- Location
- India
- Employment
- Full time
- Level
- Senior
- Posted
- 6 months ago
About this role
About Aspora
People on the move deserve a bank that moves with them. Since 2022, Aspora has been building a borderless financial operating system that makes money as mobile and transparent as its users.
Backed by influential venture capitalists like Sequoia Capital, Greylock Partners, Hummingbird Ventures, Y Combinator & Global Founders Capital. We're a team of 150+ across India, the UK, the UAE, EU and the US, working with extreme ownership, radical candour, and an obsession with customer impact.
We celebrate builders who question assumptions, ship fast, and turn regulatory complexity into elegant solutions. If you’re driven to redefine what global banking can be, we’d love to build the future with you.
About the Role
We're seeking a hands-on Senior Information Security Architect to design and implement security controls for our regulated digital banking platform. This is a builder role requiring deep technical expertise in cloud security, data protection, and regulatory compliance. You'll architect defensible, auditable, and scalable security systems that balance protection with product velocity.
Core Responsibilities
Technical Architecture (60%)
Design and implement zero-trust security architectures with clear boundaries, assuming breach scenarios and eliminating implicit trust
Build data protection systems including field-level encryption for PCI/PII data, cryptographic key management, and envelope encryption patterns
Architect hybrid cloud security for AWS-to-datacenter connectivity and vendor integrations with one-way trust models
Implement identity-first access controls with service-to-service authentication, zero standing production access, and time-bound sessions
Design SIEM and detection systems with logging strategies for legal evidence and correlation across identity, network, and application layers
Security Harden and maintain next-gen firewalls (Palo Alto, Fortinet) and their integration into our workloads, setup security observability
Operational Security (25%)
Own end-to-end vulnerability management including asset discovery, risk assessment, remediation, and crisis response (Log4j-style zero-day scenarios)
Lead incident response and disaster recovery including DR drills, incident command, regulatory notifications, and post-incident validation
Establish strategic monitoring with prioritized log collection, alert management, and security telemetry
Partner with Application and Infrastructure teams to understand their SecOps requirements and support the implementation of security solutions
Identify security gaps and drive initiatives aligned with business goals to strengthen overall security posture
Leadership & Strategy (15%)
Balance security and product velocity through compensating controls, pragmatic risk acceptance, and documented tradeoff decisions
Demonstrate scaling awareness by identifying architectural breaking points before they fail and designing for 10× organizational growth
Required Experience
7+ years in production AWS security for regulated or financial services environments
Proven PCI-DSS or financial regulatory compliance implementation experience
Hands-on incident response and DR drill leadership with real production scenarios
Startup or high-growth environment experience where you've built security programs from the ground up
Deep expertise in encryption architecture, key management systems, and cryptographic controls
Required Certifications
ISO 27001 Lead Implementer or Lead Auditor
PCI-DSS (QSA, ISA, or P2PE certification)
Additional certifications valued: CISSP, CCSP, AWS Security Specialty, CISM
#LI-AR
As published by Aspora. Applications are handled on their site.
Skills this posting mentions
About Aspora
Provider of financial services intended to provide non-dilutive funding to revenue-generating startups.
All 16 openings at AsporaOne click, then it is written
Apply to Aspora with a resume written for this role.
Queue Senior Information Security Architect and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Aspora’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 25 sent a week, free
- No card
- Nothing sent until you say so
More roles at Aspora
See all- 6 weeks ago
- 2 months ago
- 2 months ago
- 3 months ago
- 3 months ago
- 4 months ago
Similar roles elsewhere
See morePut this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board Aspora publishes. Refolk is not the employer and does not handle their hiring. Applications go to Aspora directly.