National Payments Corporation of India (NPCI) | Full Time
The National Payments Corporation of India (NPCI) is a pivotal institution in India's digital payments ecosystem, established by the Reserve Bank of India (RBI) and the Indian Banks’ Association (IBA). It operates under the Payment and Settlement Systems Act, 2007, and is incorporated as a “Not for Profit” company under Section 25 of the Companies Act 1956 (now Section 8 of the Companies Act 2013). NPCI is dedicated to building world-class digital payment infrastructure through innovative and efficient retail payment platforms. As an Equal Opportunity Employer, NPCI is committed to fostering an inclusive workplace culture, with zero tolerance for discrimination based on race, ethnicity, disability, gender identity, or sexual orientation, including support for the LGBTQ+ community.
Our Culture
TheNPCIWAY –OurGuidingPrinciples
At NPCI, we foster a culture of Inclusion, Innovation, and a High-Performance Workplace .
The NPCIWAY isnotjustaframework - it’sasharedcommitmentbyevery individual to align with our evolving business needs, dynamic market conditions, and workforce expectations.
FiveTenetsoftheNPCIWAY
- ForwardThinkingMind-Set
- CustomerFirst
- LeadWith Purpose
- PassiontoDeliver
- AllSucceedTogether
Employee Perks and Benefits
Insurance&Wellness:
- ComprehensiveCoverage :Medical,accidental,andlifeinsurance.
- Employee Assistance Program : Onsite medical center, financial/legal counselling, mental wellness.
- AnnualWellnessBouquet :Holisticwellbeingsupport
Family &Childcare
- ParentalLeave :Inclusivematernityandpaternityleave.
- Nanny at home Support: Assistance for Working Parents
Mobility&Lifestyle
- MobilityBenefits :Relocation,transfers,andtravelsupport.
- HomeLoanInterestSupport :Upto50%reimbursement*
- MobileReimbursement :Newhandsetevery2years.
- CarLease,SalaryAdvance,SubsidizedMeals.
- Reward&RecognitionProgram.
- TechnologyInnovation: PatentsandIPRightspolicy.
RetirementPlanning
- ProvidentFund(PF) and Gratuity Contributions .
Why Join Us
At NPCI, you’ll be part of a purpose-driven organization shaping the future of digital payments in India and beyond. NPCI offers a unique opportunity to work on cutting-edge projects that directly impact millions. We foster a culture of innovation, inclusion, and high performance, where every individual is empowered to lead with purpose and deliver with passion. With a strong focus on employee wellbeing, continuous learning, and collaborative success, NPCI is more than just a workplace - it’s a platform to grow, contribute, and make a meaningful difference.
NPCI is seeking an accomplished leader to Leadthe Market Information Security, Cyber Resilience and Privacy functionfor India's critical digital payments ecosystem. This is a high-impactstrategic leadership opportunity for a seasoned professional who can influencenot only enterprise security but also the cybersecurity, privacy, resilience,and trust posture of an entire financial ecosystem.
The role is responsible for defining anddriving market-wide cybersecurity strategy, information security governance,cyber resilience, privacy governance, regulatory compliance, and riskmanagement initiatives across banks, payment system participants, fintechs,third-party service providers, and other ecosystem stakeholders connected toNPCI platforms.
As a trusted advisor to regulators,industry bodies, financial institutions, and senior leadership, the incumbentwill drive initiatives that strengthen ecosystem resilience against cyberthreats, technology disruptions, privacy risks, systemic vulnerabilities, andevolving regulatory expectations. The role requires a forward-looking leadercapable of anticipating emerging risks, shaping industry standards, andfostering a culture of security, resilience, privacy, and trust across thepayments ecosystem.
Key Responsibilities
- Define and execute the Market Information Security, CyberResilience, and Privacy strategy aligned with NPCI's vision and regulatoryexpectations.
- Lead development and implementation of ecosystem-wide securitystandards, policies, frameworks, and control requirements.
