17 Sep
|
Impact HR Services
|
Mumbai
17 Sep
Impact HR Services
Mumbai
Role OverviewThe CISO will be responsible for establishing and driving the information security vision, strategy, and program to ensure the confidentiality, integrity, and availability of information assets, in alignment with RBI regulations and business objectives. This role will lead enterprise-wide cybersecurity initiatives, manage regulatory compliance, and strengthen resilience against emerging threats.Key Responsibilities
- Define and implement an enterprise information security strategy, framework, and governance for the NBFC.
- Ensure compliance with RBIs Cyber Security Framework for NBFCs, ISO 27001, and other applicable regulations.
- Develop, maintain, and test incident response, business continuity, and disaster recovery plans.
- Lead cyber risk assessments, vulnerability management, and penetration testing initiatives.
- Oversee data security, encryption, and access control policies across all business units.
- Implement SOC (Security Operations Center) monitoring, threat intelligence, and proactive detection mechanisms.
- Manage vendor and third-party security risks; ensure secure cloud and fintech integrations.
- Build employee awareness and training programs on cyber hygiene and fraud prevention.
- Report regularly to the Board and Risk Committee on cyber posture, incidents, and mitigation plans.
- Lead the security team; collaborate with IT, compliance, risk management, and business stakeholders.
Candidate Profile1. Qualifications: 1.BE + MCA (or equivalent) with relevant certifications (CISM, CISSP, CISA, ISO 27001) with 12-12 years relevant experience and at least 5 years in NBFCs and mid/large Indian private sector banks or PSU banks.
2. Leadership as CISO: 3-5 years as CISO / Deputy CISO in an NBFC (1500+ Cr AUM) or in a mid-sized Indian/PSU bank.
3. Security Strategy & Governance: Has independently led the development and implementation of Information/Cyber Security strategy, frameworks and policies in a Bank/NBFC.
4. Security Operations: Experience across security operations including SOC, vulnerability management, incident response and network/infrastructure security.
5. Regulatory, Audit & Governance Interface: Has independently handled Information/Cyber Security audits/regulatory matters and presented Cyber Security risks and preparedness to Board-level governance forums.
6. Team, Vendor & Security Culture Management: Has led an Information/Cyber Security function including team, vendors/partners and organisation-wide security awareness programmes
📌 CISO (Mumbai)
🏢 Impact HR Services
📍 Mumbai