09 Aug
|
OpenFX
|
Bengaluru
The Problem
OpenFX processes billions of dollars in transaction volume every month across global corridors. Our backend systems power pricing, routing, settlement, reconciliation, compliance, and risk. These systems sit directly on the money path, where correctness, reliability, and latency are non negotiable. Our systems connect banks, liquidity providers, third party systems, internal applications, identity systems, and cloud infrastructure - all operating in real time.
As transaction volume and geographic footprint scale, so does our threat surface.
We face
- Sophisticated financial fraud attempts
- Account takeovers and identity abuse
- Insider risk
- Infrastructure exploitation
- Third-party integration risk
- Regulatory and compliance obligations
In fintech, a delayed alert is money lost. A missed signal is reputational damage. A weak process is regulatory exposure. Security cannot be reactive or checkbox-driven. It must be operational, measurable, 24/7 capable, and deeply integrated into how we ship and scale.
We need a SOC Lead who can build and own a high-performance security operations function - one that detects early, responds decisively, reduces systemic risk, and scales ahead of growth.
Our goal is to scale transaction volume with a security foundation that is stronger than the threats we face.
What You Will Actually Do & Ow nIn your first 6 to 12 months, you will
1. :Build and operationalize a fintech-grade SOC functio
- nDefine monitoring strategy across cloud, infra, identity, endpoints, and transaction system
- sEstablish detection coverage aligned to MITRE ATT&CK; and fraud threat model
1. sOwn incident response end-to-en
- dLead containment, eradication, and recovery for security incident
- sRun post-incident reviews with clear root cause analysis and systemic fixe
- sMinimize blast radius and reduce time to detect (MTTD) and respond (MTTR
1. )Design and mature detection engineerin
- gDefine high-signal alerting strategy (reduce noise, increase signal
- )Improve SIEM use cases, telemetry coverage, correlation rule
- sBuild measurable detection coverage map
1. sDefine security KPIs & KRI
- sTrack detection coverage, false positive rate, incident severity trend
- sEstablish executive dashboards with actionable metric
- sQuantify operational risk reductio
1. nEmbed SOC into engineering and product workflow
- sIntegrate security review into new feature launche
- sEnsure logging, telemetry, and auditability are designed upfron
- tPartner with backend, infra, and platform teams to close systemic gap
1. sReduce systemic financial ris
- kAlign security monitoring with transaction flows, reconciliation pipelines, and money movement control
- sDetect abnormal patterns in account behavior, API misuse, and privilege escalatio
1. nBuild and scale the SecOps tea
- mHire, mentor, and level up analysts and detection engineer
- sDefine shift models (if required), escalation paths, and on-call processe
- sEstablish a culture of ownership and precisio
1. nOperationalize compliance through executio
- nEnsure SOC processes support ISO 27001, PCI DSS, NIST, and regulatory requirement
- sProduce defensible evidence for audit
**s
What Success Looks Li**
keYou will be measured o
- n:Reduced security risk exposur e: Fewer critical incidents, reduced dwell time, measurable control maturi
- tyOperational excellence : Explicit runbooks, high-quality incident handling, low alert fatig
- ueDetection qualit y: High signal-to-noise alerts, proactive threat hunting, coverage against key attack vecto
- rsExecutive trust : Leadership has clear visibility into risk posture and remediation progre
- ssTeam quality : Analysts are strong, accountable, and growing; the SOC becomes a force multipli
- erSecurity embedded in product velocity : Engineering moves fast without increasing ri
**sk
Requireme**
ntsRequired (Non-negotiab
- le)8 to 12+ years in cybersecurity operati
- onsProven experience building or maturing a SOC in a complex environm
- entDeep experience in incident response and security investigati
- onsHands-on experience with SIEM platforms and detection rule engineer
- ingStrong knowledge of cloud security (AWS/GCP/Azure), identity systems, and SaaS teleme
- tryExperience defining KPIs, dashboards, and operational metr
- icsStrong leadership and team management experie
- nceAbility to communicate risk clearly to executives and non-technical stakehold
**ers
Strongly Preferred (Accelerates R**
- amp)Experience in fintech, payments, or high-transaction financial sys
- temsKnowledge of SOC 2, ISO 27001, NIST,
- CISExperience with EDR, SOAR, DLP, CASB, MDM, Email Secu
- rityFamiliarity with fraud detection models and transaction risk monito
- ringExperience in Product Security and CI / CD Secu
- rityCISSP, CISM, CISA, or equivalent certificat
ions
📌 Security Operations Center (SOC) Engineer (Bengaluru)
🏢 OpenFX
📍 Bengaluru