Globacom Limited Logo

Globacom Limited

Information Security Associate

Posted Yesterday
Be an Early Applicant
In-Office
Bengaluru, Bengaluru Urban, Karnataka, IND
Mid level
In-Office
Bengaluru, Bengaluru Urban, Karnataka, IND
Mid level
Lead and build Glomopay's end-to-end InfoSec program: governance, compliance (ISO27001, PCI, IFSCA/RBI), third-party risk, SOC/SIEM/PAM/DLP operations, incident management, BCP/DR, and regulatory/audit interfacing. Hands-on implementation and ongoing monitoring across cloud (GCP), endpoints, network, and application security.
The summary above was generated by AI

As a member of the Information Security Team at Glomopay, you will own the entire information security

function — from policy and governance to hands-on implementation and regulatory compliance. Reporting

directly to the Head of Information Security, this is a strategic role for a security practitioner who can single-handedly stand up a mature InfoSec program for Glomo

Key Responsibilities

Security Governance & Compliance

  • Own the Information Security Management System (ISMS) — policy framework, risk assessments and control implementation aligned with ISO 27001, PCI DSS, and IFSCA Cyber Security and

  • Cyber Resilience Framework

  • Lead compliance with RBI outsourcing directions, IFSCA circulars, DPSC guidelines, and PCI SSF requirements applicable to payment service providers

  • Own third-party risk management — conduct due diligence audits on all technology partners and maintain records per regulatory requirements

  • Drive the internal IT audit program — plan, execute, engage external audit vendors, and track findings to closure

  • Establish the Information Classification framework, embedding it into DLP rules, employee training, and daily operations

Security Operations & Architecture (Hands-On)

  • Build and manage the SOC function — starting with MDR-augmented operations (CrowdStrike), progressively maturing toward hybrid capability

  • Own the SIEM strategy: integrate and monitor all critical log sources (application, infrastructure, database, identity, PAM) and build detection use-cases

  • Conduct threat modelling Manage Privileged Access Management (PAM) — session monitoring, password rotation,break-glass procedures, periodic user access reviews

  • Implement and manage DLP controls across endpoints, email, and cloud storage (Google Workspace DLP, CrowdStrike Device Control)

  • Own endpoint security — hardening SOPs against CIS benchmarks, approved software lists, full disk encryption

  • Drive network security posture — geo-fencing, firewall rule reviews, Cloud IDS tuning across GCP infrastructure

  • Oversee application security — integrate SAST/DAST into CI/CD pipelines, define security review thresholds, manage OWASP compliance

Incident Management & Business Continuity

  • Own the incident management lifecycle — severity classifications, closure SLAs, escalation

  • procedures, post-incident reviews

  • Establish a dedicated security incident reporting channel and ensure organization-wide awareness

  • Maintain and test the Business Continuity Plan covering office unavailability, power failure,

  • pandemic, and cloud provider disruption scenarios

  • Ensure DR drills meet RTO thresholds with proper segregation of duties

  • Serve as the primary point of contact during security incidents, coordinating response with banking partners and regulators per notification SLAs

Regulatory & Partner Interface

  • Serve as the primary security interface with banking partners, managing their Third Party Service provider Risk Assessments

  • Build the “Managed Security Transparency” program — scoped security reports, alert forwarding, incident summaries, and independent attestation for regulated entity partners

  • Coordinate with IFSCA, external auditors, and banking partner audit teams during inspections and certifications

  • Drive the SOC 2 Type II certification journey and maintain independent attestations (ISO 27001, PCI DSS)

  • Build and maintain a compliance resource center — audit reports, certifications, security

  • documentation available for partner due diligence on demand

What We're Looking For

Experience: 4 years in information security with at least 3 years in a hands-on security role, preferably in regulated financial services (fintech, banking, NBFC, payment processors)

Core Expertise:

  • Be part of the InfoSec program from the early stage, understand the GRC as well as the Security Function.

