support to employees by troubleshooting hardware, software, network, and system-related issues.
- Configure, deploy, and maintain desktops, laptops, peripherals, printers, and other IT equipment.
- Set up user accounts, systems, and required software for new employees and support onboarding activities.
- Monitor network performance and employee network activities to ensure system security and compliance.
- Implement and maintain endpoint security solutions, antivirus tools, firewalls, and access control mechanisms.
- Perform regular system updates, security patching, vulnerability assessments, and preventive maintenance.
- Identify infrastructure risks and recommend security enhancements to minimize vulnerabilities.
- Maintain documentation for IT assets, software licenses, network configurations, security policies, and system inventories.
- Assist in implementing information security best practices, security audits, and compliance initiatives.
- Coordinate with internal teams to ensure IT services effectively support business operations.
- Stay updated with the latest cybersecurity threats, technologies, and industry best practices.
Required Skills
- 2–4 years of experience in IT Infrastructure, System Administration, or Information Security.
- Strong knowledge of Windows operating systems, networking, servers, and IT infrastructure.
- Experience troubleshooting hardware, software, network, and user-related issues.
- Knowledge of network security, endpoint protection, firewalls, VPNs, and vulnerability management.
- Experience with Active Directory, user access management, and system administration.
- Familiarity with Microsoft 365 administration is an added advantage.
- Understanding of backup, disaster recovery, and IT asset management.
- Strong analytical and problem-solving skills with attention to detail.
- Good communication and documentation skills.
- Ability to work independently and collaboratively in a fast-paced environment.
Preferred Qualifications
- Bachelor's degree in Information Technology, Computer Science, or a related field.
- Certifications such as CompTIA A+, Network+, Security+, Microsoft, CCNA, or equivalent will be an added advantage.







