
ABOUT POCKETLY
Founded in 2019 by Aarav Bhatia and Navdeesh Ahuja, Pocketly is a Bengaluru-based fintech built to give young salaried professionals and self-employed individuals fast, dignified access to credit. What began as small-ticket, emergency personal loans has grown into a broader financial wellness platform, now spanning financial education resources and budget management tools alongside its core lending product - all delivered through a fully digital, minimal-KYC application process.
WHY JOIN POCKETLY
- Build, Don't Inherit: At 500 Cr AUM, we're at the inflection point where security needs a dedicated owner - this is a green-field mandate, not a maintenance role.
- Direct Leadership Access: Work closely with founders and senior management, with a real seat at the table on regulatory and risk decisions.
- High-Stakes, High-Impact: Sensitive financial data, RBI oversight, and rapid growth mean your decisions carry real weight from day one.
- Fintech at Scale: Join a well-funded, fast-growing lending platform serving young India, with the resources to invest seriously in security.
THE OPPORTUNITY
As Pocketly scales its loan book and expands its product suite, information security has become a board-level priority. We're looking for a Head of Information Security to define our security strategy from the ground up, serve as our primary interface with regulators including the RBI, and build the governance, operations, and culture needed to protect our customers and our business as we grow.
KEY RESPONSIBILITIES
Strategic Leadership:
- Define and implement Pocketly's overall Information Security strategy, aligned with business objectives and regulatory expectations.
- Act as the primary liaison with senior management and regulators (including RBI) on security-related matters.
- Establish and chair the Information Security Steering Committee.
Governance, Risk & Compliance (GRC):
- Ensure compliance with RBI cybersecurity and IT risk management guidelines for NBFCs/fintechs.
- Lead audits, regulatory inspections, and external assessments (ISO 27001, IS, SOC, etc.).
- Develop and maintain security policies, standards, and procedures.
Data Privacy & Protection:
- Ensure compliance with India's DPDP Act and global privacy regulations where applicable.
- Implement strong data classification, encryption, and retention policies.
Security Operations & Risk Management:
- Oversee security monitoring, incident detection, and response (SIEM, SOC).
- Perform regular risk assessments, vulnerability assessments, and penetration testing.
- Manage identity & access control, endpoint protection, and network security.
- Lead crisis management in case of cyber incidents.
Collaboration & Awareness:
- Partner with Engineering, IT, and Operations teams to embed security by design.
- Lead internal training, awareness programs, and phishing simulations.
QUALIFICATIONS & EXPERIENCE
- Education: Bachelor's degree in Computer Science, Information Technology, or related field (advanced certifications preferred).
- Experience: Minimum 5+ years in Information Security roles.
- Strong preference for candidates from lending, payments, or fintech organizations.
- Demonstrated ability to manage compliance with RBI and ISO 27001 frameworks.
- Certifications (preferred): CISSP, CISM, CISA, ISO 27001 Lead Auditor/Implementer, CEH.
KEY SKILLS
- Deep knowledge of cybersecurity frameworks (NIST, ISO 27001, RBI Master Directions).
- Strong leadership and stakeholder management skills.
- Hands-on experience in risk management, incident response, and regulatory compliance.
- Excellent communication and presentation skills (regulator and board-level interaction).
- Ability to balance business agility with robust security controls.
Didn’t find the job appropriate? Report this Job