Senior Security Engineer - GRC
Vegapay · Bengaluru · India · On-site
Posted Sep 30, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
The Impact You’ll Drive
We're looking for an experienced GRC professional to build and scale our governance, risk, and compliance function. As a fintech infrastructure provider processing sensitive financial data on behalf of banks and NBFCs, we operate under significant regulatory scrutiny - this role will own the frameworks, certifications, and controls that keep Vegapay compliant, secure, and trusted by our regulated BFSI partners. You’ll work closely with Security, Engineering, Legal, Product, and leadership to embed governance and risk management into how we build and operate, while being the primary point of contact for client and auditor assurance.
The Hats You Will Wear
Governance & Policy Management
Design, implement, and maintain information security and compliance policies, standards, and procedures aligned to ISO 27001, SOC 2, PCI-DSS, and RBI guidelines
Establish and run governance forums (risk council, policy reviews) with leadership and cross-functional stakeholders
Own and maintain the organization’s risk register, control framework, and compliance calendar
Conduct periodic enterprise and IT risk assessments, identifying gaps and driving remediation with process and engineering owners
Define and track key risk indicators (KRIs) and key control indicators (KCIs) across the business
Support risk-based decision-making for new products, partnerships, and vendor relationships
Risk Management
Ensure ongoing compliance with RBI guidelines, payment ecosystem regulations (NPCI, card network mandates), and data protection requirements including the DPDPA
Track regulatory and industry changes impacting fintech/BFSI operations and translate them into actionable requirements
Liaise with regulators, external auditors, and banking/NBFC partners on compliance matters as needed
Own and coordinate RBI-related audits and regulatory inspections, including evidence submission, query resolution, and remediation tracking
Information Security Compliance & Audits
Own end-to-end delivery of ISO 27001, SOC 2 Type II, PCI-DSS, and other certification audits — including evidence collection, auditor coordination, and remediation tracking
Partner with Engineering and Security to embed controls into product and infrastructure design
Drive closure of audit findings and monitor control effectiveness over time
Vendor & Third-Party Risk Management
Design and operate a vendor/third-party risk assessment program covering onboarding due diligence, periodic reviews, and offboarding
Review vendor contracts and SLAs for risk, security, and compliance clauses in partnership with Legal
Client & Stakeholder Assurance
Respond to security and compliance due-diligence questionnaires and audits from banking and NBFC clients
Represent Vegapay’s GRC posture in client and partner conversations, building trust with regulated BFSI customers
Prepare compliance dashboards, risk reports, and leadership/board updates
The…