Skip to main content
Posted 30 July, 2026

Senior Lead Information Security Analyst

Billtrust India Careers
Hyderabad, India Full Time
Reference: 102_757296_7812656003

Senior Lead Information Security Analyst

Billtrust is seeking a Senior Lead Information Security Analyst to own the end-to-end execution of our annual assurance audit portfolio. This is a hands-on leadership role - not a supervisory one - responsible for driving audit readiness, evidence quality, auditor relationships, and findings remediation across all of Billtrust's security and compliance certifications. You will serve as the subject matter authority for the Compliance & Risk team on all assurance frameworks, and as the operational lead coordinating across IT, Product, and Finance to deliver clean, on-time audit results.

This role reports to the Director, Compliance AML, who holds program-level ownership of the audit portfolio, and works closely with the VP, Compliance & Risk.

Assurance Frameworks Owned

  • SOC 1 / ISAE 3402
  • SOC 2 Type 2
  • ISO 27001
  • PCI DSS v4.0
  • NACHA
  • AML / BSA
  • HIPAA BAA

Key Responsibilities

Audit Program Execution

  • Own the annual audit calendar across all seven frameworks - planning, scoping, scheduling, and sequencing to avoid resource conflict
  • Lead control walkthroughs, evidence collection sprints, and auditor facilitation for each engagement
  • Serve as the primary point of contact for external auditors and certification bodies during fieldwork
  • Manage all audit deliverables through Sprinto (GRC platform), ensuring evidence is complete, current, and mapped to the correct controls before auditor submission

Controls & Remediation

  • Identify control gaps during readiness assessments and drive remediation to closure before audit fieldwork begins
  • Maintain the control library in Sprinto; update control mappings when framework requirements change (e.g., PCI DSS v4.0 transition, ISO 27001:2022)
  • Partner with IT and Product on technical control testing - access reviews, vulnerability scan reviews, configuration baseline checks
  • Track findings and management responses through the full lifecycle; escalate at-risk items to the Director with recommended remediation paths

Cross-Functional Coordination

  • Coordinate evidence owners across IT, Finance, Customer Support, and Product; build and maintain the annual evidence responsibility matrix
  • Brief control owners ahead of audit windows; coach non-technical stakeholders on what auditors expect
  • Support the Third Party Risk Management program on vendor compliance evidence when assurance frameworks require it

Reporting & Documentation

  • Produce pre-audit readiness scorecards and post-audit findings summaries for Director and VP review
  • Maintain audit workpapers, evidence repositories, and audit logs in accordance with each framework's documentation standards
  • Contribute to the annual compliance report and board-level assurance summaries

Qualifications

Required

  • 5+ years in information security, GRC, or IT audit, with at least 3 years directly supporting external assurance audits
  • Demonstrated hands-on experience across at least four of the seven frameworks listed above (SOC 1 or SOC 2, ISO 27001, PCI DSS, and NACHA or AML strongly preferred)
  • Direct experience managing auditor relationships during fieldwork - not just evidence collection support
  • Proficiency with a GRC platform (Sprinto, Drata, Vanta, Tugboat Logic, or equivalent)
  • Strong written communication; able to translate technical control narratives for non- technical audiences and auditors alike Bachelor's degree in Information Systems, Computer Science, Business, or equivalent

Work Experience

Preferred

  • Experience in a fintech, payments, or financial services environment
  • Prior exposure to NACHA Operating Rules and AML / BSA compliance program
  • Familiarity with SPRINTO GRC
  • Experience managing concurrent audit engagements (three or more frameworks in asingle calendar year)

Sign up for Job Alerts