HamburgerMenu
hirist

Assistant Vice President - Information Security

Employee Forums
10 - 15 Years
Pune

Posted on: 25/06/2026

Job Description

Job Description :

We are seeking a highly skilled and experienced AVP Compliance & Information Security to lead our regulatory compliance, risk management, and security governance frameworks. In the fast-paced payment gateway industry, ensuring the highest standards of data security and regulatory adherence is paramount.

The ideal candidate will possess over 12 years of IT experience (with 10+ years dedicated to information security and compliance), demonstrating deep expertise in PCI DSS, ISO 27001, SOC 1/SOC 2, and DevSecOps. You will oversee end-to-end audit processes, drive risk assessments, and collaborate closely with executive leadership, technical architects, and external auditors to safeguard our payment infrastructure.

Key Responsibilities :

1. Compliance Governance & Audit Management :

- Regulatory & Industry Standards : Lead and maintain the implementation, maintenance, and surveillance audits for PCI DSS, ISO 27001 : 2013, SSAE 18 Type 2 (SOC 1/2), and ISO 22301 (BCMS).

- Audit Execution : Conduct routine spot audits, internal audits, and comprehensive risk assessments across various business locations and cloud environments.

- Policy Management : Develop, evaluate, and periodically review Information Security (IS) policies, standard operating procedures, and Root Cause Analysis (RCA) documentation.

- RFP & Vendor Assessment : Manage security questionnaires for RFPs/RFIs and perform robust Vendor Risk Assessments on third-party integrations and partners.

2. Application & Cloud Security Oversight :

- Secure Development (SSDLC) : Oversee integration of security into the CI/CD pipeline using DevSecOps best practices, ensuring rigid adherence to OWASP Top 10 standards.

- Vulnerability & Threat Management : Manage end-to-end Web Application and Network Vulnerability Management, leveraging SAST, DAST, IAST, and RASP frameworks.

- Cloud Compliance : Direct security audits for cloud infrastructure (specifically Microsoft Azure) and containerized environments using CIS benchmarks for Docker and Kubernetes.

- Identity & Access Management : Audit and review multi-factor authentication (MFA) and Identity & Access Management (IAM) tools (e.g., Okta, CyberArk).

3. Incident Management & Business Continuity :

- Incident Response : Supervise incident and change management workflows, including Firewall Rule Change Requests (FRCR).

- Disaster Recovery (BCP/DR) : Partner with cross-functional teams to design, test (Chaos testing), and refine Business Continuity and Disaster Recovery plans using performance monitoring tools (e.g., Dynatrace).

- Security Training : Design and execute organization-wide Information Security, Data Privacy, and Risk Awareness training programs.

Required Qualifications & Technical Skills Experience & Education :

- Total Experience : Minimum 12+ years in Information Technology, with at least 910 years of core experience in Information Security Compliance.

- Education : Masters Degree in Computer Science (MCS), Information Technology, or a closely related technical field.

- Industry Context : Proven track record in banking, financial services, fintech, or payment gateway organizations is highly preferred.

Core Technical Profile :

- Compliance Frameworks : Deep practical knowledge of PCI DSS, ISO 27001, SOC 1 & 2, HIPAA, and SOX 404.

- Security Assessment Tools : Familiarity with tools such as Acunetix, WebInspect, Burp Suite, Kali Linux, Nessus, Checkmarx, and Fortify.

- Infrastructure Security : Strong comprehension of DLP, IPS/IDS, Firewalls, Routers, Switches, and Proxy Servers alongside basic TCP/IP networking.

- Methodologies : Proficient in Agile methodology practices and threat modeling frameworks.

Preferred Professional Certifications :

- ISO/IEC 27001 : 2013 Lead Auditor / Lead Implementer (IRCA)

- Certified Ethical Hacker (CEH)

- Microsoft Azure Administrator / Cloud Security certifications

- Microsoft Certified Professional (MCP)

Soft Skills & Leadership Attributes :

- Executive Communication : Ability to deliver comprehensive, actionable security compliance reports to both technical engineering teams and executive stakeholders.

- Adaptability & Problem-Solving : A self-motivated professional capable of analyzing emerging security threats and regulatory changes in a positive, solution-oriented manner.

- Collaboration : Exceptional interpersonal skills to work effectively alongside application architects, external regulatory bodies, and business managers.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...