01 Oct
|
CoRover
|
Bengaluru
Role Overview
We are looking for an experienced Chief Information Security Officer (CISO) to lead CoRover's overall security strategy, governance and security operations.
The CISO will have end-to-end ownership of the organisation's security posture and will be responsible for identifying, managing and mitigating security risks across people, processes, technology, applications, infrastructure, cloud environments, data and AI systems.
The ideal candidate should have broad and deep knowledge across Cybersecurity, Information Security, Cloud Security, Network Security, Application Security, Infrastructure Security, Data Security, Endpoint Security, Identity & Access Management, AI/ML Security, DevSecOps, Security Operations, Risk Management and Governance & Compliance.
The CISO will work closely with the Founder, Leadership, Technology, Engineering, Product, DevOps, Legal, HR and Business teams to establish a strong security-first culture and ensure security is embedded across the organisation.
Key Responsibilities
1. Enterprise Security Strategy
- Define and implement CoRover's overall enterprise security strategy, roadmap and architecture.
- Establish a comprehensive security framework covering applications, infrastructure, cloud, networks, endpoints, data, AI systems and business operations.
- Identify critical security risks and define appropriate preventive, detective and corrective controls.
- Establish security objectives, KPIs, KRIs and security maturity benchmarks.
- Regularly report the organisation's security posture, key risks, incidents and remediation status to senior leadership.
2. Cybersecurity & Information Security
- Lead the organisation's overall cybersecurity and information security programme.
- Establish policies, standards, procedures and controls for information security.
- Implement measures for protection against malware, ransomware, phishing, social engineering, unauthorised access and other cyber threats.
- Establish security monitoring, threat detection and response mechanisms.
- Drive vulnerability management, penetration testing and security assessments.
- Establish and continuously improve the organisation's security incident management framework.
3. Cloud Security
- Own security across AWS, Microsoft Azure, Google Cloud and other cloud environments, as applicable.
- Establish secure cloud architecture and security controls for production and development environments.
- Ensure appropriate controls for cloud IAM, network security, encryption, logging, monitoring and workload protection.
- Conduct regular cloud security assessments and identify configuration and architectural risks.
- Establish security standards for cloud-native applications, containers and Kubernetes environments.
4. Network & Infrastructure Security
- Oversee security of enterprise networks, servers, data centres, infrastructure and communication systems.
- Establish appropriate firewalls, VPNs, IDS/IPS, network segmentation, Zero Trust and secure access controls.
- Ensure secure configuration and hardening of servers, operating systems and infrastructure components.
- Establish infrastructure monitoring and threat detection mechanisms.
- Ensure appropriate protection of critical infrastructure and production environments.
5. Application & API Security
- Establish Security-by-Design principles across the software development lifecycle.
- Integrate security practices into application architecture, development, testing and deployment.
- Drive secure coding practices, code reviews, vulnerability assessments and penetration testing.
- Establish security standards for APIs, microservices and third-party integrations.
- Ensure effective management of application vulnerabilities and timely remediation.
- Work closely with engineering teams to implement DevSecOps practices.
6. AI, ML & LLM Security
- Establish a comprehensive AI/ML and LLM security framework for CoRover's AI products and platforms.
- Identify and mitigate AI-specific threats including prompt injection, jailbreaks, model abuse, data leakage, insecure tool usage and adversarial attacks.
- Ensure security of LLMs, AI Agents, RAG systems, vector databases, AI APIs and supporting infrastructure.
- Establish controls for protection of training data, enterprise data, prompts, model outputs and knowledge bases.
- Assess security risks associated with third-party AI models, APIs, datasets and AI tools.
- Work with Product and Engineering teams to implement secure AI architecture and responsible security practices.
7. Data Security & Privacy
- Develop and implement a comprehensive data security and protection framework.
- Establish data classification, access control, encryption, retention and secure disposal mechanisms.
- Ensure protection of sensitive, confidential and personally identifiable information.
- Implement appropriate controls for data at rest, data in transit and data in use.
- Establish Data Loss Prevention (DLP) mechanisms where required.
- Work with relevant stakeholders to ensure compliance with applicable data protection and privacy requirements.