- Drive initiatives to enhance cyber maturity, resilience, andoperational readiness across market participants.
- Provide strategic leadership on emerging technology risks,cloud security, AI security, digital trust, and cyber-defensecapabilities.
- Lead market-level cyber risk management and systemic riskassessment programs.
- Establish governance mechanisms for identifying, measuring,monitoring, and mitigating cybersecurity and technology risks.
- Drive third-party risk management, supply-chain security, andcritical dependency assessments across ecosystem participants.
- Develop risk-based frameworks and assurance mechanisms tostrengthen overall ecosystem security.
Privacy Governance & DPDP Readiness
- Drive privacy governance initiatives across ecosystemparticipants aligned with applicable privacy and data protection laws.
- Collaborate with stakeholders on privacy risk assessments,Privacy Impact Assessments (PIAs), Data Protection Impact Assessments(DPIAs), data classification, cross-border data sharing, consentmanagement, and privacy-by-design principles.
- Support implementation and monitoring of privacy controls,accountability frameworks, and data governance standards.
- Assess emerging privacy regulations and translate regulatoryexpectations into practical security and privacy controls.
- Partner with business, legal, compliance, and technology teamsto strengthen privacy compliance and data protection maturity.
Regulatory Compliance & Assurance
- Lead engagement with regulators, supervisory authorities,auditors, and industry bodies.
- Drive ecosystem-wide compliance assessments, security reviews,regulatory examinations, audits, and remediation programs.
- Ensure alignment with applicable cybersecurity, resilience,privacy, and regulatory requirements.
- Influence industry standards and contribute to regulatoryconsultations, working groups, and sector-wide initiatives.
Incident Preparedness & Resilience
- Lead cyber resilience programs including crisis management,cyber drills, tabletop exercises, threat simulations, andincident-response preparedness.
- Strengthen ecosystem readiness against cyberattacks,large-scale disruptions, systemic failures, and privacy-related incidents.
- Drive coordinated response mechanisms and information-sharinginitiatives across market participants.
- Build strong relationships with regulators, banks, fintechs,payment ecosystem participants, technology providers, auditors, andindustry forums.
- Act as NPCI's representative in cybersecurity, resilience,privacy, and governance engagements.
- Foster collaboration and collective defense strategies toaddress evolving threats and privacy challenges.
Executive Reporting & Governance
- Develop board-level dashboards, cybersecurity metrics, privacymetrics, risk indicators, and resilience maturity reports.
- Present strategic insights and recommendations to executivemanagement, Board Committees, and governance forums.
- Provide thought leadership on cyber threats, data protection,regulatory developments, and emerging technology risks.
Requirements
- Bachelor's or Master's degree in Engineering, Computer Science,Information Security, Cybersecurity, Privacy, Technology, or relateddisciplines.
- Minimum 15+ years of experience in Information Security,Cybersecurity, Privacy, GRC, Technology Risk, Audit, RegulatoryCompliance, or Cyber Resilience.
- Proven leadership experience within BFSI, Payments, FinancialMarket Infrastructure, FinTech, or other highly regulated sectors.
- Strong expertise in cybersecurity governance, informationsecurity, cyber resilience, privacy management, regulatory compliance,risk management, and audit.
- Deep understanding of financial-sector regulations,cybersecurity frameworks, privacy laws, DPDP requirements, resilienceframeworks, and industry standards.
- Proven experience engaging with regulators, auditors, Boards,senior executives, and external stakeholders.
- Demonstrated ability to influence policy, drive industry-wideinitiatives, and lead complex transformation programs.
- Excellent strategic thinking, analytical capability,stakeholder management, and leadership skills with the ability to operateeffectively at CXO, Board, and regulatory levels.
- Professional certifications such as CISSP, CISM, CISA, CRISC,ISO 27001 Lead Auditor/Lead Implementer, CIPT, CIPM, CIPP, CDPSE, orequivalent will be an added advantage.