Incred-Chief Information Security Officer (CISO)
Job Description
Job Description: Chief Information
Security Officer (CISO)
Location: Mumbai/Bengaluru
Reporting to: Chief Risk Officer (CRO)...
Job Description
Job Description: Chief Information
Security Officer (CISO)
Location: Mumbai/Bengaluru
Reporting to: Chief Risk Officer (CRO)
Experience Required: 15+ years in Information Security (Financial Services preferred)
1. Role Purpose
The CISO will be the principal architect of the NBFC's security posture as it prepares for an Initial Public Offering (IPO). Reporting to the CRO, you will be responsible for ensuring that our security framework is not only technically impenetrable but also strictly compliant with RBI Master Directions on IT Governance and Cyber Security. You will bridge the gap between technical defense and enterprise risk management, ensuring that "security" is a business enabler, not a bottleneck.
2. Key Responsibilities
Strategic Leadership & IPO Readiness
%CF; Strategy & Roadmap: Define and execute a 3-year information security roadmap with a "futuristic vision" to support the IPO transition.
%CF; Board & Regulator Liaison: Act as the primary interface with the RBI, CERT-In, and other regulatory bodies.
%CF; Governance: Lead the Information Security Committee (ISC) and provide quarterly updates to the Board on the cyber risk posture.
Technical Security & Operations
%CF; Security Architecture: Design and oversee a secure technology landscape, including cloud security (AWS), lending platforms including web & mobile, and API integrations.
%CF; Policies & SOPs: Establish and maintain Information security policies, standards and SOPs.
%CF; DevSecOps Operation: Drive secure by design and DevSecOps practice.
%CF; CSOC & SIEM: Lead the Cyber Security Operations Center (CSOC) to ensure 24/7 monitoring, threat hunting, and automated incident response.
%CF; Technical Testing: Oversee rigorous VAPT (Vulnerability Assessment and Penetration Testing) and Red Teaming exercises for all critical systems.
%CF; Infrastructure Hardening: Ensure technical controls, including hardware, network, and software security standards, are implemented to prevent data loss or fraud.
Risk & Compliance Management
%CF; RBI Compliance: Ensure 100% adherence to RBI's "Master Direction on Information Technology Governance, Risk, Control and Assurance.
%CF; Third-Party Risk: Manage technical due diligence and security audits for all IT vendors as per RBI outsourcing guidelines.
%CF; Data Privacy: Implement data protection strategies in line with the DPDP Act and international standards like ISO 27001.
%CF; Risk Management: Identify, assess, conduct and mitigate cyber technology and data risks.
3. Behavioral Aspects & Leadership Skills
%CF; Strategic Influence: Ability to translate complex technical vulnerabilities into business risk language for the Board and C-suite.
%CF; Composure Under Pressure: Ability to lead teams calmly during critical security incidents or high-stakes regulatory audits.
%CF; Demonstrated ability to work within global matrix structures and implement standardized security protocols across diverse business units.
%CF; Integrity & Accountability: Unwavering professional ethics, acting as the "conscience of the organization" regarding data security.
Evaluation Criteria:
IPO & Regulatory "Execution Excellence"
As an NBFC moving toward IPO with an AA- rating, InCred requires a "best amongst peers" risk performance.
%CF; RBI/SEBI Mastery: Proven track record of navigating RBI Master Directions and SEBI CSCRF compliance to ensure no hurdles during the IPO filing process.
%CF; Audit Readiness: Ability to maintain a digital audit trail (Hindsighting) that showcases appropriate controls to regulators without slowing down the business.
%CF; Third-Party Risk (Partnerships): Experience securing a "Partnerships" business where InCred acts as the balance sheet for other FinTechs via deep API integrations. Leadership & Culture Fit (The "Likeability" Test) In line with InCred's interview philosophy, we are looking for a leader we would "be OK working for".
%CF; Bias for Action: Does the candidate have the "grit and resilience" to fix root causes of problems rather than just managing symptoms?
%CF; Hire and Develop the Best: A track record of mentoring high-performance teams and coaching them to "raise the bar" on product/security discipline.
%CF; Intellectual Agility: Comfort with the ambiguity of a fast-paced environment and the curiosity to stay ahead of emerging cyber threats.
Category Evaluation Criteria
Technical Depth Proven hands-on experience in Security Architecture, Cloud
Security, and Application Security (DevSecOps).
Regulatory
Mastery
Comprehensive understanding of RBI Cyber Security
Framework, Master Directions, SEBI and incident reporting
norms.
Preferred
Certifications
CISSP or CISM. CISA, CCISO, or ISO 27001 Lead Auditor.
Incident
Response
Track record of managing significant cyber incidents, including
discovery-to-remediation within RBI's -6 hour reporting window.
Project
Leadership
Experience leading large-scale security transformations in a
fast-paced BFSI or MNC environment.
The InCred DNA: Who You Are
%CF; Risk-First Approach: In lending, risk is paramount. You prioritize sustainable,
calculated growth over reckless expansion.
%CF; Ownership Mentality: You act on behalf of the entire company. You never say "that's
not my job."