8. Identity & Access Management
- Establish and govern Identity & Access Management (IAM) across the organisation.
- Implement role-based and least-privilege access controls.
- Oversee privileged access management and administrative access.
- Establish appropriate authentication and multi-factor authentication mechanisms.
- Conduct periodic access reviews and ensure timely revocation of access.
- Establish controls for employee, contractor, partner and third-party access.
9. Security Operations & Incident Response
- Establish and oversee Security Operations Centre (SOC) capabilities, either internally or through managed security partners.
- Implement SIEM, security monitoring, threat intelligence and alert management capabilities.
- Establish a structured Security Incident Response Plan.
- Lead response to cybersecurity incidents and security breaches.
- Conduct root-cause analysis and ensure corrective and preventive actions.
- Conduct periodic incident response simulations and security drills.
10. Vulnerability & Threat Management
- Establish an organisation-wide vulnerability management programme.
- Conduct regular vulnerability assessments, penetration testing and security audits.
- Maintain a risk-based vulnerability remediation process.
- Monitor emerging cybersecurity threats and vulnerabilities.
- Establish threat intelligence capabilities relevant to CoRover's technology and business workplace.
- Ensure timely remediation of critical security vulnerabilities.
11. Governance,
Risk & Compliance
- Establish and maintain the organisation's Information Security Governance, Risk & Compliance (GRC) framework.
- Drive compliance with relevant security standards, frameworks and regulations.
- Lead security readiness and compliance initiatives such as:
- ISO/IEC 27001
- SOC 2
- CERT-In requirements
- Digital Personal Data Protection (DPDP) Act and applicable rules
- NIST Cybersecurity Framework
- CIS Controls
- Other applicable industry and customer security requirements
- Coordinate internal and external security audits.
- Manage security findings, corrective actions and compliance documentation.
- Establish regular security risk assessments and risk treatment plans.
12. Business Continuity & Disaster Recovery
- Establish and maintain Business Continuity and Disaster Recovery (BC/DR) frameworks.
- Identify critical systems and business processes and define recovery requirements.
- Establish backup, recovery and redundancy strategies.
- Conduct periodic DR drills and business continuity exercises.
- Ensure appropriate recovery mechanisms for critical applications, infrastructure and data.
13. Third-Party & Vendor Security
- Establish security requirements for vendors, partners and third-party service providers.
- Conduct or oversee vendor security assessments and due diligence.
- Evaluate security risks associated with third-party applications, APIs, cloud services and technology providers.
- Ensure appropriate security and data protection clauses in vendor agreements.
- Monitor ongoing third-party security compliance.
14. Security Awareness & Culture
- Build a strong security-first culture across the organisation.
- Develop cybersecurity awareness and training programmes for employees.
- Conduct regular security awareness sessions, phishing simulations and security drills.
- Establish clear processes for reporting security incidents and suspicious activity.
- Ensure employees understand their responsibilities related to information and data security.
15. Security Architecture & Technology
- Define and review the organisation's overall security architecture.
- Evaluate and recommend security technologies, platforms and tools.
- Establish security standards for new technologies and enterprise solutions.
- Review technology architecture from a security perspective before deployment.
- Ensure security controls are scalable as the organisation and its technology ecosystem grow.
Required Qualifications
- Bachelor's or Master's degree in Cybersecurity, Information Security, Computer Science, Information Technology or a related discipline.
- 512+ years of experience in cybersecurity, information security or related security functions.
- Significant experience in a senior security leadership role with responsibility for enterprise-wide security.
- Demonstrated experience managing multiple security domains rather than being limited to a single area of security.
- Strong understanding of enterprise security architecture, risk management and security governance.
- Hands-on understanding of cloud, infrastructure, application and data security.
- Strong understanding of cybersecurity frameworks, security controls and compliance requirements.
- Experience working with enterprise-scale technology environments.
- Experience in AI/ML, LLM or Generative AI security will be highly valuable.
- Experience working with enterprise and/or government customers will be preferred.
📌 CISO / IT Security Manager / Technology Risk and Security Lead (Bengaluru)
🏢 CoRover
📍 Bengaluru