JobRaahGet matched free

Jobs

Senior Security Engineer - GRC

Vegapay · Bengaluru · India · On-site

Posted Sep 30, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

The Impact You’ll Drive We're looking for an experienced GRC professional to build and scale our governance, risk, and compliance function. As a fintech infrastructure provider processing sensitive financial data on behalf of banks and NBFCs, we operate under significant regulatory scrutiny - this role will own the frameworks, certifications, and controls that keep Vegapay compliant, secure, and trusted by our regulated BFSI partners. You’ll work closely with Security, Engineering, Legal, Product, and leadership to embed governance and risk management into how we build and operate, while being the primary point of contact for client and auditor assurance. The Hats You Will Wear Governance & Policy Management Design, implement, and maintain information security and compliance policies, standards, and procedures aligned to ISO 27001, SOC 2, PCI-DSS, and RBI guidelines Establish and run governance forums (risk council, policy reviews) with leadership and cross-functional stakeholders Own and maintain the organization’s risk register, control framework, and compliance calendar Conduct periodic enterprise and IT risk assessments, identifying gaps and driving remediation with process and engineering owners Define and track key risk indicators (KRIs) and key control indicators (KCIs) across the business Support risk-based decision-making for new products, partnerships, and vendor relationships Risk Management Ensure ongoing compliance with RBI guidelines, payment ecosystem regulations (NPCI, card network mandates), and data protection requirements including the DPDPA Track regulatory and industry changes impacting fintech/BFSI operations and translate them into actionable requirements Liaise with regulators, external auditors, and banking/NBFC partners on compliance matters as needed Own and coordinate RBI-related audits and regulatory inspections, including evidence submission, query resolution, and remediation tracking Information Security Compliance & Audits Own end-to-end delivery of ISO 27001, SOC 2 Type II, PCI-DSS, and other certification audits — including evidence collection, auditor coordination, and remediation tracking Partner with Engineering and Security to embed controls into product and infrastructure design Drive closure of audit findings and monitor control effectiveness over time Vendor & Third-Party Risk Management Design and operate a vendor/third-party risk assessment program covering onboarding due diligence, periodic reviews, and offboarding Review vendor contracts and SLAs for risk, security, and compliance clauses in partnership with Legal Client & Stakeholder Assurance Respond to security and compliance due-diligence questionnaires and audits from banking and NBFC clients Represent Vegapay’s GRC posture in client and partner conversations, building trust with regulated BFSI customers Prepare compliance dashboards, risk reports, and leadership/board updates The…