Chief Information Security Officer (Mumbai)

Chief Information Security Officer (Mumbai)

16 Sep
|
Ecolux Enterprises
|
Mumbai

16 Sep

Ecolux Enterprises

Mumbai

Chief Information Security Officer (CISO)

Location: India

Responsibility: India & UK International Subsidiaries

Department: Information Security & Risk

Experience: 12–15+ Years

Leadership Experience: 5+ Years in a Senior Security Leadership Role

Industry: FinTech / Banking / Lending / Payments / Embedded Finance

Reporting To: CEO / Designated Executive Sponsor

Board Access: Direct functional reporting to Board Risk Committee

Role Overview

We are looking for an experienced and business-oriented Chief Information Security Officer (CISO) to lead the Group's enterprise-wide information security, cybersecurity, cyber resilience, and technology risk management function across India and the UK .

The CISO will be responsible for establishing and continuously improving the organization's cybersecurity strategy, governance framework, security controls, incident response capabilities, technology risk management, and regulatory compliance.

The role will provide security governance and assurance across cloud infrastructure, SaaS platforms, Salesforce, APIs, third-party vendors, and digital lending operations , while working closely with Technology and business owners responsible for implementing and operating controls.

The CISO will also work closely with the CEO, Board Risk Committee, senior leadership, regulators, auditors, and external stakeholders.

Key Responsibilities1. Cybersecurity Strategy & Leadership

- Develop and execute the Group's cybersecurity strategy aligned with business objectives.
- Establish a multi-year cybersecurity roadmap covering:
- Cyber Governance
- Cloud Security
- Identity & Access Management
- API Security
- Privileged Access Management
- Security Monitoring
- Data Protection
- Vendor Security
- Business & Cyber Resilience
- Act as the principal cybersecurity advisor to the Board, Risk Committee, and Executive Leadership Team.
- Prepare and present quarterly cyber risk reports to the Board.

1. Security Governance & Risk Management

- Establish and maintain the Information Security Framework and Technology Risk Framework.
- Maintain the Cyber Risk Register, security policies, standards, and control library.
- Implement security programs aligned with ISO 27001, NIST Cybersecurity Framework, CIS Controls, and SOC 2 requirements.
- Establish cybersecurity KPIs and KRIs.
- Conduct annual enterprise-wide cyber risk assessments.
- Drive remediation and treatment of identified security risks.

1. Cloud & SaaS Security

Provide governance and assurance over security across third-party applications, SaaS platforms, and cloud environments, including:
- Role-Based Access Controls (RBAC)
- Multi-Factor Authentication (MFA)
- Field-Level Security
- Data Encryption
- API Access Governance
- Secure Integration Architecture
- SSO Integration
- Data Retention
- Audit Logging

Ensure appropriate security controls are implemented across the organization's SaaS and cloud ecosystem.
1. API & Embedded Finance Security

- Own the security framework for internal and external APIs.
- Establish controls covering:
- API Authentication
- OAuth
- OpenID Connect
- Token Management
- Encryption Standards
- Rate Limiting
- API Monitoring
- Ensure API security assessments, penetration testing, and security reviews are conducted.
- Review and approve security architecture for:
- Banking Partners
- NBFC Partners
- Credit Bureau Integrations
- Payment Service Providers
- KYC Vendors
- AML Providers




- Customer Platforms

1. Data Privacy & Protection

Ensure cybersecurity controls support compliance with applicable privacy and regulatory requirements across India and the UK.

India:

- DPDP Act
- RBI Guidelines
- CERT-In Requirements

United Kingdom:

- UK GDPR
- Data Protection Act 2018
- FCA Operational Resilience Expectations

Responsibilities include oversight of:
- Data classification
- Data minimization
- Consent management
- Data retention
- Secure data disposal
- Personal data security controls
- Cross-border data transfer security

Work closely with Legal, Compliance, and the designated Privacy Lead / Data Protection Officer.
1. Security Operations & Incident Response

- Establish and oversee security operations covering:
- Threat Monitoring
- Vulnerability Management
- Security Analytics
- Incident Management
- Forensic Investigation
- Develop and maintain the Incident Response Plan and Cyber Crisis Management Plan.
- Establish breach notification procedures.
- Lead response to:
- Cybersecurity incidents
- Data breaches
- Ransomware attacks
- Fraud-related cyber incidents
- Coordinate with CERT-In, ICO, regulators, and law enforcement agencies when required.

1. Identity & Access Management

Own the enterprise IAM strategy and governance framework covering:
- MFA
- SSO
- Privileged Access Management
- Joiner-Mover-Leaver Controls
- Periodic Access Reviews
- Segregation of Duties

Review access rights across Salesforce, Zoho, cloud platforms, API gateways, third-party applications, and internal systems .

