Principal Information Security Engineer - Pioneer & Architect
Are you a seasoned cybersecurity professional ready to architect and lead an entire information security program from the ground up? Glomopay, India's trailblazing IFSCA-authorized PSP, is seeking a visionary and hands-on Principal Information Security Engineer to define and drive our security posture. Reporting directly to the Head of Information Security, this is a unique, strategic opportunity to build a mature InfoSec program that is not just compliant, but a core competitive advantage.
About Glomopay & Why You'll Thrive Here
Glomopay is at the forefront of financial innovation, poised to reshape the payment landscape. We believe security isn't just a checkbox; it's the foundation of trust and a critical enabler of our growth. Joining us means:
Direct Impact & Full Ownership: You won't just advise; you'll build and own the entire security program. Your actions and decisions will directly define the security ecosystem of India's first IFSCA-authorized PSP, with no inherited mess or bureaucracy.
Regulatory Pioneer: Help define the InfoSec playbook at the intersection of IFSCA, RBI, and global card network requirements.
Modern Stack: Work with a cloud-native infrastructure, leveraging cutting-edge tools like GCP, Terraform IaC, CrowdStrike, and Teleport PAM, not legacy systems.
Strategic Moat: Your robust security program will be a key reason banking partners choose Glomopay, transforming security into a revenue enabler, not a cost center.
Your Mission: Build & Secure Glomopay's Future
As our Principal Information Security Engineer, you will own the entire information security function – from policy and governance to hands-on implementation, operations, and stringent regulatory compliance. This is a hands-on, strategic role for a security practitioner who can independently establish and scale a mature InfoSec program.
Key Responsibilities
Security Governance & Compliance
Lead the design, implementation, and continuous improvement of our Information Security Management System (ISMS) – encompassing the policy framework, risk assessments, and control implementation aligned with ISO 27001, PCI DSS, and the IFSCA Cyber Security and Cyber Resilience Framework.
Drive compliance with critical regulations including RBI outsourcing directions, IFSCA circulars, DPSC guidelines, and PCI SSF requirements applicable to payment service providers.
Orchestrate comprehensive third-party risk management, conducting rigorous due diligence audits on all technology partners and meticulously maintaining records as per regulatory mandates.
Lead and manage the internal IT audit program – including planning, execution, engaging external audit vendors, and tracking findings to successful closure.
Develop and implement a robust Information Classification framework, ensuring its seamless embedding into DLP rules, employee training, and daily operations.
Security Operations & Architecture (Hands-On)
Architect and mature our Security Operations Center (SOC) function – starting with MDR-augmented operations (CrowdStrike) and progressively evolving towards a robust hybrid capability.
Define and execute the SIEM strategy: integrate and monitor all critical log sources (application, infrastructure, database, identity, PAM) and develop sophisticated detection use-cases.
Conduct regular and proactive threat modeling exercises across our systems and applications.
Manage Privileged Access Management (PAM) solutions – including session monitoring, automated password rotation, break-glass procedures, and periodic user access reviews.
Deploy and administer advanced Data Loss Prevention (DLP) controls across endpoints, email, and cloud storage platforms (Google Workspace DLP, CrowdStrike Device Control).
Take full ownership of endpoint security – defining hardening SOPs against CIS benchmarks, managing approved software lists, and implementing full disk encryption.
Drive network security posture enhancements – including geo-fencing, regular firewall rule reviews, and Cloud IDS tuning across our GCP infrastructure.
Champion application security initiatives – integrating SAST/DAST into CI/CD pipelines, defining stringent security review thresholds, and ensuring continuous OWASP compliance.
Incident Management & Business Continuity
Take full ownership of the incident management lifecycle – from defining severity classifications and closure SLAs to establishing escalation procedures and conducting thorough post-incident reviews.
Establish a dedicated security incident reporting channel and ensure organization-wide awareness and training.
Maintain and rigorously test the Business Continuity Plan, covering critical scenarios such as office unavailability, power failure, pandemic, and cloud provider disruption.
Ensure Disaster Recovery (DR) drills meet defined RTO thresholds with proper segregation of duties.
Act as the primary incident response liaison during security incidents, coordinating response efforts with banking partners and regulators per notification SLAs.
Regulatory & Partner Interface
Represent Glomopay as the primary security interface with banking partners, expertly managing their Third-Party Service Provider Risk Assessments.
Build and lead the "Managed Security Transparency" program – delivering scoped security reports, alert forwarding, incident summaries, and independent attestation for regulated entity partners.
Coordinate seamlessly with IFSCA, external auditors, and banking partner audit teams during inspections and certifications.
Drive the SOC 2 Type II certification journey and maintain existing independent attestations (ISO 27001, PCI DSS).
Establish and maintain a comprehensive compliance resource center – making audit reports, certifications, and security documentation readily available for partner due diligence on demand.
What You'll Bring
Experience
A minimum of 4 years of progressive experience in information security, with at least 3 years in a hands-on security role.
Prior experience in regulated financial services (fintech, banking, NBFC, payment processors) is strongly preferred.
Core Expertise
Proven experience in standing up and maturing InfoSec programs from the ground up, covering both GRC and hands-on security functions.
Deep working knowledge and practical experience with PCI DSS, ISO 27001, SOC 2, and Indian financial regulatory frameworks (RBI, IFSCA).
Hands-on experience with cloud security on GCP (strongly preferred) or AWS/Azure.
Demonstrated experience on both sides of third-party security assessments – having been audited and auditing vendors.
Practical expertise in implementing and managing PAM, SIEM, DLP, endpoint hardening, and network security solutions.
The Right Person For This Role Will:
Be adept at interpreting SIEM detection rules and alerts, as well as configuring and optimizing them.
Translate complex regulatory requirements into practical, effective controls without over-engineering.
Uphold security non-negotiables while maintaining a pragmatic approach to business constraints.
Possess excellent written communication skills for crafting clear policy documents, detailed audit responses, and robust regulatory submissions.
Thrive solo in a fast-paced, startup environment where security is a strategic differentiator, not a bottleneck.
Demonstrate unwavering integrity, given access to the most sensitive systems, data, and partner relationships.
Exhibit a strong ability to handle audits and provide sound, logical justifications when required.
If you're ready to make a significant impact and build the security future of a pioneering fintech, we want to hear from you!