Deputy Manager - Infosec
FlexiLoans · Mumbai
- Experience4–5 yrs
- SalaryNot disclosed
- Work modeonsite
- Posted1 Oct 2026
About FlexiLoans
FlexiLoans is hiring in Mumbai in financial services. This role looks for around 4+ years of experience.
Skills
- DPDP Act
- Identity and Access Management
- AWS
- Microsoft Azure
- Google Cloud Platform
- MFA
- PAM
- encryption
- data masking
- SAST
- DAST
- API security
- VAPT
- SIEM
- DLP
- incident response
- ISO 27001
- PCI-DSS
- NIST CSF
- RBI Master Directions
- CERT-In requirements
The role
An information security manager at a digital lending platform secures backend systems through Identity and Access Management, manages DPDP Act compliance, and coordinates VAPT. The role also applies ISO 27001 and incident response practices.
Full job description
Who we are:FlexiLoans is a technology based Digital financing platform started with an endeavor to solve the problems that small businesses face in accessing Quick, Flexible and Adequate funds for growing their Businesses. Our vision is to give "Financial access at a click". Our talent pool has rockstars from diverse backgrounds - ex- Founders, investment bankers, e-commerce and payments with the passion to make a difference to the lives of 70 mn+ MSME businesses in India.FlexiLoans.com is a pioneer in the ecosystem-based digital lending for small businesses in India. Till date, we have disbursed over 100,000+ loans worth over Rs. 5,000 Crs+ to small sized businesses across 3,200+ cities without having a single branch! We are the leaders in using technology and risk models that focus on alternate / surrogate methods for scoring customers. Our origination is 100% digital with over 100 embedded partnerships like Amazon, Flipkart, Nykaa, Paytm, Paisabazaar, META, etc. for providing credit access to MSME businesses.Founded by CA/ISB alumni, FlexiLoans is funded by marquee funds and HNIs in the form of MAJ invest, Fasanara Capital, Sanjay Nayar (Founder - Sorin Investments, Chairman - KKR India and Ex-CEO, Citibank South Asia), Dr. Harry Banga (Founder, Caravel group), Yogesh Mahansaria (Founder, Alliance Tyres) Gunit Chaddha (Ex-CEO, Deutsche Bank, Asia Pacific), Anil Jaggia (Ex-CIO, HDFC Bank), Vikram Sud (Ex-COO, Kotak Mahindra Bank), Narayan Seshadri (Ex-Managing Partner, KPMG), Gopal Srinivasan (Chairman, TVS Capital) and Siddharth Parekh (Co-Founder, Paragon Partners) to name a few.Our product offerings and value proposition can be accessed on our website: https://www.flexiloans.com/ Why join us?A six-times certified ‘Great Place to work’ workplace, at FlexiLoans you will be working with top tier talent from diverse backgrounds hungry to make a dent in the MSME universe. We believe in people owning what you do and providing support to folks for making decisions (sometimes even wrong decisions!) all the while learning and growing with the organization. FlexiLoans is your front row seat to the MSME Fintech revolution in India!
The role in a gist:The Deputy Manager, Information Security is a hands-on role that supports the CISO in executing the information security program at FlexiLoans. You will own day-to-day DPDP Act compliance and the security of our backend systems (databases, APIs, servers, and cloud infrastructure), while helping the company stay compliant with RBI Master Directions for NBFCs and CERT-In requirements.
What we are looking for in the role:Data Privacy & DPDP ComplianceExecute the DPDP Act 2023 compliance program, including consent management, data minimisation, and retention and deletion practices.Maintain data inventories, data flow maps, and records of processing across systems and vendors.Handle data principal requests (access, correction, erasure, grievance) within defined timelines.Conduct Data Protection Impact Assessments (DPIAs) for new products, integrations, and high-risk processing.Support breach notification workflows in line with DPDP and CERT-In timelines, and coordinate with the DPO, Legal, and Product teams.Backend & Infrastructure SecuritySecure backend systems, including the loan management system, databases, APIs, servers, and cloud environments (AWS / Azure / GCP).Manage and review Identity and Access Management controls, including MFA, PAM, and role-based access, with periodic access reviews.Apply encryption, key management, data masking, and data classification standards for data at rest and in transit.Review security configurations, patch status, logs, and alerts for backend assets, and escalate gaps.Support secure SDLC practices, including SAST, DAST, and API security reviews, and security sign-off for new releases.Vulnerability Management & AuditsCoordinate VAPT cycles, track findings, and drive time-bound remediation with technology teams.Support IS audits, RBI inspections, and ISO 27001 / PCI-DSS assessments, including evidence collection and closure tracking.Prepare audit closure reports and compliance dashboards for the CISO and Audit Committee.Security Operations & Incident ResponseMonitor SIEM alerts and work with the SOC (in-house or managed) on triage, escalation, and incident closure.Support incident response, including containment, root cause analysis, documentation, and CERT-In reporting.Track security KPIs and KRIs and contribute to periodic management reporting.Participate in cyber drills and tabletop exercises.Third-Party Risk & GovernancePerform security assessments of vendors, fintech partners, and cloud and outsourced service providers.Ensure security and data protection clauses are embedded in outsourcing and data-sharing agreements.Maintain security policies, SOPs, and the risk register, and run security awareness sessions and phishing simulations for employees.
Ideal Candidate:Hands-on exposure to securing backend systems, databases, APIs, and cloud infrastructure.Working knowledge of the DPDP Act, RBI Master Directions on IT Governance and Outsourcing, ISO 27001, NIST CSF, and PCI-DSS.Experience with VAPT management, SIEM, DLP, and incident response.Prior experience in BFSI, preferably an NBFC, bank, or fintech, with working knowledge of RBI IT and cyber security guidelines.
Qualification & Experience:Bachelor's degree in Engineering, Computer Science, IT, or a related field (Master's in Cybersecurity or IT preferred).4+ years of experience in information security, including at least 2-3 years in data privacy and IT compliance. (Prior experience in NBFC, bank, or fintech preferred)