
Job Description :
We are seeking a highly skilled and experienced AVP - Compliance & Information Security to lead our regulatory compliance, risk management, and security governance frameworks. In the fast-paced payment gateway industry, ensuring the highest standards of data security and regulatory adherence is paramount.
The ideal candidate will possess over 12 years of IT experience (with 10+ years dedicated to information security and compliance), demonstrating deep expertise in PCI DSS, ISO 27001, SOC 1/SOC 2, and DevSecOps. You will oversee end-to-end audit processes, drive risk assessments, and collaborate closely with executive leadership, technical architects, and external auditors to safeguard our payment infrastructure.
Key Responsibilities :
1. Compliance Governance & Audit Management :
- Regulatory & Industry Standards : Lead and maintain the implementation, maintenance, and surveillance audits for PCI DSS, ISO 27001:2013, SSAE 18 Type 2 (SOC 1/2), and ISO 22301 (BCMS).
- Audit Execution : Conduct routine spot audits, internal audits, and comprehensive risk assessments across various business locations and cloud environments.
- Policy Management : Develop, evaluate, and periodically review Information Security (IS) policies, standard operating procedures, and Root Cause Analysis (RCA) documentation.
- RFP & Vendor Assessment : Manage security questionnaires for RFPs/RFIs and perform robust Vendor Risk Assessments on third-party integrations and partners.
2. Application & Cloud Security Oversight :
- Secure Development (SSDLC) : Oversee integration of security into the CI/CD pipeline using DevSecOps best practices, ensuring rigid adherence to OWASP Top 10 standards.
- Vulnerability & Threat Management : Manage end-to-end Web Application and Network Vulnerability Management, leveraging SAST, DAST, IAST, and RASP frameworks.
- Cloud Compliance : Direct security audits for cloud infrastructure (specifically Microsoft Azure) and containerized environments using CIS benchmarks for Docker and Kubernetes.
- Identity & Access Management : Audit and review multi-factor authentication (MFA) and Identity & Access Management (IAM) tools (e.g., Okta, CyberArk).
3. Incident Management & Business Continuity :
- Incident Response : Supervise incident and change management workflows, including Firewall Rule Change Requests (FRCR).
- Disaster Recovery (BCP/DR) : Partner with cross-functional teams to design, test (Chaos testing), and refine Business Continuity and Disaster Recovery plans using performance monitoring tools (e.g., Dynatrace).
- Security Training : Design and execute organization-wide Information Security, Data Privacy, and Risk Awareness training programs.
Required Qualifications & Technical Skills :
Experience & Education :
Didn’t find the job appropriate? Report this Job