30 Sep
|
Fatakpay
|
Mumbai
Job Title: Chief Information Security Officer (CISO)
Designation: Vice-President
Location: Mumbai Andheri East
Reports to: COO
Industry: Fintech / NBFC
Role Overview:
We are seeking a seasoned security leader to own information security, cyber resilience and data protection across FatakPay and its group companies. The role involves end-to-end ownership of security strategy, operations,
regulatory compliance and information security risk reporting to the Board. The ideal candidate will have a strong understanding of RBI IT and cyber security directions, CERT-In, DPDP Act and securing high-scale digital platforms within the Fintech/NBFC/InsurTech space.
Key Responsibilities:
Strategy and governance
- Set the information security strategy, policy framework and 3-year roadmap, approved by the Board.
- Convene the Information Security Committee and report cyber risk to the Board at least quarterly.
- Own the cyber risk register, risk appetite and security budget.
- Ensure compliance with RBI IT Governance Master Direction, RBI Digital Lending Directions, the IT Outsourcing Master Direction, RBI cyber security guidelines for NBFCs, CERT-In, DPDP Act, PCI DSS and ISO 27001.
- Lead compliance with the Digital Personal Data Protection Act, 2023 and its Rules: consent, data minimisation, retention, breach notification
- Handle RBI inspections and IS audits, VAPT cycles, and close audit findings on time.
Fraud, identity, Security operations and incident response
- Run a 24x7 SOC (in-house or managed) with SIEM, EDR and threat intelligence.
- Own the incident response and cyber crisis management plan; lead drills and live incidents.
- Partner with technology and business teams on BCP/DR, RTO/RPO targets, and ransomware resilience
- Run fraud-adjacent security controls: account takeover, synthetic identity, deepfake and social engineering defences, working closely with the fraud risk function.
- Report incidents to CERT-In within 6 hours and to RBI within its timelines.
Application, cloud and infrastructure security
- Embed DevSecOps: secure SDLC, code review, SAST/DAST, and API security for the mobile apps and lending stack.
- Own application and API security, mobile app security (including anti-tampering and device-binding).
- Lead security reviews and threat modelling for new products, features, and partner integrations.
- Secure the customer data lifecycle across LSPs, DLAs, co-lending partners, credit bureaus, payment aggregators, and bank interfaces, and manage data localisation requirements.
- Own cloud security posture (CSPM, workload protection, encryption, key management, secrets management).
- Lead identity and access management: privileged access, zero-trust principles, MFA, and access reviews.
- Oversee network and endpoint security, email security, and secure configuration baselines.
- Secure the physical-touchpoint extension of the journey: field agents, branch/partner devices, document handling, and cash/instrument-related processes.
- Run regular VAPT, red-team exercises and a responsible disclosure / bug bounty program.
Fraud, identity and data protection
- Partner with Risk and Product on fraud controls: device fingerprinting, account takeover, synthetic identity and loan fraud.
- Protect KYC, bank and credit bureau data with encryption, tokenisation, DLP and data classification.
- Ensure all customer data is stored on servers located in India.
Third-party and partner risk
- Assess and monitor vendors, cloud providers, lending partners and API integrations before and after onboarding.
- Set security clauses and audit rights in outsourcing and partner contracts.
Culture and team
- Build and lead a security team across engineering, SOC, GRC and privacy.
- Run security awareness and phishing programs for all staff and collections agents.
Key Skills & Requirements:
- Bachelor’s degree in Computer Science, IT or Engineering; Master’s or MBA preferred.
- 15+ years of experience in Information Security / Cyber Security, with 5+ years leading security at a Bank / NBFC / Fintech.
- Strong knowledge of RBI cyber security and IT frameworks, CERT-In directions, DPDP Act, PCI DSS and ISO 27001.
- Proven track record in building SOCs, handling live incidents and managing regulatory audits.
- Hands-on expertise in cloud security (AWS / GCP / Azure), application, API and mobile app security.
- Certifications such as CISSP, CISM or CISA (OSCP, CCSP or CRISC preferred).
- Excellent stakeholder management with the ability to explain cyber risk to the Board and regulators.
- Strategic thinker with robust execution skills and calm, decisive judgment under pressure.
Key Outcomes (First 12 Months)
- Complete a baseline assessment of security posture and compliance gaps, with a prioritised roadmap approved by the Board.
- Close all critical and high findings from regulatory and internal audits.
- Establish a functioning SOC with measurable detection and response times.
- Integrate security into the SDLC, with security sign-off for all major releases.
- Roll out a vendor and partner risk framework covering all critical third parties.
- Conduct at least two full incident response and crisis simulations, including one with the Board or senior management
📌 Chief Information Security Officer (Mumbai)
🏢 Fatakpay
📍 Mumbai