Posted on: 27/08/2026
IT Security & Compliance Analyst
Location : Gurgaon
Company : The Card Company
Experience : 3 - 6 Years
Department : Security, Risk & Compliance
About The Card Company :
The Card Company is a fast-growing fintech startup focused on revolutionizing card-based payments in India. As a regulated entity, we are committed to building secure, compliant, and trustworthy financial infrastructure. We're already PCI-DSS certified, and regularly undergo RBI audits, SAR audits, and ISO 27001 assessments. Were looking for a driven and detail-oriented IT Security & Compliance Analyst to help maintain our security posture, manage audit and regulatory compliance, and support the secure growth of our platform.
Key Responsibilities :
Compliance & Regulatory Readiness :
- Lead coordination of all audits including PCI-DSS, ISO 27001, SAR (System Audit Reports), and RBI inspections.
- Maintain updated security documentation, audit artifacts, and compliance calendars.
- Work closely with engineering, product, and legal teams to address audit findings and ensure continuous compliance.
Vulnerability Management & Security Monitoring :
- Perform and track remediation of vulnerability scans across cloud infrastructure using tools like Qualys, Nessus, or AWS Inspector.
- Monitor and analyze logs using SIEM solutions (e.g., Wazuh, ELK, or Splunk) and respond to alerts or incidents.
- Regularly review AWS security posture: IAM policies, Security Groups, GuardDuty, CloudTrail, S3 bucket policies, etc.
Policy Governance & Risk Management :
- Draft and maintain security policies, procedures, and risk registers aligned with ISO 27001, RBI Cybersecurity Framework, and PCI-DSS.
- Conduct risk assessments, DPIAs, and vendor security evaluations.
- Support periodic access reviews, incident response planning, and business continuity testing.
Required Qualifications :
- 3 - 6 years of experience in Information Security, GRC (Governance, Risk, Compliance), or IT audit in a fintech or regulated financial environment.
- Hands-on knowledge of :
1. PCI-DSS, ISO 27001, RBI Cybersecurity Guidelines
2. Cloud security best practices (preferably on AWS)
3. Vulnerability assessment and compliance tooling
- Excellent communication skills to work with auditors, regulators, and internal stakeholders.
Preferred (Nice to Have) :
- Certifications such as CISA, CISSP, ISO 27001 Lead Auditor, CEH, or Security+
- Experience with DevSecOps, automated compliance tooling, or infrastructure-as-code security (e.g., tfsec, Checkov)
- Prior experience in handling RBI-regulated audits for Payment Aggregators, NBFCs, or Card Issuers
- Experience with payments domain.
What We Offer :
- Join a security-first fintech thats scaling rapidly and tackling real-world financial challenges.
- Be a core part of managing national-level compliance in a live, growing platform.
- Work with a highly talented and mission-driven team in Gurgaon, with a flexible hybrid work model and competitive compensation.
The job is for:
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1666627