29 Aug
|
DoubleTick
|
Mumbai
Chief Information Security Officer (CISO)
Company : DoubleTick
Location : Mumbai, India
Department : Information Security
Reports to : CEO / Founder / CTO
About the Role :
DoubleTick is a WhatsApp Business API–based CRM and enterprise messaging platform serving large regulated enterprises, including leading banks and Fortune 500 brands. We are looking for a CISO to own our end-to-end security and compliance posture — building the security organization, driving certifications and enterprise client security assessments, and running day-to-day security operations across our cloud infrastructure.
We are looking for a hands-on Information Security leader who can own and strengthen our overall security and compliance posture. The role will involve driving security strategy, compliance programs, cloud and application security, security operations, risk management, and enterprise security assessments.
We are looking for someone who can independently own security initiatives, work closely with engineering and leadership teams, and drive projects from planning through implementation.
Key Responsibilities
Security Strategy & Governance
- Define and drive the organization's information security strategy, policies, standards, and roadmap.
- Establish security governance, risk management, and security reporting processes.
- Identify security gaps and drive remediation across the organization.
- Work closely with engineering, product, IT, and leadership teams to embed security into business and technology processes.
- Take ownership of security initiatives and drive them independently from planning to execution.
Security Compliance & IT Compliance
- Lead and maintain compliance certifications such as SOC 2 Type II and ISO 27001.
- Manage GRC activities using platforms Sprinto.
- Ensure compliance with relevant Indian regulatory requirements, including:
- DPDP Act 2023
- CERT-In directives
- RBI cybersecurity and outsourcing guidelines applicable to BFSI clients
- IT Act
- Own internal and external audits, including scoping, evidence collection, gap remediation, and auditor coordination.
- Respond to enterprise client security questionnaires, RFP security sections, and vendor risk assessments.
- Drive third-party / vendor risk management, including supply-chain security and SBOM reviews.
Security Operations / SIEM / SOC
- Manage and improve SIEM deployment and security monitoring.
- Hands-on experience with Wazuh.
- Configure and tune security rules, decoders, alerts, dashboards, and log retention.
- Build and improve incident detection, response, escalation, and post-incident review processes.
- Coordinate incident response and security investigations.
- Drive vulnerability management, VAPT cycles, and patch governance.
Privileged Access Management (PAM) & IAM
- Design and implement PAM controls covering: Privileged account discovery, Credential vaulting, Session recording, Just-in-time access, Least-privilege access
- Work with PAM solutions such as CyberArk, BeyondTrust, Delinea, Teleport, or AWS-native controls.
- Own IAM governance, including RBAC, SSO/MFA, access reviews, and joiner-mover-leaver processes.
Data Loss Prevention (DLP)
- Define and implement DLP controls across endpoints, email, SaaS, and cloud environments.
- Classify and protect sensitive information including PII, financial data, and client data.
- Establish data-handling controls aligned with DPDP requirements and enterprise client contracts.
- Monitor and investigate potential data-exfiltration and insider-risk events.
Cloud & Application Security
- Secure AWS environments, including: Network security, Encryption and KMS, GuardDuty / Security Hub, CloudTrail logging
- Work with engineering teams to embed security into the SDLC.
- Drive secure code review, SAST/DAST, container security, and Kubernetes security practices.
- Own business continuity, disaster recovery, and backup security governance.
- Conduct and improve periodic DR testing.
Required Qualifications
- 5+ years of experience in Information Security / Cybersecurity.
- Solid hands-on experience across multiple areas of security, including cloud security, security operations, compliance, IAM/PAM, application security, or risk management.
- Hands-on SIEM experience, preferably with Wazuh.
- Experience implementing or managing SOC 2 Type II and/or ISO 27001 programs.
- Practical experience with PAM and/or DLP technologies.
- Good understanding of Indian cybersecurity and regulatory requirements, including DPDP Act, CERT-In, and RBI guidelines.
- Experience handling enterprise security assessments, audits, questionnaires, or vendor risk assessments.
- Strong AWS, GCP security knowledge.
- Ability to independently identify security gaps, design solutions, and drive implementation.
- Strong communication and stakeholder-management skills.
Preferred Qualifications
- Experience working in a SaaS / Product company.
- Certifications such as CISSP, CISM, CISA, ISO 27001 Lead Auditor / Lead Implementer, CCSP, or OSCP.
- Experience with GRC platforms such as Sprinto.
- Exposure to WhatsApp Business API / messaging platform security and Meta platform compliance.
- Experience building or improving security programs in a growing technology organization.
About Us
- DoubleTick is a mobile-first conversational CRM built on the official WhatsApp Business API, designed to unlock WhatsApp-led sales, marketing, and customer engagement at scale.It enables businesses to manage conversations through a centralized team inbox, automate workflows with chatbots and bot studio, and drive growth via bulk broadcasting and analytics. With features like WhatsApp Calling, commerce & cataloging, and role-based access, DoubleTick helps teams streamline operations and improve conversion efficiency.
- Backed by Info Edge Ventures and BeeNext, the platform serves 10,000+ businesses across India and UAE in 100+ industries. Leading brands such as MakeMyTrip, Royal Enfield, CoinDCX, Tarun Tahiliani, Times Media, GRT Jewellers, Malabar Gold and Diamonds, Jaro Education, Sabyasachi, and DarGlobal trust DoubleTick to power their customer conversations.
📌 Chief Information Security Officer (CISO) (Mumbai)
🏢 DoubleTick
📍 Mumbai