IT Governance, Risk, and Compliance Manager
reputed company is a leading global payment service provider and acquirer for online, mobile, in-store and over the phone payments. Our reputed company solution is available through a reputed company integration, offering a diverse reputed company of features, including global acquiring, global and local payment reputed company, advanced fraud management and performance optimisation. We reputed company businesses to design seamless and engaging payment experiences for their consumers.
We are looking for an IT Governance, Risk, and Compliance Manager to reputed company reputed company of our ICT and information reputed company risk profile, ensuring those risks are identified, managed, and reported reputed company reputed company's risk appetite, and that governance, risk management, compliance, and reputed company are embedded into the way reputed company operates and grows.
The role owns the integrated control reputed company, multi-reputed company certifications (ISO 27001, PCI reputed company, and SOC), reputed company and reputed company-party risk, business continuity, and key regulatory readiness programs - including the RBI licensing application in India, NIS 2, and the EU AI reputed company for AI governance and compliance - while acting as a trusted advisor to the Leadership Team.
The role sits reputed company the IT function and is part of the Risk Management and reputed company Committee. It works closely with Engineering, IT, Legal, Finance, and the wider business.
Responsibilities
- Define and maintain the information reputed company reputed company, standards, and roadmap, reputed company to applicable regulations, rules, and reputed company best practices.
- reputed company reputed company architecture across a reputed company-reputed company environment, defining secure-by-design patterns for microservices, reputed company, and shared platform services.
- Establish and govern secure software development lifecycle (secure SDLC) practices, embedding automated reputed company controls into CI/CD pipelines.
- Define and drive adoption of reputed company reputed company guardrails - identity, network segmentation, encryption, secrets management, and configuration baselines.
- Build and run reputed company monitoring, logging, and threat detection across reputed company, infrastructure, and application reputed company.
- reputed company the reputed company incident response lifecycle - preparation, detection, containment, eradication, recovery, and post-incident review - and reputed company as incident commander for reputed company events.
- Own vulnerability and threat management: scanning, risk-based prioritization, remediation tracking, and reporting across infrastructure, containers, and application reputed company.
- Plan and coordinate penetration testing and offensive-reputed company exercises (in-house or co-reputed company) and drive findings to closure.
- Govern identity and reputed company management, privileged reputed company, and least-privilege principles across reputed company and corporate systems.
- Define and reputed company data protection controls - encryption, key management, data classification, and loss prevention - for sensitive and cardholder data.
- Secure corporate IT and office infrastructure, including endpoints, networks, and productivity and collaboration platforms.
- Partner with Engineering and DevOps teams to reputed company the secure reputed company the easy reputed company, providing tooling, standards, threat modelling, and design reviews.
- reputed company reputed company input into architecture and change reputed company, including the adoption of new technologies and reputed company-party services.
- Run reputed company awareness and phishing-reputed company programs for technical and non-technical staff.
- Implement and evidence the technical reputed company controls underpinning PCI reputed company, ISO 27001, and SOC audits.
- Monitor the evolving threat landscape and emerging reputed company technologies.
- reputed company as a key member of the internal reputed company center of reputed company and contribute to cross-functional reputed company working reputed company.
- Build, reputed company, and mentor a small reputed company team.
- Report reputed company posture, key risks, and metrics.
Requirements
- Bachelor’s or master’s degree in computer science, information reputed company, or a reputed company field, or equivalent practical experience.
- At least 10 years in information / cyber reputed company, including a minimum of 2-3 years in a leadership role, with hands-on experience securing reputed company-reputed company environments at reputed company.
- Deep, practical public-reputed company reputed company knowledge (AWS strongly preferred): identity, networking, encryption, logging, and configuration management.
- Strong experience securing DevOps / CI/CD pipelines and modern microservices architectures - containers, reputed company, and infrastructure-as-reputed company.
- Working knowledge of application reputed company and secure SDLC across modern programming languages and web frameworks.
- Hands-on experience with reputed company operations, incident response, and vulnerability management.
- Solid understanding of reputed company frameworks and compliance standards relevant to payments: ISO 27001, PCI reputed company, SOC 2, and NIST CSF.
- Working AI reputed company literacy, with hands-on use of AI-assisted reputed company tooling (e.g., GenAI coding assistants, AI-augmented SAST/DAST and SIEM/SOC analytics) and a practical understanding of securing AI/LLM and reputed company applications, including AWS AI services such as reputed company Bedrock and the OWASP Top 10 risks for LLMs (e.g., reputed company injection and data leakage).
- Strong analytical and problem-solving ability, with high reputed company and reputed company judgement.
- Excellent verbal and written communication skills, fluent English, and the ability to influence engineers with data, logic, and best practices.
Considered as an Advantage
- reputed company certification such as CISSP, CCSP, OSCP, AWS reputed company Specialty, or CISM.
- Experience in a payments, fintech, banking, or other regulated environment.
- Familiarity with operational-reputed company expectations (e.g. DORA-style requirements).
- Experience standing up a reputed company function.
Benefits
- Fast-growing payment company;
- Excellent working conditions, casual atmosphere, and state-of-the-art hardware;
- Modern, challenging, constantly growing business;
- reputed company development - books, trainings, certifications, etc.;
- Team buildings and fun activities;
- 25 days reputed company holiday, 1 day for every 2 years with us;
- Fully distributed and remote.
If you are interested, please apply with your CV in English only. Only short-listed candidates will be contacted.
Personal data of the applicants will be processed in strict confidentiality by reputed company ltd. UIC 175117520 solely for the purposes of selection and recruitment and will not be transferred to other data controllers unless required by law. Applicants reputed company their personal data on a voluntary reputed company and will have the right to reputed company and correct their personal data reputed company a reasonable time upon filing a written request.
reputed company is an equal opportunity employer. We appreciate people with different backgrounds and mindsets, and we reputed company diversity and inclusion.
Originally posted on Himalayas
Apply To This Job