Role - Information Security Officer Experience - 3-5 yrs
Location - Mumbai
Responsibilitie
sOwn and drive information security governance, risk management, compliance, and audit readiness
- Manage the audit and compliance calendar, including bank audits, regulatory reviews, partner reviews, security questionnaires, and external assessments
- Maintain audit and compliance readiness for ISO 27001, PCI DSS, DL-SAR, CICRA, RBI Cyber Security Framework, Digital Lending Guidelines, DPDP/data privacy, and other applicable requirements
- Maintain policies, procedures, risk registers, audit evidence, compliance trackers, security documentation, and closure reports
- Conduct and coordinate internal reviews for access control, privileged access, policy compliance, vendor security, cloud security, and security configurations
- Coordinate VAPT, source code reviews, cloud security reviews, configuration reviews, SAST/DAST activities, and remediation tracking
- Work with Technology, Dev Ops, IT, Compliance, HR/Admin, vendors, and business teams to close vulnerabilities, audit findings, security gaps, incidents, and risks
- Own and drive security incident response execution, including escalation coordination, RCA tracking, corrective actions, evidence documentation, closure reports, and periodic drills
- Required Skill
sGood understanding of information security, GRC, IT risk, audits, compliance,
and cybersecurity controls
- Working knowledge of application security, API security, cloud security, IAM, vulnerability management, incident response, secure SDLC, and vendor security
- Understanding of ISO 27001, PCI DSS, RBI Cyber Security Framework, Digital Lending Guidelines, banking/fintech requirements, and data protection requirements
- Ability to assess technical security risks, define controls, and coordinate remediation with technical teams
- Solid audit handling, evidence management, documentation, communication, follow-up, and ownership
- Ability to work independently with auditors, banks, vendors, technical teams, and business stakeholders
- Required Qualificatio
n3–5years of experience in information security, GRC, IT risk, cybersecurity coordination, audit, or compliance
- Experience handling bank audits, regulatory audits, ISO 27001, PCI DSS, VAPT coordination, access reviews, risk registers, audit evidence, and remediation tracking is preferred
- Experience in fintech, banking, NBFC, payments, lending, or regulated technology environments is preferred
- Bachelor's degree in Computer Science, IT, Information Security, or a related field
- Relevant certification preferred, such as ISO 27001 LA/LI, CISA, CISM, PCI DSS, ISO 27701, Security+, CEH, or equivalent
📌 Chief Information Security Officer - CISO (work from home) (Mumbai)
🏢 Recro
📍 Mumbai