27 Aug
|
Nexedge Capital
|
Delhi
27 Aug
Nexedge Capital
Delhi
Infosec & IT Asset Management Lead - Nexedge Capital
Location: Delhi (HQ) - travel to Mumbai / other Nexedge offices as needed
Function: Technology & AI Initiatives
Reports to: Head of Technology & AI Initiatives
About the role
Nexedge Capital is a SEBI-registered wealth management and investment advisory firm scaling its technology stack across Delhi, Mumbai, Kolkata, Bengaluru, Chandigarh, Jaipur, and Surat. As we grow our Azure footprint and AI tooling, we need someone to own two things that are currently under-owned: information security and IT asset management - as one combined charter, not two half-jobs.
This is a build-the-function-from-scratch role. You'll take control of what we run on Azure, put real security governance and incident response in place, and drive us toward ISO certification. If you like inheriting clean, mature environments, this isn't that role - if you like establishing the environment yourself and being the person who decided how it works, it is.
What you'll own
IT Asset Management (Azure & beyond)
- Build and maintain a single source of truth for all Nexedge Azure resources - subscriptions, resource groups, storage (ADLS Gen2), compute, networking, and licensing - across both entities (Nexedge Distribution Services and Nexedge Investment Adviser)
- Establish tagging, ownership, and lifecycle policies so nothing is provisioned or left running without accountability
- Track software licensing, endpoint inventory (laptops, mobiles under Intune MDM), and third-party SaaS subscriptions firm-wide
- Own cost visibility and rightsizing - flag orphaned resources, unused licenses, and avoidable spend
Information Security
- Own and continuously improve security architecture across Azure infrastructure - including Azure Firewall Premium / SSL inspection, identity and access management, and endpoint controls via Intune
- Write, implement, and maintain an incident management policy - detection, triage, escalation, containment, and post-incident review - and be the person who runs the room when something goes wrong
- Manage vulnerability management and patch cadence across cloud and endpoint estate
- Own access reviews and least-privilege enforcement, particularly around the arm's-length data segregation required between NDS and NIA under SEBI Reg. 22
- Lead ISO 27001 certification end to end - gap assessment, ISMS documentation, control implementation, internal audit prep, and external audit liaison
- Support broader regulatory security requirements relevant to a SEBI-registered entity, including alignment with DPDPA obligations on data handling and cross-border transfer
Securitisation & Documentation
- Document security policies, standards, and runbooks so security isn't tribal knowledge held by one person
- Work with legal/compliance on vendor risk assessments and data processing agreements involving client data
- Partner with the AI/tech team to ensure new tools (Nex AI, internal Claude workspace,
third-party integrations) meet security and data-handling standards before go-live
What we're looking for
- 5+ years in information security and/or IT infrastructure roles, ideally with direct ownership of at least one full ISO 27001 certification cycle
- Hands-on Azure experience - you should be comfortable auditing and hardening a live workplace, not just reading about one
- Working knowledge of incident response frameworks and the discipline to write policy that people can actually follow under pressure
- Experience with IT asset management practices - inventory, lifecycle, licensing - at an organizational level
- Understanding of financial services or regulated-industry security requirements (SEBI, RBI, or equivalent) is a strong plus
- Comfortable working directly with leadership, compliance, and external auditors - this role talks to a lot of different people
- Someone who documents as they go, not after the fact
Good to have
- Prior experience with Microsoft Intune, Azure AD/Entra, and Microsoft 365 security tooling
- Exposure to DPDPA or other data protection regulation implementation
- Certifications: CISSP, CISM, ISO 27001 Lead Implementer/Auditor, or equivalent
What you'll get
- A green-field mandate - you're not maintaining someone else's system, you're building the one that doesn't exist yet
- Direct visibility to leadership; security and asset governance report into the technology function, not buried under general IT
- The chance to shape how a growing wealth management firm handles security and compliance as it scales
📌 Infosec & IT Asset Management Lead (Delhi)
🏢 Nexedge Capital
📍 Delhi