About this role
Who are we?
We are a fast-growing AI-first fintech platform enabling banks, NBFCs, and financial institutions to launch and scale next-generation credit products , including credit cards, credit lines, lending, and payment solutions. Our platforms process high-volume financial transactions and power business-critical customer journeys where reliability, performance, and security are non-negotiable. We are looking for a Lead Security GRC Analyst who thrives in high-ownership environments, enjoys solving complex engineering challenges, and is passionate about building products that directly impact millions of users and financial institutions. For more details, please visit https://falconfs.com/ (https://falconfs.com)
Job Summary:
We are looking for an experienced Security GRC leader to own and scale our information security governance, risk, and compliance function. Reporting to the Security Architect, you will set the GRC strategy and roadmap, lead audits and regulatory engagements end-to-end, and manage a team of 1–2 GRC Analysts. This role is central to our position as a card issuer and issuer-processor, so a strong grounding in PCI DSS from the issuing side — and hands-on experience within the Indian fintech and payments ecosystem — is essential. You will partner closely with Engineering, Product, Risk, Internal Audit, and senior leadership to drive security and regulatory compliance across our card, wallet, and UPI platforms, mentor and develop your team, and represent the security program to leadership, auditors, and regulators.
Key Responsibilities:
- GRC Strategy & Program Ownership: Define, own, and continuously mature the organization's security GRC strategy, roadmap, and operating model, aligned with business objectives and the regulatory landscape.
- Team Leadership: Manage, mentor, and develop a team of 1–2 GRC Analysts; establish standards, playbooks, and ways of working; and build a scalable, repeatable GRC function.
- PCI DSS Compliance (Issuer / Issuer-Processor): Own and lead PCI DSS compliance from the card issuer and issuer-processor perspective — protecting cardholder data (PAN) and PIN data across the issuance and processing flows, including HSM-based key management (PCI PTS HSM), CDE scope definition and reduction, and end-to-end audit readiness. (This role is focused on the issuing side, not the merchant/acquirer or payment-application / PA-DSS perspective.)
- ISMS & Standards: Own and continually improve the ISO 27001 Information Security Management System, including risk registers, SOA, policies, and control evidence; drive management reviews and continual-improvement cycles.
- SOC 2 Type 2: Own the implementation, operation, and audit of SOC 2 Type 2 controls.
- CERT-IN / SAR / DLA: Lead and own SAR (System Audit Report) and DLA (Data Localisation Audit) compliance, managing relationships with CERT-IN empanelled auditors.
- Regulatory Engagement: Monitor RBI, NPCI, and other applicable regulations; translate requirements into internal controls and roadmaps; and serve as a key liaison for regulatory and partner-bank engagements.
- Risk Management: Own the enterprise information security risk program — risk assessments, control gap analysis, risk treatment, and reporting of residual risk to leadership.
- Audits & Assessments: Lead internal and external audits end-to-end, including ISO 27001, PCI DSS, SOC 2, and regulatory audits; drive remediation, track closure, and act as the primary escalation point.
- Policy & Process: Own the security policy framework — develop, review, approve, and maintain security policies, standards, procedures, and guidelines.
- Vendor Risk: Own the third-party/vendor risk management program and lead security assessments of vendors and partners.
- Security Awareness: Own and drive security awareness, training, and phishing simulation programs across the organization.
- Reporting & Governance: Prepare and present dashboards and reports for leadership, the board, auditors, and regulators; drive governance forums and risk committees.
Required Qualifications:
- 7–10 years of experience in Information Security Governance, Risk, and Compliance, with mandatory, hands-on experience in the Indian fintech / payments ecosystem (RBI/NPCI-regulated card, wallet, or UPI businesses), including experience leading GRC programs and/or teams.
- Hands-on PCI DSS experience from the card issuer / issuer-processor side — securing PAN and PIN data across issuance and processing — as opposed to a purely merchant/acquirer or payment-application (PA-DSS) background.
- Hands-on, in-depth experience with ISO 27001 and SOC 2 compliance.
- Strong, practical knowledge of RBI and NPCI guidelines relevant to payments, wallets, and card platforms.
- Proven experience owning and managing audits end-to-end across risk assessments, control frameworks, and remediation.
- Strong understanding of HSM concepts and key management for PCI DSS in an issuing environment.
- Demonstrated ability to lead and mentor analysts and influence cross-functional and senior stakeholders.
- Excellent communication, documentation, and executive stakeholder management skills.
- Relevant certifications such as CISA, CISM, CRISC, CGRC, ISO 27001 LA/LI are preferred.
Good-to-Have:
- Working knowledge of the Digital Personal Data Protection (DPDP) Act 2023.
- Exposure to AI security and AI governance frameworks.
- PCI QSA / ISA or similar audit credentials.
- Experience working in cloud environments (AWS, Azure, GCP).
What You Will Work On:
- Securing and governing a regulated payments ecosystem spanning credit cards, prepaid cards, wallets, and UPI credit lines — from a card issuer and issuer-processor standpoint.
- Driving and owning compliance maturity across ISO 27001, SOC 2 Type 2, PCI DSS (issuing side), and CERT-IN requirements.
- Building and leading a scalable GRC function and team that aligns with RBI and NPCI expectations.