Program Lead - Information Security

Khatabook

Bengaluru

On-site

INR 1,500,000 - 2,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Khatabook is seeking a Program Lead for Information Security to help implement and maintain security standards and ensure compliance with regulations. The ideal candidate will have over 8 years of experience in the field, with strong knowledge of ISO 27001 and SOC 2.

The role involves developing a governance, risk, and compliance program, auditing, and overseeing training on information security best practices. Join Khatabook in Bengaluru to empower MSMEs and drive security initiatives.

Qualifications

  • Excellent knowledge of ISO 27001, SOC 2, NIST, GDPR.
  • Strong analytical and problem-solving skills.
  • Exceptional communication and interpersonal skills.

Responsibilities

  • Implement and maintain security standards and regulations.
  • Develop and manage the governance, risk, and compliance program.
  • Lead ISO 27001 and SOC 2 compliance programs.
  • Conduct security awareness and training programs.
  • Manage vendor security assessments.

Skills

Information security standards
Analytical skills
Communication skills
Project management
Crisis management
Knowledge of Indian data protection laws
Experience in financial services

Education

8+ years of information security experience

Job description

Are you passionate about solving roadblocks & challenges faced by MSMEs in India? MSMEs contribute significantly to India’s total GDP. 90% of India’s ~\$1 Trillion Retail Market is controlled by Micro, Small & Medium Enterprises (MSMEs). Which means ~\$900B worth of commerce flows through these ~60M MSMEs in the form of shops/kiosks/homes, scattered all over the country. We at Khatabook, have a vision to empower MSMEs and help them increase their incomes. We have built a product that brings efficiency in MSME operations by providing them easy to use tools to manage their receivables, inventory and billing which creates transparency in their cash flow. Within the Khatabook platform, we have also enabled the facility to take loans for their short term working capital needs for select Khatabook users that are displaying good credit behavior. Our app has been downloaded over 100 Million times with a monthly active user base of 8 Million+ which are adding 220 Million+ transactions with a transaction value of $18 Billion.

Why work with us?

People are our biggest asset! At Khatabook, every one of us is a dynamic superstar. We have carefully bred an ecosystem which hires nothing but incredibly and exceptionally talented people who can dream, collaborate, experiment, and break new ground. We’re a strong team that looks out for each other.

Your Role: Program Lead – Information Security

As a Program Lead – InfoSec, you will be implementing and maintaining various security standards, regulations, and best practices (e.g., ISO 27001, SOC 2) while ensuring compliance with India’s data localization requirements through comprehensive risk management and audit programs. We’re seeking a seasoned security professional with 8+ years of experience who can translate complex security requirements into actionable policies, demonstrate strong stakeholder management skills, and bring hands‑on experience in building security programs that enable business growth while maintaining robust security controls.

What would you do at Khatabook?
  • Governance, Risk, and Compliance (GRC):
    • Develop, implement, and maintain the organization’s GRC program to ensure alignment with business objectives and regulatory requirements.
    • Identify, assess, and mitigate information security risks across the organization.
    • Establish and enforce policies, procedures, and controls to ensure compliance with applicable laws, regulations, and standards.
    • Coordinate with internal teams for security controls implementation.
    • Monitor and report on security metrics to senior management.
  • Audit Management:
    • Act as the primary point of contact for internal and external audits, including ISO 27001, SOC 2, and other relevant frameworks.
    • Prepare for and facilitate audits by coordinating with cross‑functional teams, gathering evidence, and addressing auditor inquiries.
    • Ensure timely remediation of audit findings and implement corrective actions to maintain compliance.
  • ISO 27001 and SOC 2 Implementation:
    • Lead the implementation, maintenance, and continuous improvement of ISO 27001 and SOC 2 compliance programs.
    • Conduct gap assessments and develop action plans to address deficiencies.
    • Manage the documentation of policies, procedures, and controls required for certification and recertification.
  • Security Awareness and Training:
    • Develop and deliver security awareness programs to educate employees on information security policies, procedures, and best practices.
    • Provide training to internal teams on GRC-related topics and audit readiness.
  • Vendor and Third‑Party Risk Management:
    • Assess and monitor the security posture of third‑party vendors and partners to ensure compliance with organizational standards.
    • Review and negotiate security terms in contracts and agreements.
What are we looking for?
  • Excellent knowledge of information security standards, regulations, and best practices (e.g., ISO 27001, SOC 2, NIST, GDPR).
  • Strong analytical and problem‑solving skills with the ability to assess complex security issues.
  • Exceptional communication and interpersonal skills, with the ability to interact effectively with technical and non‑technical stakeholders.
  • Detail‑oriented with strong organizational and project management skills.
  • Experience in managing security incidents and crisis situations.
  • Strong knowledge of Indian data protection laws and data localization requirements.
  • Experience in financial services or fintech industry is great to have.
  • Minimum 8 years of information security experience.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Business Analyst - Operations
Lead Business Analyst - Operations

Khatabook • Bengaluru

On-site
INR 800,000 - 1,200,000
Chief Information Security Officer
Chief Information Security Officer

ETCIO - Cloud Data Center • Pune District

On-site
INR 2,000,000 - 2,500,000
Manager - Information Security
Manager - Information Security

Easebuzz Private limited. • Pune District

On-site
INR 1,500,000 - 2,500,000
Financial Analyst
Financial Analyst

Khatabook • Bengaluru

On-site
INR 600,000 - 900,000
Module Lead Information Security
Module Lead Information Security

IDfy • Mumbai

On-site
INR 4,000,000 - 7,000,000
Information Security - Senior Security Manager
Information Security - Senior Security Manager

Paytm Payments Services • Dadri

On-site
INR 2,500,000 - 4,000,000
Growth Program Manager - Lending
Growth Program Manager - Lending

Khatabook • Bengaluru

On-site
INR 1,200,000 - 2,400,000
GRC Analyst – Information Security & Compliance
GRC Analyst – Information Security & Compliance

WeRize • Bengaluru

On-site
INR 800,000 - 1,200,000
Business Analyst - Product
Business Analyst - Product

Khatabook • Bengaluru

On-site
INR 600,000 - 1,000,000
Data Scientist - I
Data Scientist - I

Khatabook • Bengaluru

On-site
INR 1,000,000 - 1,500,000