Information Security Manager
Location : Mumbai
Designation : Information Security Manager
About the role
We're looking for someone to build BitDelta's information security function from the ground up — and stay hands-on while doing it.
This isn't a role where you'll inherit a team and a playbook. You'll create both. You'll design the security architecture that protects our live trading platform, run our penetration testing and red-team work, keep us compliant with the regulators who matter, oversee our SOC and incident response, and act as our Data Protection Officer.
It's a builder's job, and a technical one. We care most about strong security fundamentals. If you know crypto and blockchain, great — but you don't need to be an expert on day one. A solid high-level understanding is enough, and we'll teach you the rest. What we can't teach is a security-first instinct.
What you'll actually do
Security architecture and operations
You'll own the whole security picture — the exchange app, the APIs, and everything underneath. That means driving application security and secure development practices, staying on top of vulnerabilities as they surface, and hardening endpoints across our Mumbai offices. You'll run our 24x7 SOC monitoring, write the runbooks and escalation paths, and lead incidents from the first alert through to the post-mortem.
Offensive security
You'll plan and run penetration tests across the application, network, and infrastructure — including the live platform. You'll work with both internal and external red teams, think like an attacker to find gaps before anyone else does, and design phishing simulations and social engineering tests to keep everyone sharp. Then you'll chase every finding through to a fix.
Governance, risk, and compliance
You'll own our security governance — the policies, standards, and controls, aligned to ISO 27001, NIST, and general good practice. You'll handle regulatory queries from FIU-IND, CERT-In, and others, make sure our controls stay audit-ready, and support internal and external audits and risk assessments.
Data protection
As our DPO under India's DPDP Act 2023, you'll represent BitDelta on data-protection matters with regulators. You'll get to know our data deeply — how it moves, where it lives, who can touch it — and own classification, lifecycle management, privacy controls, DPIAs, and breach notifications.
Vendors and third parties
You'll manage our security service providers: setting clear SLAs, holding people to them, checking vendor security posture, and reviewing the security terms in contracts.
Building the team
You'll hire, structure, and mentor a security team from scratch — defining roles and growth paths, setting up processes and tooling that scale, and working closely with engineering, infrastructure, compliance, and operations.
What we're looking for
- Around 7–10 years in information security, with real technical depth — not just management experience.
- Strong hands-on grounding in infrastructure, network, application, and cloud security.
- Genuine penetration testing experience, comfortable with tools like Burp Suite, Nmap, and Metasploit.
- Solid GRC and regulatory background, ideally in fintech, BFSI, or another regulated space.
- Experience running or overseeing SOC/SIEM operations and incident response.
- Working knowledge of data protection principles and India's DPDP Act.
- A track record of building teams and processes from nothing.
- Clear communication — you can hold your own with regulators, auditors, and senior leadership
Nice to have
Certifications like CISSP, CISM, OSCP, CEH, or ISO 27001 Lead Auditor / Lead Implementer. Exposure to crypto, blockchain, or VDA platforms — or a real eagerness to learn.
A background in fintech, exchanges, or BFSI.
Prior DPO or privacy experience.
Recommended Jobs
Posted just now
Posted just now
Posted just now
Posted just now
Posted just now

