- Experience
- 10+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 3 hours ago
- Work mode
- Work from home
- Education
- Bachelor's or master's degree in computer science, information security, or related field
- Resume
- Required to apply
Job description
About emerchantpay
emerchantpay is a global leader in payment services, facilitating transactions online, via mobile, in-store, and telephonically. Their comprehensive payment solutions feature global and local acquiring, an expansive array of payment methods, sophisticated fraud management, and performance optimization to help businesses craft smooth and engaging payment experiences.
Role Overview
We seek an IT Governance, Risk, and Compliance Manager to oversee the company's ICT and information security risk profile, ensuring risks are identified, managed according to the organization's risk appetite, and that governance, risk management, compliance, and resilience principles are integrated into daily operations and expansion strategies. The position holds accountability for the integrated control framework, maintains certifications such as ISO 27001, PCI DSS, and SOC, manages enterprise and third-party risks, oversees business continuity efforts, and drives key regulatory initiatives including RBI licensing in India, NIS 2, and compliance with the EU AI Act. This role reports into the IT department and participates in the Risk Management and Oversight Committee, collaborating with Engineering, IT, Legal, Finance, and other teams.
Key Duties
- Develop and maintain a comprehensive information security strategy, standards, and roadmap aligned with relevant regulations and industry best practices.
- Guide the security architecture within a cloud-native environment, establishing secure-by-design patterns for microservices, APIs, and shared platform services.
- Implement governance over secure software development lifecycle (SDLC) practices with integrated automated security controls in CI/CD pipelines.
- Define and enforce cloud security guardrails including identity management, network segmentation, encryption, secrets management, and configuration baselines.
- Operate security monitoring, logging, and threat detection across cloud infrastructure and applications.
- Lead the security incident response lifecycle, taking charge during security events from preparation through recovery and review.
- Manage vulnerability and threat programs involving scanning, prioritization, remediation tracking, and reporting covering infrastructure, containers, and application code.
- Organize penetration testing and offensive security exercises and ensure resolution of findings.
- Oversee identity and access management enforcing privileged access and least-privilege principles across cloud and corporate systems.
- Define and manage data protection measures including encryption, key management, data classification, and loss prevention for sensitive and cardholder information.
- Secure corporate IT and office infrastructure such as endpoints, networks, and collaboration platforms.
- Partner with Engineering and DevOps to provide secure tooling, standards, threat modeling, and architectural reviews to simplify security adoption.
- Provide security guidance on architecture and change management, including third-party technologies.
- Run security awareness and phishing resilience training for both technical and non-technical employees.
- Implement technical controls required for certifications including PCI DSS, ISO 27001, and SOC audits.
- Keep abreast of evolving threats and emerging security technologies.
- Engage as an active member in internal security centers of excellence and cross-departmental security groups.
- Build and lead a small security-focused team.
- Report on security posture, risks, and relevant metrics to leadership.
Qualifications and Experience
- Bachelor’s or master’s degree in computer science, information security, or related disciplines, or comparable experience.
- Minimum 10 years in information or cybersecurity roles with at least 2-3 years in management, having practical experience securing large-scale cloud-native platforms.
- In-depth practical knowledge of public cloud security, particularly AWS, including identity, networking, encryption, logging, and configuration management.
- Experience securing DevOps environments, CI/CD pipelines, microservices architectures including containers and APIs, and infrastructure as code.
- Familiarity with application security and secure software development practices across modern programming frameworks.
- Hands-on expertise in security operations, incident response, and vulnerability management.
- Strong understanding of information security frameworks and payment industry standards such as ISO 27001, PCI DSS, SOC 2, and NIST CSF.
- Competence in AI security concepts with practical use of AI-based security tools, including securing AI applications and knowledge of related vulnerabilities.
- Excellent analytical capabilities, integrity, sound judgment, and effective communication skills in English.
Preferred Qualifications
- Certifications like CISSP, CCSP, OSCP, AWS Security Specialty, or CISM.
- Experience in regulated sectors such as payments, fintech, or banking.
- Awareness of operational resilience frameworks such as DORA.
- Experience establishing security functions.
Benefits
- Dynamic and expanding payment company atmosphere.
- Relaxed work environment with advanced hardware.
- Engagement in a modern, challenging, and continuously evolving business.
- Opportunities for professional growth, including books, training, and certifications.
- Team events and enjoyable activities.
- 25 days annual paid leave plus additional day for every two years employed.
- Fully remote and distributed working model.
Additional Information
Applications must be submitted with a CV in English. Only shortlisted candidates will be contacted. Applicants' personal data will be handled securely and only used for recruitment purposes by emerchantpay ltd. The company promotes equal opportunity and respects diverse backgrounds and viewpoints.