  • Deep working knowledge of PCI DSS, ISO 27001, SOC 2, and Indian financial regulatory frameworks (RBI, IFSCA)

  • Hands-on with experience with cloud security on GCP (strongly preferred) or AWS/Azure

  • Experience on both sides of third-party security assessments — being audited and auditing vendors

  • Practical expertise in PAM, SIEM, DLP, endpoint hardening, and network security.

The Right Person For This Role:

  • You should be able to make sense of SIEM detection rules and alerts and configure the same as well

  • Translates regulatory requirements into practical controls without over-engineering

  • Holds firm on security non-negotiables while being pragmatic with business constraints

  • Writes clean policy documents, audit responses, and regulatory submissions

  • Thrives solo in a fast-paced startup where compliance is a competitive advantage, not overhead

  • High integrity — this role has access to the most sensitive systems, data, and partner relationships

  • Ability to handle audits and provide right and logical justifications where appropriate.

Why Join Glomopay?

  • Direct Impact: Report directly to the Head of Information Security. Shape the security foundation of India's first IFSCA-authorized PSP, your actions and decisions define the ecosystem.

  • Full Ownership: You will be instrumental in building the entire security program and be a part of the team from scratch. No inherited mess, no bureaucracy — This gives you an opportunity to define the culture from scratch.

  • Regulatory Pioneer: You will help define the InfoSec playbook at the intersection of IFSCA, RBI, and global card network requirements.

  • Modern Stack: GCP, Terraform IaC, CrowdStrike, Teleport PAM — cloud-native infrastructure, not legacy systems.

  • Strategic Moat: Your security program becomes the reason banking partners choose Glomopay. Security here is a revenue enabler, not a cost center.

Similar Jobs

An Hour Ago
Hybrid
Bangalore, Bengaluru Urban, Karnataka, IND
Senior level
Senior level
Fintech • Legal Tech • Software • Financial Services • Cybersecurity • Data Privacy
Perform and review fund accounting for Luxembourg real estate funds, calculate NAVs, fees and investor allocations, manage SPV consolidations, support audits, investor services and regulatory compliance (AIFMD/CSSF). Liaise with auditors, valuers, property managers and cross-functional teams, improve processes, and mentor junior staff.
An Hour Ago
Easy Apply
In-Office
Bangalore, Bengaluru Urban, Karnataka, IND
Easy Apply
Mid level
Mid level
Cloud • Security • Software • Cybersecurity • Automation
Design, build, and deploy enterprise UiPath RPA automations end-to-end. Gather requirements, create reusable solutions, document designs, support production bots, perform root-cause analysis, and continuously optimize automations while collaborating with stakeholders and Enterprise Apps teams.
Top Skills: AdpCi/CdCoupaDevOpsEtradeJSONNavanNetSuiteOauthPythonRestSalesforceSAMLSoapSoxSQLUipath Agentic AiUipath Automation HubUipath OrchestratorUipath RobotsUipath StudioWorkdayXMLZipZuora BillingZuora Revenue
3 Hours Ago
Easy Apply
Remote or Hybrid
India
Easy Apply
Senior level
Senior level
Artificial Intelligence • Cloud • Information Technology • Machine Learning • Software
The Senior Sales Engineer at LogicMonitor partners with Sales to provide technical solutions, deliver presentations, mentor peers, and promote the use of AI tools, ensuring technical excellence and collaboration within the team.
Top Skills: AIAutomation ConceptsCloudGptGroovyIt InfrastructureMonitoringPowershellPython

What you need to know about the Bengaluru Tech Scene

Dubbed the "Silicon Valley of India," Bengaluru has emerged as the nation's leading hub for information technology and a go-to destination for startups. Home to tech giants like ISRO, Infosys, Wipro and HAL, the city attracts and cultivates a rich pool of tech talent, supported by numerous educational and research institutions including the Indian Institute of Science, Bangalore Institute of Technology, and the International Institute of Information Technology.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account