AndPayments is building the next-generation payments stack for Indian businesses, and for businesses globally that need India-grade payments infrastructure. We operate across Payments, RegTech, B2B SaaS and Prepaid Instruments. These are not separate bets. They are a deliberate stack: compliance infrastructure that enables payment products that enable financial instruments, all built together rather than bolted together.
We move fast because we have to. We care deeply about compliance because we build on regulated infrastructure, and because we believe compliance done right is a competitive moat, not just a cost of doing business. We use AI as a primary operating layer, not as a productivity add-on. If you want to spend the next few years building something that will define how Indian businesses transact, and eventually how businesses transact globally, this is where you should be.
About the role
Own end-user IT for a licensed payments company, and build the function from the ground up. You will be the single point of contact for everything IT at our Noida office: an all-Mac fleet, Microsoft 365, the office network, and getting every joiner productive from day one. Device management, the service desk, and endpoint security are greenfield here. You will stand all three up, then run them to a standard that holds up under a regulatory audit.
What you'll do
- Act as the single point of contact for IT support: triage, troubleshoot, and resolve hardware, software, peripheral, and network issues across our all-Mac fleet, with remote support for Mumbai and Pune.
- Manage the laptop lifecycle end to end: procurement, provisioning, repairs and warranty, secure wipe, and disposal.
- Administer Microsoft 365: Entra ID, Exchange Online, Teams, SharePoint, OneDrive, and license allocation.
- Own onboarding, offboarding, and logical access control: account creation, access provisioning, hardware handover, and complete revocation with asset recovery on exit, with an auditable record of every access grant and revocation.
- Administer physical access: issue employee IDs and office access cards, control access to server and network areas, revoke cards on exit, and keep the badge register reconciled against the live employee roster.
- Run the office network: Wi-Fi, internet uptime, firewall and router configuration, and ISP coordination.
- Select and deploy an MDM (Intune, Jamf, Kandji, or Mosyle), enrol the fleet through our Apple Business Manager, and use it to enforce FileVault encryption, OS and application patching, and controlled software installation on every Mac.
- Stand up the IT service desk from scratch: pick and configure the ticketing tool, define the intake path, set response and resolution targets, and build a self-service knowledge base so support is measurable instead of ad hoc.
- Deploy and operate endpoint, email, and data-loss prevention controls: anti-malware on every Mac, phishing and spam controls in Exchange Online, MFA and conditional access in Entra ID, and DLP policies across email, OneDrive, and SharePoint to stop cardholder and personal data leaving through end-user channels.
- Maintain the IT asset inventory, software licenses, and vendor and AMC records, and implement and enforce AndPayments IT policies.
- Produce the IT evidence our compliance programme runs on: access reviews, patch and encryption compliance reports, asset records, and offboarding proof, on the schedule our PCI DSS, SOC 2 and ISO 27001 audits require.
What we're looking for
- 5+ years of hands-on IT support experience in a corporate environment.
- Strong macOS troubleshooting across hardware, software, and peripherals.
- Hands-on experience deploying and administering an MDM for Macs (Intune, Jamf, Kandji, or Mosyle), including Apple Business Manager enrollment.
- Networking fundamentals: Wi-Fi, DHCP, DNS, VPN, and firewall configuration.
- End-to-end onboarding and offboarding experience, including access provisioning and revocation.
- Hands-on with Microsoft 365 security and compliance tooling: conditional access, email threat protection, and configuring DLP policies across mail and file storage.
- Experience administering a physical access control system, including card issuance, revocation, and register reconciliation.
- Experience building an IT function rather than inheriting one: selecting the tools, writing the process, and documenting it so it survives you.
- Working knowledge of the compliance obligations that land on IT: the CERT-In Directions of April 2022 (log retention, incident reporting timelines, clock synchronisation), the Digital Personal Data Protection Act, 2023, and the Information Technology Act, 2000, plus experience implementing organisational IT policies.
- Clear communication with non-technical users and disciplined documentation.
Required stack
macOS Microsoft 365 Entra ID Exchange Online Apple Business Manager MDM (Intune / Jamf / Kandji / Mosyle) FileVault Endpoint protection DLP Wi-Fi / DNS / DHCP / VPN Firewall Physical access control Service desk Asset management
Nice to have
- A recognised IT certification, for example Apple ACSP, Jamf 200, CompTIA A+ or Network+, or ITIL Foundation.
- Basic scripting: Bash, AppleScript, or PowerShell.
- Specific experience with Microsoft Purview DLP, Defender for Endpoint, or Defender for Office 365.
- Fintech or regulated-environment experience.
- Hands-on with Jira Service Management or a comparable service desk platform.
- Having been the IT evidence owner through a PCI DSS, SOC 2, or ISO 27001 audit.