HamburgerMenu
hirist

Job Description

Overview :

We are seeking a hands-on security leader to build and own our data protection and application security function from the ground up. This role reports directly to the CTO and carries a direct mandate to close gaps, enforce standards, and embed proactive security into product and engineering workflows. In fintech, data is the product and protecting it is protecting the business.

Responsibilities :

Data Leakage Detection & Prevention :

- Design and operationalize a comprehensive DLP framework across structured data stores, APIs, SaaS tools, email, and endpoints.

- Implement continuous monitoring to detect anomalous queries, bulk exports, unauthorized reads, and privilege abuse in real time.

- Own sensitive data classification and enforce access boundaries across storage, application, and transport layers.

API & Application Flow Security :

- Conduct deep audits of internal and external APIs, reviewing contracts, authentication, and data scopes to identify vulnerabilities (BOLA, excessive exposure, broken auth, etc.).

- Walk product flows end-to-end to identify over-exposure, unnecessary retention, and unintended access paths.

- Actively participate in threat modelling during SDLC for new features.

- Define and enforce API security standards with measurable release pipeline gates.

Database & Infrastructure Access Control :

- Audit and redesign least-privilege access models across databases and warehouses.

- Implement query-level monitoring, data masking in non-production, and tokenisation where applicable.

- Ensure defensible, documented access justifications for all data stores.

Employee Data Risk & Internal Threat Containment :

- Identify and close employee data exfiltration channels (email, cloud sync, SaaS integrations, removable media).

- Deploy technical DLP controls for outbound data movement.

- Implement tiered RBAC/ABAC frameworks with regular access reviews.

Customer Account & Identity Protection :

- Own detection and prevention of account takeover, spoofing, and unauthorized session access.

- Review authentication flows, session management, and customer data exposure directly with product and engineering.

- Maintain zero-blind-spot ownership of identity vulnerabilities.

Risk Reporting & Organizational Influence :

- Produce risk-rated findings with business impact context for both technical teams and the board.

- Constructively challenge infra, product, engineering, and CISO functions when gaps are identified.

- Build a culture of proactive data protection embedded in engineering and product practices.

Requirements :

Experience :

- 10 - 14 years in security, with 4 - 5 years in fintech, payments, banking, or financial data environments.

- Hands-on expertise in application security, API security, and data access governance.

- Prior experience building a security sub-function from scratch strongly preferred.

- Backgrounds may include: Senior AppSec Engineer, Principal Security Architect, Red Team Lead, or senior penetration tester turned internal security leader.

Product Mindset & Systems Thinking :

- Ability to map complete product flows and identify leakage risks from design decisions.

- Skilled at engaging product/engineering teams in their language, framing risks in terms of user impact and system design.

- Curiosity-driven approach: asking 'why does this system work this way?' before 'what CVEs apply here?'

Technical Skills :

- OWASP API Top 10, DLP tooling, STRIDE/PASTA threat modelling.

- SIEM & detection rules, RBAC/ABAC, OAuth 2.0, JWT security.

- Database audit & access control, data masking & tokenisation.

- API penetration testing, endpoint DLP, session management.

Privileged Access Management :

- Strong command of database security, audit logging, and privilege management.

- Ability to write meaningful SIEM detection rules and alerting logic.

- Solid understanding of IAM, RBAC/ABAC, OAuth 2.0, JWT vulnerabilities, and session security.

Regulatory Awareness :

- Working knowledge of PCI-DSS, SOC 2, GDPR, and local financial regulations (RBI, MAS, FCA).

- Compliance understood as guardrails, not the primary measure of success.

Leadership & Influence :

- Proven ability to drive change across engineering, product, and business teams.

- Strong communication skills - translating technical vulnerabilities into board-level risk statements.

- Politically resilient, evidence-driven, and ego-free.

- Builder mindset: thrives in greenfield environments, leads by doing.

The Team You Will Build :

You will hire and manage specialists with full ownership of team structure and tooling selection:

- API & Application Security Specialist - continuous API auditing, threat modelling, SDLC security gates.

- Data Access & Monitoring Specialist - database governance, query monitoring, anomaly detection.

- Internal Threat & Employee Risk Analyst - controls for internal data egress, access provisioning reviews.

Why Join Us :

- Direct mandate from the top - report to the CTO, not into a security hierarchy.

- Real authority - findings are acted on, gaps get closed.

- Greenfield build - define the function, tools, processes, and team.

- Hands-on leadership - lead by doing, not delegating.

- Meaningful problem - in fintech, data is the product. Protecting it is protecting the business.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...