1. Third-Party & Vendor Security

Establish and manage the Vendor Security Risk Program. Assess the security posture of:
- SaaS Providers
- Cloud Providers
- Technology Vendors
- Outsourcing Partners
- Managed Service Providers

Responsibilities include:
- Vendor due diligence
- Security questionnaires
- Security audits
- Ongoing vendor monitoring
- Contractual security requirements

1. Regulatory Compliance

Support and oversee cybersecurity compliance with applicable regulatory requirements.

India:

- RBI Digital Lending Guidelines
- RBI Outsourcing Framework
- DPDP Act
- Companies Act

United Kingdom:

- FCA SYSC Requirements
- FCA Consumer Duty
- UK GDPR
- Operational Resilience Requirements

Coordinate regulatory audits and inspections and maintain appropriate evidence repositories.
1. Security Architecture

- Review and approve security aspects of new technology implementations.
- Review APIs, cloud deployments, vendor integrations, and product launches.
- Establish Security by Design principles.
- Drive secure SDLC practices across technology and product development.

1. Business Continuity & Operational Resilience

Own the cybersecurity and cyber-resilience components of enterprise resilience programs.
- Support Business Continuity Planning and Disaster Recovery.
- Conduct disaster recovery testing and tabletop exercises.
- Conduct ransomware simulations and cyber crisis exercises.




- Support technology and business owners in establishing and testing recovery objectives and impact tolerances for critical services.

1. Security Awareness

Develop and execute an enterprise-wide security awareness program covering:
- Phishing
- Password Security
- Data Protection
- Social Engineering
- Regulatory Obligations

Conduct simulated phishing exercises and monitor employee security awareness metrics. Board Reporting The CISO will present regular updates to the Board / Board Risk Committee covering:
- Cyber Risk Profile
- Critical Vulnerabilities
- Material Security Incidents
- Third-Party Risks
- Regulatory Developments
- Security Program Progress
- Audit Results
- KRI Dashboard
- Security Investment Roadmap

Key Performance IndicatorsRisk & Compliance
- Timely closure or formally accepted treatment of material regulatory and audit findings.
- 100% completion of scheduled enterprise cyber risk assessments.
- High-risk remediation actions completed within agreed timelines.

Vulnerability Management
- Critical vulnerabilities remediated within defined SLAs.
- High-risk vulnerabilities remediated within defined SLAs.

Access Management
- 100% MFA coverage.
- Quarterly access reviews completed.

Vendor Security
- 100% of critical vendors assessed.
- Annual reassessment of critical vendors.

Security Awareness
- Phishing susceptibility rate below 5%.
- 100% mandatory security training completion.

Incident Management
- Year-on-year reduction in Mean Time to Detect (MTTD).
- Year-on-year reduction in Mean Time to Respond/Recover (MTTR).

Education & CertificationsEducation
- Bachelor's degree in Information Security, Computer Science, Engineering, or a related field .
- Master's degree preferred.

Mandatory Certifications At least one of the following:

- CISSP
- CISM
- CCSP

Preferred Certifications
- CRISC
- ISO 27001 Lead Implementer
- ISO 27001 Lead Auditor
- SABSA
- TOGAF
- CDPSE

Experience Required
- 12–15+ years of experience in Cybersecurity, Technology Risk, Information Security, or Cyber Resilience.
- Minimum 5+ years in a senior security leadership role .
- Proven experience in FinTech, Banking, Lending, Payments, or Embedded Finance .
- Experience with Salesforce Security Governance .
- Solid experience securing cloud-first environments .
- Strong understanding of API Security and Open Banking ecosystems .
- Experience working with RBI, FCA, GDPR/UK GDPR, and DPDP requirements .
- Demonstrable experience presenting to and reporting to Boards, Board Risk Committees, or Audit Committees .

Ideal Candidate Profile The ideal candidate will be a strategic, business-oriented cybersecurity leader who can effectively balance cyber risk, regulatory obligations, customer protection, and commercial growth. The candidate should bring deep expertise in:

- Enterprise Cybersecurity
- SaaS & Cloud Security
- API Security
- Salesforce Security
- Digital Lending Platforms
- Identity & Access Management
- Third-Party Risk Management
- Data Privacy & Protection
- Technology Risk
- Cyber Resilience
- Regulatory Compliance

The ideal candidate should be comfortable communicating with Board members, CXOs, regulators, auditors, technology teams, business leaders, and external partners , while building a strong security culture across the organization. This is a senior leadership position with Group-wide responsibility for cybersecurity, information security, technology risk, and cyber resilience across India and UK operations.

📌 Chief Information Security Officer (Mumbai)
🏢 Ecolux Enterprises
📍 Mumbai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: chief information security officer (mumbai) / mumbai

Subscribe to this job alert:

Get the latest job offers by email for: chief information security officer (mumbai) / mumbai