HamburgerMenu
hirist

The Card Company - IT Security & Compliance Analyst

The Card Company
3 - 6 Years
Gurgaon/Gurugram

Posted on: 27/08/2026

Job Description

IT Security & Compliance Analyst

Location : Gurgaon

Company : The Card Company

Experience : 3 - 6 Years

Department : Security, Risk & Compliance

About The Card Company :

The Card Company is a fast-growing fintech startup focused on revolutionizing card-based payments in India. As a regulated entity, we are committed to building secure, compliant, and trustworthy financial infrastructure. We're already PCI-DSS certified, and regularly undergo RBI audits, SAR audits, and ISO 27001 assessments. Were looking for a driven and detail-oriented IT Security & Compliance Analyst to help maintain our security posture, manage audit and regulatory compliance, and support the secure growth of our platform.

Key Responsibilities :

Compliance & Regulatory Readiness :

- Lead coordination of all audits including PCI-DSS, ISO 27001, SAR (System Audit Reports), and RBI inspections.

- Maintain updated security documentation, audit artifacts, and compliance calendars.

- Work closely with engineering, product, and legal teams to address audit findings and ensure continuous compliance.

Vulnerability Management & Security Monitoring :

- Perform and track remediation of vulnerability scans across cloud infrastructure using tools like Qualys, Nessus, or AWS Inspector.

- Monitor and analyze logs using SIEM solutions (e.g., Wazuh, ELK, or Splunk) and respond to alerts or incidents.

- Regularly review AWS security posture: IAM policies, Security Groups, GuardDuty, CloudTrail, S3 bucket policies, etc.

Policy Governance & Risk Management :

- Draft and maintain security policies, procedures, and risk registers aligned with ISO 27001, RBI Cybersecurity Framework, and PCI-DSS.

- Conduct risk assessments, DPIAs, and vendor security evaluations.

- Support periodic access reviews, incident response planning, and business continuity testing.

Required Qualifications :

- 3 - 6 years of experience in Information Security, GRC (Governance, Risk, Compliance), or IT audit in a fintech or regulated financial environment.

- Hands-on knowledge of :

1. PCI-DSS, ISO 27001, RBI Cybersecurity Guidelines

2. Cloud security best practices (preferably on AWS)

3. Vulnerability assessment and compliance tooling

- Excellent communication skills to work with auditors, regulators, and internal stakeholders.

Preferred (Nice to Have) :

- Certifications such as CISA, CISSP, ISO 27001 Lead Auditor, CEH, or Security+

- Experience with DevSecOps, automated compliance tooling, or infrastructure-as-code security (e.g., tfsec, Checkov)

- Prior experience in handling RBI-regulated audits for Payment Aggregators, NBFCs, or Card Issuers

- Experience with payments domain.

What We Offer :

- Join a security-first fintech thats scaling rapidly and tackling real-world financial challenges.

- Be a core part of managing national-level compliance in a live, growing platform.

- Work with a highly talented and mission-driven team in Gurgaon, with a flexible hybrid work model and competitive compensation.

The job is for:

May work from home
info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...