Ovii Job Board

Senior Information Security Architect

aspora

Bangalore, India • Onsite - Bangalore, India • Full-Time • 7+ years

Posted 2026-07-13 Tech & Engg

Apply on employer site

Job Description

Ovii's Interpretation of the Role

Aspora seeks a senior security architect to design zero‑trust, encryption, and compliance controls for its regulated digital banking platform. The role blends deep cloud security expertise with hands‑on incident response and a focus on balancing protection and product velocity.

Role Snapshot

  • Design zero‑trust security architectures
  • Implement data encryption and key management
  • Lead incident response and disaster recovery
  • Drive PCI‑DSS and ISO 27001 compliance
  • Collaborate with engineering on secure cloud deployments
  • Mentor security best practices across teams

Must-Have Requirements

  • Zero‑trust security architecture
  • AWS cloud security
  • PCI‑DSS compliance implementation
  • Encryption architecture & key management
  • Incident response & disaster recovery leadership
  • Vulnerability management
  • SIEM design & logging strategy
  • Next‑gen firewall configuration (Palo Alto, Fortinet)
  • Identity‑first access controls
  • AWS security
  • regulated financial services
  • PCI‑DSS compliance
  • ISO 27001 Lead Implementer or Lead Auditor
  • PCI‑DSS (QSA, ISA, or P2PE) certification

Nice-to-Have Signals

  • CISSP certification
  • CCSP certification
  • AWS Security Specialty certification
  • CISM certification
  • Startup or high‑growth environment experience
  • Scaling awareness for 10× growth
  • startup/high‑growth environment
  • CISSP
  • CCSP
  • AWS Security Specialty
  • CISM

Work Setup

  • Location: Bangalore, India
  • Work mode: ONSITE
  • Employment type: Full-Time

Not Specified in JD

  • Visa sponsorship
  • Salary range
  • Remote eligibility
  • Relocation
  • Notice period
  • Travel
  • Security clearance
  • Coding test
  • Portfolio
  • GitHub
  • Writing sample
  • Cover letter

What You'll Likely Work On

  • Architect zero‑trust and hybrid‑cloud security models for AWS‑to‑datacenter connectivity
  • Build field‑level encryption, key management, and envelope encryption for PCI/PII data
  • Design SIEM, logging, and audit‑ready detection systems across identity, network, and application layers
  • Configure and integrate next‑gen firewalls and security observability tools
  • Own end‑to‑end vulnerability management, risk assessment, and zero‑day remediation
  • Lead incident response, disaster‑recovery drills, and regulatory notifications
  • Partner with application and infrastructure teams to embed security controls and close gaps
  • Balance security controls with product velocity through pragmatic risk acceptance and scaling foresight

Good Fit If You Have

  • Hands‑on experience building security programs in startup or high‑growth environments
  • Proven track record implementing PCI‑DSS or other financial regulatory controls
  • ISO 27001 Lead Implementer or Lead Auditor certification
  • Deep expertise in encryption architecture and cryptographic key management
  • Experience leading real‑world incident response and DR exercises

Skills

  • Zero‑trust security design
  • AWS cloud security
  • PCI‑DSS compliance
  • Encryption & key management
  • Incident response & DR
  • Vulnerability management
  • SIEM & logging strategy
  • Next‑gen firewall configuration (Palo Alto, Fortinet)
  • Identity & access management
  • Security monitoring & telemetry