Search by job, company or skills

Crystal Peak

Chief Information Security Officer (For a global client)

Save
  • Posted 7 days ago
  • Be among the first 10 applicants
Early Applicant

Job Description

Location: Bengaluru / Pune

Experience: 16+ years

Budget: Upto INR 90 lacs

About the Role

We are seeking an experienced and strategic Chief Information Security Officer (CISO) to lead the client's cybersecurity vision, strategy, and execution. The CISO will be responsible for protecting enterprise information assets, ensuring regulatory compliance, driving cyber resilience, and embedding security across technology, business operations, and digital transformation initiatives.

This is a leadership role requiring close collaboration with executive leadership, technology teams, risk functions, customers, and regulators.

Key Responsibilities

Cybersecurity Strategy & Leadership

  • Develop and execute the enterprise cybersecurity strategy aligned with business objectives.
  • Build and lead a high-performing global cybersecurity organization.
  • Establish security governance frameworks, policies, standards, and operating models.
  • Act as the primary advisor to executive leadership and the Board on cyber risks.

Security Governance, Risk & Compliance

  • Establish enterprise security governance and risk management programs.
  • Ensure compliance with ISO 27001, SOC 2, PCI DSS, GDPR, HIPAA, NIST CSF, CIS Controls, RBI/SEBI/IRDAI guidelines (as applicable).
  • Drive enterprise risk assessments and remediation programs.
  • Oversee internal and external security audits.

Security Operations

  • Lead Security Operations Center (SOC), Incident Response, Threat Intelligence, Vulnerability Management, and Digital Forensics.
  • Develop cyber incident response and crisis management capabilities.
  • Ensure continuous monitoring and proactive threat detection.

Cloud & Infrastructure Security

  • Define security architecture for cloud platforms (AWS, Azure, GCP).
  • Oversee Identity & Access Management (IAM), Privileged Access Management (PAM), Zero Trust, endpoint security, and network security.
  • Ensure secure infrastructure and application deployments.

Application & Product Security

  • Embed security into the Software Development Lifecycle (SSDLC).
  • Drive DevSecOps adoption.
  • Lead secure code reviews, penetration testing, and application security programs.

Third-Party Risk Management

  • Assess and monitor vendor and supply chain security risks.
  • Establish third-party security assessment frameworks.
  • Ensure contractual security and privacy requirements are met.

Business Continuity & Cyber Resilience

  • Develop cyber resilience strategies.
  • Oversee Disaster Recovery and Business Continuity Planning.
  • Conduct tabletop exercises and cyber drills.

Executive & Board Reporting

  • Present cybersecurity posture, risks, KPIs, and strategic initiatives to executive leadership and Board committees.
  • Drive cyber awareness across the organization.

Team Leadership

  • Mentor and develop cybersecurity leaders and specialists.
  • Manage cybersecurity budgets, vendor relationships, and strategic investments.

Required Qualifications

  • Bachelor's degree in computer science, Information Security, Engineering, or related field.
  • Master's degree or MBA preferred.
  • 16+ years of experience in Information Security with at least 5 years in a CISO or senior cybersecurity leadership role.
  • Experience leading enterprise security programs in large organizations, GCCs, BFSI, SaaS, healthcare, manufacturing, or technology companies.
  • Proven experience managing security teams across multiple security domains.

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 151247445