06 Aug
|
FlexiLoans
|
Mumbai
Chief Information Security Officer
Who we are:
FlexiLoans is a technology based Digital financing platform started with an endeavor to solve the problems that small businesses face in accessing Quick, Flexible and Adequate funds for growing their Businesses. Our vision is to give "Financial access at a click". Our talent pool has rockstars from diverse backgrounds - ex- Founders, investment bankers, e-commerce and payments with the passion to make a difference to the lives of 70 mn+ MSME businesses in India.
FlexiLoans.com is a pioneer in the ecosystem-based digital lending for small businesses in India. Till date, we have disbursed over 100,000+ loans worth over Rs. 5,000 Crs+ to small sized businesses across 3,200+ cities without having a single branch! We are the leaders in using technology and risk models that focus on alternate / surrogate methods for scoring customers.
Our origination is 100% digital with over 100 embedded partnerships like Amazon, Flipkart, Nykaa, Paytm, Paisabazaar, META, etc. for providing credit access to MSME businesses.
Founded by CA/ISB alumni, FlexiLoans is funded by marquee funds and HNIs in the form of MAJ invest, Fasanara Capital, Sanjay Nayar (Founder - Sorin Investments, Chairman - KKR India and Ex-CEO, Citibank South Asia), Dr.
Harry
Banga (Founder, Caravel group), Yogesh Mahansaria (Founder, Alliance Tyres) Gunit Chaddha (Ex-CEO, Deutsche Bank, Asia Pacific), Anil Jaggia (Ex-CIO, HDFC Bank), Vikram Sud (Ex-COO, Kotak Mahindra Bank), Narayan Seshadri (Ex-Managing Partner, KPMG), Gopal Srinivasan (Chairman, TVS Capital) and Siddharth Parekh (Co-Founder, Paragon Partners) to name a few.
Our product offerings and value proposition can be accessed on our website: https://www.flexiloans.com/
Why join us?
A six-times certified ‘Great Place to work’ workplace, at FlexiLoans you will be working with top tier talent from diverse backgrounds hungry to make a dent in the MSME universe. We believe in people owning what you do and providing support to folks for making decisions (sometimes even wrong decisions!) all the while learning and growing with the organization. FlexiLoans is your front row seat to the MSME Fintech revolution in India!
The role in a gist:
The Chief Information Security Officer (CISO) is a senior executive role responsible for defining, driving,and overseeing the enterprise information security strategy of FlexiLoans. The CISO will ensure the confidentiality, integrity, and availability of all information assets across the organisation, while ensuring full compliance with RBI Master Directions on IT Framework for NBFCs, the Digital Personal Data Protection (DPDP) Act 2023, and evolving global cybersecurity standards.
What we are looking for in the role:
Strategic Leadership & Governance
- Develop, implement, and continuously evolve a comprehensive Enterprise Information Security
- Program aligned to the company's business strategy, growth objectives, and risk appetite.
- Establish and maintain the Information Security Governance framework including policies, standards, procedures, and controls in line with ISO 27001, NIST CSF, and RBI guidelines
- Serve as the primary executive interface for the Board of Directors, Risk Committee, and Audit
- Committee on all matters related to cybersecurity risks, threat landscape, and mitigation roadmaps.
- Define and manage the Information Security budget, ensuring optimal allocation of resources across preventive, detective, and corrective controls.
- Partner with the CEO, CTO, CFO, and COO to embed security as an enabler of business growth rather than a constraint.
Regulatory Compliance & Audit
- Ensure full and timely compliance with RBI Master Directions on IT Framework for NBFCs , including requirements on IT Governance, IS Audit, Cyber Security Framework, Business Continuity, and Outsourcing Risk.
- Ensure compliance with the Digital Personal Data Protection (DPDP) Act, including appointment and coordination with the Data Protection Officer (DPO), consent management, and data principal rights.
