Position- Compliance Officer
Department- Risk, Governance & Compliance
Experience Required
3+ years overall experience in information security / compliance. of which 2 years' experience working directly with RBI-regulated entities (bank, NBFC, or payment aggregator), including hands-on involvement in at least one RBI System Audit Report (SAR) cycle and/or NPCI compliance audit.
Qualification- Graduation (any discipline); a background in IT, Information Security, Finance, or Law is preferred
Mandatory Certification- CISA (Certified Information Systems Auditor)
Core KPIs- Zero Audit Non-Compliance & 100% System Uptime
Role Overview
The Compliance Officer will own the end-to-end regulatory and certification compliance posture of the organization, acting as the primary liaison between the company, its auditors, the partner bank, NPCI, and regulatory bodies including RBI and CERT-In. This role is critical to maintaining the company's license to operate within India's payments ecosystem and requires direct, demonstrable experience navigating RBI and NPCI compliance cycles.
Key Responsibilities
Audit Ownership
• Lead the end-to-end certification process for ISO 27001, PCI DSS, and SOC 2 Type II.
• Own preparation, evidence collection, and closure for all internal and external audits.
Technical Liaison
• Manage the relationship with CERT-In auditors for annual and quarterly VAPT cycles.
• Coordinate VAPT scope, remediation tracking, and closure across network, application, and cloud layers.
Regulatory Reporting
• Prepare and submit "Cyber Security Adequacy" reports to the partner bank and NPCI (for UPI/Card interactions) on a quarterly/annual basis as per applicable SLAs.
• Own preparation and submission of the annual RBI System Audit Report (SAR) via a CERT-In empanelled auditor.
• Ensure ongoing compliance with RBI's Master Directions on IT Governance and the Cyber Security Framework for Payment System Operators.
Privacy by Design
• Act as the Data Protection Officer (DPO