%CF; Bias for Action: You believe speed matters. You encourage your team to run towards
challenges and make reversible decisions quickly.
%CF; Customer Obsessed: You build a culture that values user research. You ensure your
team understands the role our product plays in users' financial lives.
Below are some other jobs we think you might be interested in.
-
Incred-Chief Information Security Officer (CISO)
- Nexthire
- Mumbai/Bengaluru,IN
Job Description: Chief InformationSecurity Officer (CISO)Location: Mumbai/BengaluruReporting to: Chief Risk Officer (CRO)Experience Required: 15+ years...12 Jun -
Chief Information Security Officer (CISO)
- Weekday AI
- Mumbai,Maharashtra,India
This role is for one of the Weekday's clientsSalary range: Rs 1500000 - Rs 4000000 (ie INR 15-40 LPA)Experience: 10+ yrsLocation: MumbaiJob Type:...12 Jun -
Chief Information Security Officer (CISO) - Large Agri Enterprise
- Riverforest Connections Private Limited
- Chennai, TN, TN, IN
- Quick Apply
Role Overview The Chief Information Security Officer (CISO) will be responsible for establishing and leading the information security strategy,...20 May -
CISO (Chief Information & Security Officer)
- Energy Exemplar
- Pune, Maharashtra, India
About the Position CISO is a critical role for Energy Exemplar to protect and safeguard organization's digital assets,employeeand customer data in...12 Jun -
Country Chief Information Security Officer (CISO), Societe Generale India (Mumbai)
- Societe Generale
- India-Mumbai
The country Chief Information Security Officer (CISO) in India is responsible to coordinate locally on the application of group cyber security policies...30 May -
Chief Information Security Officer
- Adani Group
- Ahmedabad, Gujarat, India
About Business:Adani Group: Adani Group is a diversified organisation in India comprising 10 publicly traded companies. It has created a world class...07 Jun -
Algotale ( InCred ) - Information Security Engineer
- Nexthire
- Bangalore, Hybrid,IN
Role- Information Security EngineerLocation- Bangalore Hybrid 2 Days OnsiteCompany- InCred Job Description Evaluating, Testing, and integrating...12 Jun -
CISO - Delivery
- TAC Security
- Chandigarh, CH, IN
Job Description About TAC Security TAC Security is a global cybersecurity company delivering risk-based vulnerability management, attack surface...16 Jun -
Information Security Risk Officer
- Davies
- Pune
We are seeking a 3 year+ experienced Information Security Risk Officer to join our second line of defence, providing independent oversight, challenge,...26 May -
Information Security Consultant
- Presidio Information Risk Management LLP
- Pune, MH, IN
Job Description Company Description\nPresidio Information Risk Management LLP (PIRM) is a global leader in Information Security, Cybersecurity,...16 Jun -
Algotale ( InCred)- Product Support Security Engineer
- Nexthire
- Bangalore, Hybrid,IN
Work Mode- Hybrid 2 Days OnSite Company- Algotale ( Incred Financial Services Limited )Position- Product Support Security Engineer Location- Bangalore...12 Jun -
Information Security Consultant
- Presidio Information Risk Management LLP
- Pune District, MH, IN
Job Description Company Description Presidio Information Risk Management LLP (PIRM) is a global leader in Information Security, Cybersecurity,...14 Jun -
Incred-FSD
- Nexthire
- Bangalore,IN
Full Stack Engineer (MEAN) Location: Whitefield, Bangalore Work Mode: Hybrid Experience : 2-3 Years Job Summary : We are looking for a Full Stack...12 Jun -
Field CISO - Identity Security & Governance
- TechDemocracy
- Hyderabad, TG, IN
Job Description About the Company TechDemocracy is expanding its Identity Security leadership team and is seeking a Field CISO focused on Identity...16 Jun -
Information Security & Data Protection Officer
- ALIQAN Technologies
- Gurgaon, Haryana, IN
Job Title: Information Security & Data Protection Officer (DPO) Manager Location: gurugramExperience: 67 yearsEmployment Type: Full-Time About the Role...15 Jun -
Incred-APM
- Nexthire
- Mumbai,IN
Job Title: Associate Product ManagerAbout the RoleAs an Associate Product Manager at InCred, you'll be at the heart of our product development engine....12 Jun -
Incred-Infosec Engineer
- Nexthire
- Bangalore,IN
Job Title: Senior Information Security EngineerExperience Required: 3-6 years in Information SecurityLocation: Whitefield, BengaluruSenior Information...12 Jun -
Incred-Product Analyst
- Nexthire
- Bangalore,IN
About InCredInCred was founded by Bhupinder Singh in 2016. InCred is credit for Incredible India. We use technology and data-science to make lending...12 Jun -
Incred- BA/PA
- Nexthire
- Mumbai,IN
Role - Business Analyst / Product Analyst Experience - 2 Yrs +Location - Mumbai (Work from office )Responsibilities :Business Analysis: Collaborate...12 Jun -
Incred - IT Lead
- Nexthire
- Bangalore,IN
Job Description - Lead IT Infrastructure Support & Operations Location: Bangalore About the Role We are seeking a visionary and highly-motivated...12 Jun