- Maintain compliance with PCI-DSS for payment data handling, CERT-In incident reporting mandates, and applicable ISO/IEC standards
- Oversee all IS Audits, both internal and external, as mandated by RBI — including Information Systems Audit by CERT-In empanelled auditors.
- Manage and lead the organisation's Vulnerability Assessment & Penetration Testing (VAPT) programme on a scheduled and on-demand basis.
- Track all audit findings, drive time-bound remediation, and present closure reports to the Audit Committee.
- Liaise proactively with RBI, CERT-In, and other regulatory bodies on cybersecurity disclosures, incident reporting, and policy consultations.
Security Operations & Incident Management
- Direct the Security Operations Center (SOC) — whether in-house or managed — ensuring 24x7 monitoring, threat detection, and real-time response capability.
- Implement and maintain a SIEM (Security Information and Event Management) platform within defined use cases, correlation rules, and escalation thresholds.
- Develop, test, and maintain a robust Cyber Incident Response Plan (CIRP) covering detection, containment, eradication, recovery, and post-incident review.
- Lead all major security incident responses, including coordinating forensic investigations, regulatory notifications (CERT-In within 6 hours as per mandate), and customer/partner communications.
- Establish and track Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) for security operations — reporting regularly to management and the Board.
- Conduct regular cyber drills, tabletop exercises, and red team / blue team exercises to test and improve incident preparedness.
Architecture & Risk Management
- Oversee the secure design and review of FlexiLoans' digital lending applications, APIs, mobile platforms, and cloud infrastructure (AWS / Azure / GCP).
- Implement and maintain Zero Trust Architecture (ZTA) principles across the enterprise network, applications, and data layers.
- Ensure robust Identity and Access Management (IAM) controls, including Multi-Factor Authentication (MFA), Privileged Access Management (PAM), and Role-Based Access Control (RBAC).
- Review all recent technology implementations, system integrations, and platform changes from a security perspective — establishing Security by Design as a standard practice.
- Govern application security testing including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and API security assessments.
- Manage encryption standards, key management policies, and data classification frameworks for all data at rest and in transit.
Third-Party & Vendor Risk Management
- Establish and operationalise a Third-Party Risk Management (TPRM) framework to assess the information security posture of all vendors, fintech partners, cloud service providers, and outsourced service providers.
- Conduct periodic security assessments of critical third parties and embed information security requirements in all outsourcing contracts, as mandated by RBI outsourcing guidelines.
- Maintain an approved vendor register with security ratings and periodic review schedules.
Data Privacy & Protection
- Lead the organisation's data privacy programme in compliance with the DPDP Act 2023, ensuring appropriate consent frameworks, data minimisation, and data retention/deletion policies are in place.
- Coordinate with Product, Technology, and Legal teams to embed privacy-by-design principles in all product development and data handling processes.
- Conduct Data Protection Impact Assessments (DPIAs) for high-risk data processing activities.
- Manage data breach notification processes in accordance with DPDP Act timelines and CERT-In reporting obligations.
Culture, Awareness & Capability Building
- Champion a culture of security awareness across the organisation through mandatory training programmes, phishing simulations, and role-specific security education.
- Build and mentor a high-performing information security team, defining clear roles, career development pathways, and succession planning.
- Drive security awareness at the Board level through regular reporting on threat intelligence, emerging risks, and the company #39;s security posture.
- Engage with the wider fintech and BFSI security community to stay abreast of emerging threats, regulatory developments, and best practices.
Ideal Candidate:
- Industry Background: Mandatory prior experience working within the BFSI sector (preferably in an NBFC, Bank, or Fintech) with a deep understanding of financial regulatory frameworks (RBI guidelines) with CISO certification
- Proven track record of building and managing an independent Information Security function and budget
Qualification & Experience:
- Master’s degree in Computer Science, Information Technology, Cybersecurity, or a related field
- Experience: Minimum of 10+ years of experience in Information Security, with at least 5+ years as a CISO or Department Head
📌 Chief Information Security Officer (Mumbai)
🏢 FlexiLoans
📍 Mumbai