Chief Information Security Officer (CISO) (12-18 yrs)
Job Summary:
The Chief Information Security Officer (CISO) is responsible for establishing, implementing, and maintaining the enterprise vision, strategy, and program to ensure information assets and technologies are adequately protected. In a regulated Housing Finance NBFC environment, the CISO ensures full compliance with RBI and NHB cybersecurity directives, manages cyber risk, and promotes a culture of data protection and operational resilience across the organization.
Key Responsibilities1.
Information Security Strategy & Governance- Develop and execute an information security strategy aligned with the company's business objectives and RBI/NHB guidelines.
- Establish governance structures, policies, and standards consistent with ISO 27001, NIST, and RBI Cyber Security Framework for NBFCs.
- Define and track key security performance indicators (KPIs) and key risk indicators (KRIs).
- Present regular updates on cybersecurity posture, incidents, and remediation progress to senior management and the Board Risk Committee.
2.
Risk Management & Regulatory Compliance- Identify, assess, and mitigate information security risks across enterprise systems, applications, and third-party providers.
- Ensure compliance with RBI/NHB circulars, IT Act, DPDP Act, and relevant cybersecurity regulations.
- Manage regulatory audits, vulnerability assessments, and cybersecurity inspections.
- Implement a robust data privacy governance framework aligned with national data protection laws.
3.
Cybersecurity Operations- Oversee daily security operations, including network defense, SIEM monitoring, and endpoint protection.
- Implement and manage incident detection, response, and recovery processes.
- Ensure the security of core lending platforms, digital loan origination systems, and customer portals.
- Conduct regular penetration testing, threat intelligence reviews, and red team exercises.
4.
Third-Party and Cloud Security- Evaluate and continuously monitor security controls of third-party service providers and fintech partners.
- Establish a vendor risk management framework and ensure contracts include adequate cybersecurity clauses.
- Review and approve cloud security architecture and controls.
5.
Security Awareness & Training- Build a strong security-aware culture across all departments.
- Conduct regular employee training sessions and phishing simulations.
- Develop executive-level briefings on emerging threats and cyber risk trends.
6.
Business Continuity & Disaster Recovery- Collaborate with IT and Risk teams to design and test business continuity and disaster recovery plans.
- Ensure minimal downtime and data loss during incidents through proactive resilience measures.
Qualifications & Experience- Bachelor's degree in computer science, Information Technology, or related field. Master's degree preferred.
- 12-18 years of experience in information security, with at least 5 years in a leadership role.
- Prior experience in a financial services or housing finance NBFC environment is highly preferred.
- Strong understanding of RBI/NHB cybersecurity frameworks, ISO 27001, and NIST standards.
- Professional certifications such as CISSP, CISM, CISA, CRISC, or ISO 27001 Lead Implementer strongly preferred.
Key Competencies- Strategic vision and the ability to align security initiatives with business objectives.
- Strong leadership, communication, and stakeholder management skills.
- Deep knowledge of IT infrastructure, digital lending platforms, and regulatory technology.
- Ability to manage crises and make decisions under pressure.
- High integrity and commitment to confidentiality and compliance.
Performance Metrics- Closure of audit observations and ongoing strengthening of controls at all levels to prevent cybersecurity incidents
- Timely closure of risk remediation activities.
- Compliance with RBI/NHB directives and internal security policies.
- Improvement in overall organizational security maturity and employee awareness.