hirly

Vegapay Technology Private Limited

Head of Information Security

Bengaluru, India

Apply through hirly

hirly scores this role against your resume, shows its reasoning, then writes a resume and cover letter for it and fills the application with you. Free to start — no card required.

hirly's read of this role

Seniority
Lead / management
Country
IN
Work mode
On-site / unstated
First seen by hirly
23 Sept 2026

Derived automatically from the posting. Sign up to see how the role scores against your own resume.

the posting

The Impact You'll Drive

We're looking for a Head of Information Security to own and scale Vegapay's end-to-end security posture across infrastructure, applications, and DevOps pipelines. You will set the security vision and strategy, build and lead a high-performing security team, drive compliance across global standards, and build robust systems to proactively detect, prevent, and respond to threats in a highly regulated fintech environment. This is a leadership role reporting into senior engineering/executive leadership, with direct accountability for the organization's security posture at a strategic and operational level.

The Hats You Will Wear

  • Define and own Vegapay's security strategy, roadmap, and architecture across infrastructure, applications, and data
  • Build, mentor, and lead a team of security engineers and analysts, establishing clear ownership and growth paths
  • Own and strengthen identity, access, and endpoint security across the organization (SSO, MFA, RBAC, least privilege, device controls)
  • Lead infrastructure and application security, including vulnerability assessments, penetration testing, secure coding practices, and DevSecOps integration across CI/CD pipelines
  • Build and operate real-time threat detection and response systems across cloud and endpoints, ensuring robust monitoring, alerting, and data protection standards
  • Design and scale security automation, including SIEM, incident response playbooks, and integrated alerting workflows across systems
  • Own end-to-end compliance across PCI DSS, ISO 27001, SOC 2, and CICRA, including audit readiness, risk management, and continuous compliance monitoring
  • Act as the primary point of contact for security matters with auditors, regulators, banking/NBFC partners, and enterprise customers
  • Lead security awareness initiatives, including phishing simulations and strengthening defenses against social engineering threats
  • Partner with engineering, product, and leadership to embed security into the culture and roadmap of the organization

The Perfect Fit

  • 10+ years of experience in information security, with at least 3-5 years in a leadership or team-management capacity
  • Strong experience with security tooling across SIEM, DevSecOps, cloud security, and vulnerability management
  • Hands-on expertise with AWS security ecosystem, IAM hardening, and infrastructure security
  • Proficiency in scripting (Python, Bash) and securing IaC (Terraform, Ansible)
  • Deep understanding of modern security frameworks and threat models (OWASP, MITRE ATT&CK, CIS)
  • Proven experience owning compliance programs for global security standards, including direct engagement with auditors and regulators
  • Demonstrated ability to build and scale a security function and team from the ground up
  • Ability to balance hands-on execution with strategic, org-wide ownership

Your Edge Over the Rest

  • Certifications like CISSP, OSCP, CISA, CEH, or CCSP
  • Experience in FinTech, SaaS, or regulated environments, ideally at leadership level
  • Prior experience as a Head of Security, CISO, or similar senior security leadership role
  • Strong stakeholder management and cross-functional collaboration skills, including with executive leadership and external regulators

The Problem We’re Solving

Financial institutions today are held back by legacy systems that are slow, rigid, and expensive to scale. Launching or evolving credit, lending, and UPI products often takes months, requires heavy engineering effort, and limits the ability to create personalized customer experiences.

At the same time, customer expectations have changed - speed, flexibility, and tailored financial products are no longer optional. Banks and fintechs need infrastructure that allows them to innovate quickly, adapt continuously, and scale without friction.

This is where we come in.

At Vegapay, we are building modern, configurable fintech infrastructure that enables banks, NBFCs, and enterprises to design, launch, and manage credit and payment programs with ease. Our platform brings together flexibility, speed, and control - helping our partners unlock new growth opportunities and deliver personalized banking experiences at scale.

The Opportunity Ahead

  • Play a pivotal role in defining and owning Vegapay's security architecture and practices as we build a category-defining fintech infrastructure company
  • Own security at a strategic, organization-wide level
  • Operate at the intersection of scale and regulation
  • Build, shape, and lead a high-performing security team
  • High ownership, high accountability environment with direct visibility to leadership

Is this role actually a fit for you?

hirly answers with a score and its reasoning, then writes the resume and cover letter if you decide to go for it.

Score it against my resume
Head of Information Security at Vegapay Technology Private Limited — hirly