Posted on: 25/06/2026
Job Description :
We are seeking a highly skilled and experienced AVP Compliance & Information Security to lead our regulatory compliance, risk management, and security governance frameworks. In the fast-paced payment gateway industry, ensuring the highest standards of data security and regulatory adherence is paramount.
The ideal candidate will possess over 12 years of IT experience (with 10+ years dedicated to information security and compliance), demonstrating deep expertise in PCI DSS, ISO 27001, SOC 1/SOC 2, and DevSecOps. You will oversee end-to-end audit processes, drive risk assessments, and collaborate closely with executive leadership, technical architects, and external auditors to safeguard our payment infrastructure.
Key Responsibilities :
1. Compliance Governance & Audit Management :
- Regulatory & Industry Standards : Lead and maintain the implementation, maintenance, and surveillance audits for PCI DSS, ISO 27001 : 2013, SSAE 18 Type 2 (SOC 1/2), and ISO 22301 (BCMS).
- Audit Execution : Conduct routine spot audits, internal audits, and comprehensive risk assessments across various business locations and cloud environments.
- Policy Management : Develop, evaluate, and periodically review Information Security (IS) policies, standard operating procedures, and Root Cause Analysis (RCA) documentation.
- RFP & Vendor Assessment : Manage security questionnaires for RFPs/RFIs and perform robust Vendor Risk Assessments on third-party integrations and partners.
2. Application & Cloud Security Oversight :
- Secure Development (SSDLC) : Oversee integration of security into the CI/CD pipeline using DevSecOps best practices, ensuring rigid adherence to OWASP Top 10 standards.
- Vulnerability & Threat Management : Manage end-to-end Web Application and Network Vulnerability Management, leveraging SAST, DAST, IAST, and RASP frameworks.
- Cloud Compliance : Direct security audits for cloud infrastructure (specifically Microsoft Azure) and containerized environments using CIS benchmarks for Docker and Kubernetes.
- Identity & Access Management : Audit and review multi-factor authentication (MFA) and Identity & Access Management (IAM) tools (e.g., Okta, CyberArk).
3. Incident Management & Business Continuity :
- Incident Response : Supervise incident and change management workflows, including Firewall Rule Change Requests (FRCR).
- Disaster Recovery (BCP/DR) : Partner with cross-functional teams to design, test (Chaos testing), and refine Business Continuity and Disaster Recovery plans using performance monitoring tools (e.g., Dynatrace).
- Security Training : Design and execute organization-wide Information Security, Data Privacy, and Risk Awareness training programs.
Required Qualifications & Technical Skills Experience & Education :
- Total Experience : Minimum 12+ years in Information Technology, with at least 910 years of core experience in Information Security Compliance.
- Education : Masters Degree in Computer Science (MCS), Information Technology, or a closely related technical field.
- Industry Context : Proven track record in banking, financial services, fintech, or payment gateway organizations is highly preferred.
Core Technical Profile :
- Compliance Frameworks : Deep practical knowledge of PCI DSS, ISO 27001, SOC 1 & 2, HIPAA, and SOX 404.
- Security Assessment Tools : Familiarity with tools such as Acunetix, WebInspect, Burp Suite, Kali Linux, Nessus, Checkmarx, and Fortify.
- Infrastructure Security : Strong comprehension of DLP, IPS/IDS, Firewalls, Routers, Switches, and Proxy Servers alongside basic TCP/IP networking.
- Methodologies : Proficient in Agile methodology practices and threat modeling frameworks.
Preferred Professional Certifications :
- ISO/IEC 27001 : 2013 Lead Auditor / Lead Implementer (IRCA)
- Certified Ethical Hacker (CEH)
- Microsoft Azure Administrator / Cloud Security certifications
- Microsoft Certified Professional (MCP)
Soft Skills & Leadership Attributes :
- Executive Communication : Ability to deliver comprehensive, actionable security compliance reports to both technical engineering teams and executive stakeholders.
- Adaptability & Problem-Solving : A self-motivated professional capable of analyzing emerging security threats and regulatory changes in a positive, solution-oriented manner.
- Collaboration : Exceptional interpersonal skills to work effectively alongside application architects, external regulatory bodies, and business managers.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Senior Management
Job Code
1648320