Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
National Payments Corporation of India (NPCI) invites a senior cybersecurity and regulatory governance professional to oversee risk management, security controls, and third‑party cybersecurity assurance across NPCI ecosystems. The role requires coordinating with banks, TPAPs, CERT-In and other regulatory bodies while driving privacy and data protection commitments.
You will lead cross‑functional teams to implement robust security controls, ensure GDPR/DPDP and PCI DSS alignment, and guide
National Payments Corporation of India (NPCI) | Full Time
The National Payments Corporation of India (NPCI) is a pivotal institution in India's digital payments ecosystem, established by the Reserve Bank of India (RBI) and the Indian Banks’ Association (IBA). It operates under the Payment and Settlement Systems Act, 2007, and is incorporated as a “Not for Profit” company under Section 25 of the Companies Act 1956 (now Section 8 of the Companies Act 2013). NPCI is dedicated to building world‑class digital payment infrastructure through innovative and efficient retail payment platforms. As an Equal Opportunity Employer, NPCI is committed to fostering an inclusive workplace culture, with zero tolerance for discrimination based on race, ethnicity, disability, gender identity, or sexual orientation, including support for the LGBTQ+ community.
To learn more about our company please click on link AboutNPCI
TheNPCIWAY -OurGuidingPrinciples
At NPCI, we foster a culture of Inclusion, Innovation, and a High- Performance Workplace .
The NPCIWAY isnotjustaframework - it’sasharedcommitmentbyevery individual to align with our evolving business needs, dynamic market conditions, and workforce expectations.
Insurance&Wellness:
At NPCI, you’ll be part of a purpose-driven organization shaping the future of digital payments in India and beyond. NPCI offers a unique opportunity to work on cutting‑edge projects that directly impact millions. We foster a culture of innovation, inclusion, and high performance, where every individual is empowered to lead with purpose and deliver with passion. With a strong focus on employee wellbeing, continuous learning, and collaborative success, NPCI is more than just a workplace - it’s a platform to grow, contribute, and make a meaningful difference.
This role is responsible for ascertaining and overseeing the risk and security guidelines and controls applicable to third parties interacting with NPCI. It will ensure ecosystem‑wide compliance with evolving security requirements arising from innovations across the organization.
The core focus of the role will be to ensure that member banks and TPAPs comply with the standards laid down by NPCI. It will also interface with CERT‑In, NCIIPC, NCCC, RBI, MeitY and other government bodies on cybersecurity‑related matters.
The role will also play a key part in addressing privacy‑related aspects, including adherence to the DPDP Act, GDPR and other applicable data protection requirements.
Provide direction on regulatory compliance and cybersecurity protection.
Demonstrate a thorough understanding of international governance and management principles.
Engage with multiple stakeholders across organizational boundaries.
Develop and maintain robust international information security controls.
Provide an external perspective to strengthen the design and implementation of security controls.
Lead and review assessments for external agencies and members.
Make decisions regarding the maintenance of the security posture of the organization and its subsidiaries.
Identify emerging global cyber‑threat trends and align organizational strategy to address them.
Provide solutions to address international challenges related to security architecture.
Act as a subject matter expert (SME) across multiple internal security domains, such as Identity and Access Management (IAM), infrastructure security, application security cloud security, Data Privacy and DPDP Act.
Engage with development teams to enable DevSecOps.
Demonstrate SME‑level knowledge of key security and data protection standards and frameworks, such as GDPR, CIS, ISO 27001, NIST and PCI DSS.
Coordinating with external entities and multiple stakeholders on information security‑related matters.
Identifying security gaps and following up to ensure their closure.
Focusing information security operations on external parties and addressing data protection and privacy‑related concerns.
Reviewing and verifying controls relating to third‑party applications and member banks.
Certifying third parties associated with NPCI.
Reviewing information security controls and guidelines followed by TPAPs and member banks.
Effectively addressing various data‑related concerns, as required by the Data Protection Officer (DPO), and ensuring adherence to DPDP and GDPR requirements.
Conducting various third‑party audits to ensure acceptable levels of cyber hygiene.
Exceptions and approvals relating to third‑party risks.
Measures to strengthen ecosystem‑wide cyber hygiene.
Matters relating to data protection and privacy.