
Chief Information Security Officer
Location : Head Office-Bangalore
Organizational Relationships
Position reporting to : Chief Risk Officer
No. of Direct Reports : 0 Reportees
Job Purpose :
The Chief Information Security Officer (CISO) is responsible to coordinate locally on the application of group cyber security policies and standards in line with local regulation with the ultimate goal of protecting business functions, systems and data. The CISO is responsible for implementing, enhancing and overseeing the information security framework locally with strong synchronization with regional Cybersecurity experts. The CISO will be directly responsible for cybersecurity for India Securities, and provide support as needed for the entity.
Key Responsibilities :
Information Security Strategy
- Develop and implement an organization-wide information security strategy and vision.
- Align information security initiatives with business goals and objectives.
- Stay abreast of emerging threats and technologies to adapt the security strategy accordingly.
Meeting and Board Presentation
- Participate in a senior management meeting
- Present to board on security strategy and vision.
- Present to the risk committee on risk and mitigation plan.
Risk Management
- Identify, assess, and prioritize information security risks.
- Develop and implement risk mitigation strategies.
- Establish risk management frameworks and policies.
Security Policies and Procedures
- Develop, implement, and enforce information security policies and procedures
- Ensure compliance with relevant laws, regulations, and industry standards
- Promote security awareness and education throughout the organization.
Incident Response and Management
- Develop and maintain an incident response plan.
- Lead and coordinate responses to security incidents
- Conduct post-incident reviews and implement improvements
Security Architecture
- Design and implement a robust information security architecture
- Evaluate and select security technologies and tools
- Ensure the integration of security measures into the organization's IT infrastructure
Security Awareness and Training
- Develop and implement security awareness programs for employees
- Provide training to staff on security policies and best practices
Vendor and Third-Party Risk Management
- Assess and manage the security risks associated with external vendors and third-party relationships
- Ensure that third-party contracts include appropriate security requirements
Compliance
- Monitor and ensure compliance with relevant data protection and privacy laws.
- Coordinate with legal and compliance teams to address regulatory requirements
Security Audits and Assessments
- Conduct regular security audits and assessments
- Ensure the effectiveness of security controls and measures
Security Governance
- Establish and chair a security governance committee
- Report regularly to executive leadership and the board on the state of information security
Budget and Resource Management
- Develop and manage the information security budget
- Allocate resources effectively to support security initiatives
Collaboration and Communication
- Collaborate with other senior executives to integrate security into overall business strategies
- Communicate effectively with stakeholders about the importance of information security.
Job Requirements :
Qualifications :
A bachelor's degree in computer science, information technology, cybersecurity. Knowledge / Certification on
Digital Personal Data Protection (DPDP) Act, 2023 of India and the regulatory expectations around it as applicable to RBIregulated
entities (REs) such as banks, NBFCs, fintechs, payment system operators, etc.
Experience :
5+ years of experience preferred.
Functional Competencies :
- Solid understanding of information security concepts, frameworks, standards and best practices, strong understanding of IT
infrastructure and IT applicative framework architectures.
- Proven ability to interact with regulators and other external parties on information security matters, Knowledge and understanding
of the cyber threat landscape and the cyber threat intelligence lifecycle, as well as the tools, methods, and frameworks for cyber
threat intelligence collection, analysis and dissemination
- Familiarity with the cyber threat actors, TTPs, and challenges specific to the India region, as well as the regulatory and legal
requirements and standards for cybersecurity and data protection in the region.
Behavioral Competencies :
- Strong partner orientation - strive to satisfy board members / clients / internal partners while taking into account risks for the
company. Ability to communicate clear vision and strategy.
- Risk Awareness and constant strive to identify new risks and ability to put forward convictions and make decisions with courage.
- Communication and Presentation Skills, continuous learning, collaboration, resilience, problem solving and Leadership.
- Understanding and alignment to NBFC and BFSI business.
Key Interactions :
Internal
Nature or purpose of interaction :
All Branch Employees
Functional requirement for compliance related issues.
HO Functional employees ( HR/IT/Ops/Finance)
Work relating to hiring, training, technology related points, Operations related points.
External
Nature or purpose of interaction :
Board of Directors
For reporting as required.
Vendors
Functional work as applicable
Didn’t find the job appropriate? Report this Job