19 Aug
|
FundsIndia
|
Bangalore Metropolitan Area
19 Aug
FundsIndia
Bangalore Metropolitan Area
Designation: Chief Information Security Officer (CISO)
Experience: 10–15+ years in information/cyber security, including 5+ years leading security in BFSI, broking, AMC, or depository environments
Qualification: B.E./B.Tech (CS/IT/Electronics) or equivalent; MBA/M.Tech preferred
Location: Bangalore/Chennai
About The Role
We are looking for a Chief Information Security Officer to own and continuously improve FundsIndia's information/cyber security posture — spanning Board-level governance and hands-on security architecture and engineering — across broking and mutual fund distribution. The role involves securing the technology stack end-to-end, ensuring SEBI/CERT-In/AMFI compliance, protecting client data, leading incident response, and reporting to the Board and regulators on all cyber matters.
Must Have (Skills/Exposures/Certifications)
- Prior experience as a CISO or in senior security leadership roles within BFSI, broking, AMC, or depository environments.
- Relevant certifications such as CISSP, CISM, CISA, ISO 27001 LA, or CEH, along with relevant NISM/SEBI certifications.
- Technical certifications preferred, such as OSCP, GCIH/GCFA, or a cloud security specialty certification (AWS/Azure/GCP or CCSP).
- Hands-on experience with cloud platforms (AWS/Azure/GCP), SIEM/SOAR, and EDR/XDR tooling.
- Strong working knowledge of SEBI CSCRF, SEBI (Stock Brokers) and (Mutual Funds) Regulations, AMFI, DPDP Act 2023, CERT-In directions, and frameworks such as ISO 27001/NIST CSF.
- Experience with secure API/microservices architecture and cryptography/key management (HSM/KMS). What You will Own.
- Own the Board-approved Cyber Security Policy under CSCRF, validate the applicable RE tier, and run the Board ITCommittee.
- Lead the SOC/incident response function, ensuring all cyber incidents are reported to SEBI;s portal and CERT-In within the mandated 6-hour window, and lead forensics, RCA, and remediation.
- Commission VAPT, cyber audits, CCI assessments, red-teaming/threat-hunting, and cyber drills per tier; drive ISO
- 27001 alignment and maintain the risk register.
- Secure trading, back-office, CRM, and distribution platforms across network, application, cloud, and API layers, and own BCP/DR.
- Design and own zero-trust network segmentation, IAM/PAM, secure SDLC/DevSecOps, SIEM/SOAR detection engineering, EDR/XDR, and cryptography/key management.
- Protect KYC, trading, and personal data of clients per the DPDP Act 2023, and manage third-party/vendor security risk across RTA, KRA, cloud, and AMC partners.
- Drive security awareness training and phishing simulations across the organization.
- Ensure compliance with SEBI Regulation 18(5)/19, including terminal access controls and QSB obligations, and independent non-compliance reporting to exchanges.
- Act as the primary point of contact for SEBI,
exchanges, CERT-In, and AMFI on cyber matters and inspections.
- Report regularly to the Board, IT Committee, and Risk ; Audit Committees on the organization’s cyber posture.
- What You will Bring
- Deep technical fluency in cloud-native security, DevSecOps/secure SDLC, SIEM/SOAR, IAM/PAM, and cryptography/key management.
- Strong Board-reporting and crisis-management skills under regulatory time pressure.
- Ability to translate evolving SEBI regulation into policy, process, and controls.
- High integrity and independence, given direct Board and regulator accountability.
- Strong vendor and third-party risk management skills.
- A proven track record of leading cyber/information security functions in regulated financial services environments.
Is This You?
- 10–15+ years of experience in information/cyber security, including 5+ years leading security in BFSI, broking,
- AMC, or depository environments.
- Prior experience as a CISO or in senior security leadership roles is preferred.
- Hold relevant certifications (CISSP, CISM, CISA, ISO 27001 LA, CEH); technical certifications (OSCP, GCIH/GCFA,
- cloud security specialty) are a plus.
- Comfortable owning Board-level governance while staying hands-on with security architecture and engineering.
- Strong working knowledge of SEBI CSCRF, SEBI regulations, AMFI, DPDP Act, and CERT-In directions.
- High integrity and independence, with solid stakeholder and crisis-management skills.
- Based in or willing to relocate to Chennai.
📌 Chief Information Security Officer (Bangalore Metropolitan Area)
🏢 FundsIndia
📍 Bangalore Metropolitan Area