HamburgerMenu
iimjobs

Posted by

Job Views:  
522
Applications:  139
Recruiter Actions:  0

Posted in

IT & Systems

Job Code

1715664

Flexiloans - Chief Information Security Officer

Epimoney.10 - 15 yrs.Mumbai
Posted 1 month ago
Posted 1 month ago

The role in a gist:

The Chief Information Security Officer (CISO) is a senior executive role responsible for defining, driving, and overseeing the enterprise information security strategy of FlexiLoans. The CISO will ensure the confidentiality, integrity, and availability of all information assets across the organisation, while ensuring full compliance with RBI Master Directions on IT Framework for NBFCs, the Digital Personal Data Protection (DPDP) Act 2023, and evolving global cybersecurity standards.

Strategic Leadership & Governance:

- Develop, implement, and continuously evolve a comprehensive Enterprise Information Security Program aligned to the company's business strategy, growth objectives, and risk appetite.

- Establish and maintain the Information Security Governance framework including policies, standards, procedures, and controls in line with ISO 27001, NIST CSF, and RBI guidelines.

- Serve as the primary executive interface for the Board of Directors, Risk Committee, and Audit Committee on all matters related to cybersecurity risks, threat landscape, and mitigation roadmaps.

- Define and manage the Information Security budget, ensuring optimal allocation of resources across preventive, detective, and corrective controls.

- Partner with the CEO, CTO, CFO, and COO to embed security as an enabler of business growth rather than a constraint.

Regulatory Compliance & Audit:

- Ensure full and timely compliance with RBI Master Directions on IT Framework for NBFCs, including requirements on IT Governance, IS Audit, Cyber Security Framework, Business Continuity, and Outsourcing Risk.

- Ensure compliance with the Digital Personal Data Protection (DPDP) Act, including appointment and coordination with the Data Protection Officer (DPO), consent management, and data principal rights.

- Maintain compliance with PCI-DSS for payment data handling, CERT-In incident reporting mandates, and applicable ISO/IEC standards.

- Oversee all IS Audits, both internal and external, as mandated by RBI including Information Systems Audit by CERT-In empanelled auditors.

- Manage and lead the organisation's Vulnerability Assessment & Penetration Testing (VAPT) programme on a scheduled and on-demand basis.

- Track all audit findings, drive time-bound remediation, and present closure reports to the Audit Committee.

- Liaise proactively with RBI, CERT-In, and other regulatory bodies on cybersecurity disclosures, incident reporting, and policy consultations.

Security Operations & Incident Management:

- Direct the Security Operations Center (SOC) whether in-house or managed ensuring 24x7 monitoring, threat detection, and real-time response capability.

- Implement and maintain a SIEM (Security Information and Event Management) platform within defined use cases, correlation rules, and escalation thresholds.

- Develop, test, and maintain a robust Cyber Incident Response Plan (CIRP) covering detection, containment, eradication, recovery, and post-incident review.

- Lead all major security incident responses, including coordinating forensic investigations, regulatory notifications (CERT-In within 6 hours as per mandate), and customer/partner communications.

- Establish and track Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) for security operations reporting regularly to management and the Board.

- Conduct regular cyber drills, tabletop exercises, and red team / blue team exercises to test and improve incident preparedness.

Architecture & Risk Management:

- Oversee the secure design and review of FlexiLoans' digital lending applications, APIs, mobile platforms, and cloud infrastructure (AWS / Azure / GCP).

- Implement and maintain Zero Trust Architecture (ZTA) principles across the enterprise network, applications, and data layers.

- Ensure robust Identity and Access Management (IAM) controls, including Multi-Factor Authentication (MFA), Privileged Access Management (PAM), and Role-Based Access Control (RBAC).

- Review all new technology implementations, system integrations, and platform changes from a security perspective establishing Security by Design as a standard practice.

- Govern application security testing including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and API security assessments.

- Manage encryption standards, key management policies, and data classification frameworks for all data at rest and in transit.

Third-Party & Vendor Risk Management:

- Establish and operationalise a Third-Party Risk Management (TPRM) framework to assess the information security posture of all vendors, fintech partners, cloud service providers, and outsourced service providers.

- Conduct periodic security assessments of critical third parties and embed information security requirements in all outsourcing contracts, as mandated by RBI outsourcing guidelines.

- Maintain an approved vendor register with security ratings and periodic review schedules.

Data Privacy & Protection:

- Lead the organisation's data privacy programme in compliance with the DPDP Act 2023, ensuring appropriate consent frameworks, data minimisation, and data retention/deletion policies are in place.

- Coordinate with Product, Technology, and Legal teams to embed privacy-by-design principles in all product development and data handling processes.

- Conduct Data Protection Impact Assessments (DPIAs) for high-risk data processing activities.

- Manage data breach notification processes in accordance with DPDP Act timelines and CERT-In reporting obligations.

Culture, Awareness & Capability Building:

- Champion a culture of security awareness across the organisation through mandatory training programmes, phishing simulations, and role-specific security education.

- Build and mentor a high-performing information security team, defining clear roles, career development pathways, and succession planning.

- Drive security awareness at the Board level through regular reporting on threat intelligence, emerging risks, and the company's security posture.

- Engage with the wider fintech and BFSI security community to stay abreast of emerging threats, regulatory developments, and best practices.

Ideal Candidate:

- Industry Background: Mandatory prior experience working within the BFSI sector (preferably in an NBFC, Bank, or Fintech) with a deep understanding of financial regulatory frameworks (RBI guidelines) with CISO certification.

- Proven track record of building and managing an independent Information Security function and budget.

Qualification & Experience:

- Masters degree in Computer Science, Information Technology, Cybersecurity, or a related field.

- Experience: Minimum of 10+ years of experience in Information Security, with at least 5+ years as a CISO or Department Head.

Didn’t find the job appropriate? Report this Job

Similar jobs that you might be interested in

Posted by

Job Views:  
522
Applications:  139
Recruiter Actions:  0

Posted in

IT & Systems

Job Code

1715664

Loading chat...