Chief Information Security Officer (CISO) (Mumbai)

Chief Information Security Officer (CISO) (Mumbai)

19 Aug
|
DoubleTick
|
Mumbai

19 Aug

DoubleTick

Mumbai

Chief Information Security Officer (CISO)

About the Role

DoubleTick is a WhatsApp Business API–based CRM and enterprise messaging platform serving large regulated enterprises, including leading banks and Fortune 500 brands. We are looking for a CISO to own our end-to-end security and compliance posture — building the security organization, driving certifications and enterprise client security assessments, and running day-to-day security operations across our cloud infrastructure.

Key Responsibilities

Security Strategy & Governance

- Define and own the organization-wide information security strategy, policies, standards, and roadmap.
- Establish security governance, risk management, and reporting processes for leadership and the board.
- Build, mentor, and lead the security and IT compliance team.

Security Compliance & IT Compliance
- Lead and maintain compliance certifications: SOC 2 Type II and ISO 27001, including GRC platform operations (Sprinto / Vanta / Drata).
- Ensure compliance with Indian regulatory requirements: DPDP Act 2023, CERT-In directives, RBI cybersecurity and outsourcing guidelines applicable to BFSI clients, and the IT Act.
- Own internal and external audits — scoping, evidence collection, gap remediation, and auditor coordination.
- Respond to enterprise client security questionnaires, RFP security sections, and vendor risk assessments (BFSI-grade due diligence).
- Run the third-party / vendor risk management program, including SBOM and supply chain security reviews.

Security Operations (SIEM / SOC)
- Own deployment, tuning, and operations of the SIEM — hands-on experience with Wazuh (or equivalent: Splunk, ELK, QRadar), including agent rollout, rule and decoder tuning, alerting, dashboards, and log retention.
- Build incident detection, response,



and escalation processes; lead incident response, forensics, and post-incident reviews.
- Oversee vulnerability management, periodic VAPT cycles, and patch governance.

Privileged Access Management (PAM)

- Design and enforce PAM controls: privileged account discovery, credential vaulting, session recording, just-in-time access, and least privilege.
- Evaluate and operate PAM tooling (CyberArk, BeyondTrust, Delinea, Teleport, or AWS-native controls).
- Own IAM governance: periodic access reviews, RBAC, SSO/MFA enforcement, and joiner-mover-leaver processes.

Data Loss Prevention (DLP)

- Define and implement the DLP strategy across endpoints, email, SaaS, and cloud workloads.
- Classify sensitive data (PII, financial, client data) and enforce handling policies aligned to DPDPA and enterprise client contracts.
- Monitor, investigate, and respond to data exfiltration and insider-risk events.

Cloud & Application Security
- Secure AWS environments (ap-south-1 / Mumbai region): network security, encryption and KMS, GuardDuty / Security Hub, CloudTrail logging.
- Embed security in the SDLC: secure code review, SAST/DAST, container and Kubernetes security.
- Own business continuity, disaster recovery, and backup governance, including periodic DR testing.

Required Qualifications

- 10+ years in information security, with 3+ years leading security or compliance functions.




- Hands-on SIEM experience, ideally with Wazuh, including production deployment and tuning.
- Proven track record delivering SOC 2 Type II and/or ISO 27001 certification programs.
- Solid implementation experience with PAM and DLP technologies.
- Deep familiarity with the Indian regulatory landscape: DPDP Act, CERT-In, RBI guidelines.
- Experience facing enterprise / BFSI clients in security assessments and audits Strong AWS cloud security expertise

Preferred Qualifications

- Certifications: CISSP, CISM, CISA, ISO 27001 Lead Auditor / Lead Implementer, CCSP, or OSCP.
- Experience at a SaaS / product company serving banking or regulated clients.
- Exposure to WhatsApp Business API / messaging platform security and Meta platform compliance.
- Experience operating GRC platforms (Sprinto, Vanta, Drata).

About Us

DoubleTick is a mobile-first conversational CRM built on the official WhatsApp Business API, designed to unlock WhatsApp-led sales, marketing, and customer engagement at scale.It enables businesses to manage conversations through a centralized team inbox, automate workflows with chatbots and bot studio, and drive growth via bulk broadcasting and analytics. With features like WhatsApp Calling, commerce & cataloging, and role-based access, DoubleTick helps teams streamline operations and improve conversion efficiency.

Backed by Info Edge Ventures and BeeNext, the platform serves 10,000+ businesses across India and UAE in 100+ industries. Leading brands such as MakeMyTrip, Royal Enfield, CoinDCX, Tarun Tahiliani, Times Media, GRT Jewellers, Malabar Gold and Diamonds, Jaro Education, Sabyasachi, and DarGlobal trust DoubleTick to power their customer conversations.

📌 Chief Information Security Officer (CISO) (Mumbai)
🏢 DoubleTick
📍 Mumbai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: chief information security officer (ciso) (mumbai) / mumbai

Subscribe to this job alert:

Get the latest job offers by email for: chief information security officer (ciso) (mumbai) / mumbai