HamburgerMenu
iimjobs

Posted by

Rewa Singh deo

Partner at Crest'XO

Last Active: 09 October 2026

Job Views:  
249
Applications:  76
Recruiter Actions:  44

Posted in

IT & Systems

Job Code

1737599

Chief Information Security Officer - IT Governance & Risk - Information Security

Crest'XO.12 - 15 yrs.Bangalore/Mumbai
Posted 6 days ago
Posted 6 days ago

Key responsibilities:

Regulatory compliance and governance:

- Keep technology processes and policies compliant with the IT Act and with regulatory and statutory requirements, including RBI, SEBI, UIDAI and GDPR, working with internal and external stakeholders.

- Track new government and regulatory guidelines on information technology and data security, and translate them into action for the business.

- Run the IT committee calendar as required by the regulator and the Information Security Manual, and circulate minutes to members and business heads.

- Maintain business-wise IT infrastructure records that the Compliance and Legal teams need for regulatory filings.

- Review and complete mandatory IT submissions to regulatory bodies.

IT policies and procedures:

- Draft IT and information security policies and make sure they are followed at the operating level.

- Keep the Information Security Manual and internal IT manuals current with regulation, business needs and technology changes.

- Review processes periodically, flag the risks behind any gaps, and issue advisories to close them.

- Introduce new policies based on audit observations and on industry benchmarking relevant to the business.

- Set up and run vendor risk assessments and audits, and follow through on remediation.

- Ensure key controls are executed consistently and that audit trails are available.

Risk assessments and audits:

- Plan and manage IT and information security risk assessments, IT audits and VAPT with internal teams, external auditors and vendors.

- Lead periodic internal and external audits covering systems, processes and policies.

- Close audit findings by amending existing controls or introducing new ones.

Cyber security and incident management:

- Design, implement and maintain the Cyber Crisis Management Plan.

- Make sure the right cyber security safeguards are designed and in place.

- Lead incident management and resolution, and report incidents to management and the relevant regulators.

- Provide IT and security information to partner functions and business teams when needed.

Business continuity and disaster recovery:

- Formulate, review and monitor business continuity plans and their implementation.

- Coordinate BCP and DR drills and present the findings to management.

- Keep BCP and DR plans updated as the business and technology landscape changes.

What we are looking for:

Must have:

- 10+ years of professional experience in information security, IT risk or IT governance.

- Hands-on experience implementing and auditing SOC 2 Type II (Trust Services Criteria).

Experience and skills:

- ISO 27001 readiness, implementation and audit.

- SOX IT general controls (ITGC).

- Strong command of information security concepts, principles and best practices.

- Clear communication with internal and external stakeholders, and the ability to explain security and risk to both technical and non-technical audiences.

- A collaborative working style across technology, compliance, legal and business teams.

- High personal integrity and sound judgement in handling confidential matters

Didn’t find the job appropriate? Report this Job

Similar jobs that you might be interested in

Posted by

Rewa Singh deo

Partner at Crest'XO

Last Active: 09 October 2026

Job Views:  
249
Applications:  76
Recruiter Actions:  44

Posted in

IT & Systems

Job Code

1737599

Loading chat...