28 Sep
|
Emeritus
|
Mumbai
Emeritus is committed to teaching the skills of the future by making high-quality education accessible and affordable to individuals, companies, and governments around the world. Emeritus’ short courses, degree programs, professional certificates, and senior executive programs help individuals learn new skills and transform their lives, companies, and organizations. Founded in 2015, Emeritus, part of Eruditus Group, has more than 2,000 employees globally and offices in Mumbai, New Delhi, Singapore, Palo Alto, Mexico City, New York, Boston, London, and Dubai.
We are seeking a Chief Information Security Officer to lead information security, cyber risk and resilience across the Emeritus Group. The CISO will set the Group’s security strategy and translate it into an effective, measurable operating program. and ensure that security supports commercial growth and innovation. The ideal candidate combines sound risk judgment, technical depth and executive influence.
Define and execute a risk-based security strategy aligned with the Group’s business priorities, geographic footprint and growth plans.
Establish
Group-wide security policies, minimum standards and clear accountability across businesses and functions. Maintain an actionable view of cyber risk, with explicit ownership, remediation priorities and escalation of material exposures. Provide executive leadership and the Board with clear reporting on security posture, significant risks, investment priorities and incident readiness.
Own the security budget, team structure and vendor portfolio, balancing risk reduction, operating effectiveness and cost. Security operations and resilience Lead security monitoring, threat detection,
vulnerability management and incident response across cloud, corporate and application environments. Strengthen identity and access management, endpoint security, data protection and the security of critical business systems.
Establish and rehearse incident response plans, including executive decision-making, communications and coordination with Legal, Privacy and business leaders. Partner with Technology and Operations to validate disaster recovery and business continuity readiness for critical services. Product, cloud and AI security Embed security into product development and engineering workflows through secure design, threat modeling, automated checks and timely remediation.
Strengthen cloud security, application security, API protection and software supply-chain controls. Establish security requirements for AI-enabled products and internal AI use, including data handling, access boundaries, model-provider risk and testing for misuse.
Ensure
SaaS products and university integrations meet appropriate standards for tenant isolation, access control, data protection and auditability. Data protection, assurance and partner trust Partner with Legal and Privacy to translate applicable data-protection obligations and contractual commitments into effective technical and organizational controls. Own the security assurance roadmap, including relevant certifications,
independent assessments, penetration testing and audit readiness.
Build a scalable third-party risk program covering critical vendors, service providers and technology partners. Establish a shared security operating model across Technology, Product, Operations, HR, Finance and Legal.
Experience and qualifications Substantial progressive experience in information security, including senior leadership accountability for an enterprise-wide security program.
Experience operating in a global, distributed organization with cloud-based technology and digital products. Demonstrated ability to build and improve security programs, prioritize material risks and deliver results within defined budgets. Robust working knowledge of cloud security, application security, identity and access management, security operations, incident response and data protection.
Experience leading significant incident response efforts and communicating effectively with executives during high-pressure situations.
Experience supporting enterprise customer or institutional-partner security assessments and contractual requirements. Ability to assess emerging AI security risks and work with product and engineering teams on practical controls. Excellent communication and influencing skills, including the ability to present technical risks in business terms.
Experience in education technology, SaaS, consumer digital platforms or other businesses handling substantial personal data.
Experience supporting university, enterprise or other institution-led procurement processes.
Experience developing security programs across multiple businesses and jurisdictions.
📌 Senior Cyber Security and Information Security Officer (Mumbai)
🏢 Emeritus
📍 Mumbai