Associate — Audit and Infosec · 2 to 4 years of work experience · Bengaluru
Setu is working to reimagine financial products for the next billion users. How do you put a dent in India's economy when most of her population cannot afford insurance, credit, investments, etc. through the formal channels that you and I take for granted? If we break down financial products such as loans, insurance and investments into their fundamental building blocks, and offer them as APIs to businesses, they then package these APIs into highly custom apps, tailor-made for their specific customers, instead of a generic one-size-for-all approach that is the norm today. This also enables them to go live with a fintech product or service in a matter of days, not months. We believe that fintech will be a core part of every company's offering, and at Setu, we're building the infrastructure that will accelerate this.
Setu is an acquired entity of Pine Labs, one of the fastest growing fintech companies in India and rapidly expanding its footprint in Asia, UAE, and the US. At Pine Labs, we're looking for those who share our core belief — "Every Day is Game Day". We bring our best selves to work each day to realise our mission of enriching the world through the power of digital commerce and financial services.
We are seeking a dedicated and skilled Associate — Audit and Infosec. Financial services is a highly regulated sector, which means our mission of being a bridge between regulated financial institutions (asset partners) and fast-growing technology companies (developers) comes with a significant set of responsibilities, including audit and compliance. Our asset partners, including some of India's largest private and public sector banks, have very high expectations when it comes to a partner like us, who have direct access to their technical infrastructure. This includes vendor audits and certifications at the start of a relationship, as well as continuing audits on a set schedule. At present, we have an ISO 27001 certification and are compliant with data localisation requirements, and intend to build on this base to complete more relevant certifications.
This role reports to the Audit & Compliance Head. Implement, maintain, and improve a best-in-class information security, risk & compliance management framework, covering Setu at both the company and individual product level. Help manage and improve Setu's security, compliance, assessment, and penetration testing programs. Establish, in consultation with management, the level of risk Setu is willing to take and ensure it isn't breached. Work with Engineering, Customer Success, and other teams to improve security compliance and reduce risks. Review and update security policies and standards regularly. Plan, prepare for, and conduct process-led internal, external, and vendor audits. Ensure Setu achieves and maintains relevant certifications such as ISO 27001:2022, SOC2 Type 2, and data localisation, and proactively recommend new certifications/audits. Coordinate regular internal system and network audits, reviews, and tests to verify compliance with security policies and standards.
Minimum 2-4 years of prior experience in managing audit and compliance at a fintech or a regulated financial institution, with specific experience in frameworks and audits such as ISO 27001:2022, SOC, ReBIT, SOX and PCI DSS, and completed bank/financial institution vendor and technical audits in the past. Patient and detail-oriented, comfortable being the last line of defence. Process-driven, with a knack for building accountability into processes — checklists, TATs, and sanity checks. Well versed in the prevalent tools used in this domain, and values intelligent automation over throwing bodies at a problem.
We will spare no efforts to ensure that Setu empowers you to do the most important and impactful work of your career. Opportunity to work closely with the founding team who built and scaled public infrastructure such as UPI, GST, Aadhaar, etc. We care deeply about your growth, so we provide a fully stocked library and unlimited book budget, tickets to conferences and industry events, learning sessions with team members and external experts, and a learning and development allowance covering subscriptions, courses, certifications, and more. Kick-ass benefits include comprehensive health insurance for you and your family, personal accident and term life insurance, access to mental health counsellors, extraordinary coffee, and a beautiful office with lots of solid wood and natural light. Our culture code, "How We Move", centers on six elements: Take the shot, Sign your work like an artist, Be the sherpa, Be the CEO of what you do, Care with tough love, and Own tomorrow.