Skip to main content
Posted 26 August, 2026

CISO | BFSI | Mumbai - Churchgate

Yugn HR
Mumbai, MH, MH, IN Full Time

CISO Job Description 

A Chief Information Security Officer (CISO) a top-level executive responsible for 

developing, implementing, and managing an organization’s comprehensive information 

security strategy. The CISO leads the development and implementation of strategies to 

protect company data, safeguard sensitive information, and ensure the company complies 

with legal and regulatory standards related to cybersecurity.​

On a daily basis, the role of CISO involves working closely with IT departments and senior 

management to assess security risks, manage security incidents, and oversee security teams. 

They are tasked with developing security policies, conducting audits, and ensuring all 

security systems are up-to-date and effective. These professionals are also responsible for 

employee security training and awareness programs, ensuring that all staff members 

understand the importance of cybersecurity and their role in maintaining it. 

Objectives of this role 

∙Leading the development and implementation of the company’s information security 

strategy. 

∙Overseeing the protection of company data, intellectual property, and technology 

assets from cyber threats. 

∙Developing and enforcing security policies, procedures, and protocols that align with 

business goals and regulatory requirements. 

∙Identifying and mitigating security risks, ensuring the organisation remains resilient 

against emerging threats. 

∙Ensuring the company’s compliance with industry standards and regulations. 

∙Managing security audits, compliance assessments, incident response processes, and 

investigating security breaches. 

∙Collaborating with cross-functional teams to integrate security measures into the 

company’s IT and business operations. 

Key tasks 

∙Develop, implement, and maintain a comprehensive security program that includes 

cyber defence, data protection, and security operations. 

∙Conduct risk assessments, identify vulnerabilities, and prioritise remediation efforts to 

reduce risk exposure. 

∙Oversee security incident detection, response, and recovery, ensuring swift mitigation 

of potential breaches. 

∙Manage the security architecture, tools, and technologies deployed across the 

organisation’s IT infrastructure. 

∙Coordinate with legal, compliance, and regulatory teams to ensure compliance with 

data protection laws, such as IRDA Cyber Laws, RBI, CERT-IN, Meity, DDPA. 

∙Monitor security metrics and report on the organisation’s security posture to executive 

leadership. 

∙Lead security awareness training programs for employees to promote a culture of 

cybersecurity across the organisation. 

∙Stay updated on cybersecurity trends, technologies, and best practices to enhance 

security measures proactively. 

Required skills and qualifications 

∙Bachelor’s degree in Information Security, Computer Science, or a related field. 

∙6+ years of demonstrable experience as a Chief Information Security Officer or in a 

similar senior-level cybersecurity role. 

∙Extensive knowledge of information security principles, cybersecurity frameworks 

(e.g., NIST, ISO 27001,DDPA), and risk management practices. 

∙Working knowledge of security auditing, vulnerability assessments, and risk 

mitigation. 

∙Experience with security technologies such as firewalls, intrusion detection systems, 

SIEMs,DLP, and encryption protocols. 

∙Solid knowledge of data privacy regulations and compliance requirements. 

∙Ability to develop and implement complex security strategies. 

∙Strong leadership and communication skills, with the ability to influence decision-

making at the executive level. 

∙Strong analytical and problem-solving skills with a keen eye for identifying potential 

risks and vulnerabilities. 

∙Ability to manage a team of security professionals and work cross-functionally with 

IT, legal, and compliance teams. 

Preferred skills and qualifications 

∙Master’s degree in Cybersecurity, IT, or related fields. 

∙Relevant certifications in cybersecurity, such as Certified Information Systems 

Security Professional (CISSP), Certified Information Security Manager (CISM), or 

Certified Information Systems Auditor (CISA). 

∙Experience with cloud security and securing cloud infrastructure & SAAS platforms. 

∙Familiarity with incident management and disaster recovery planning. 

∙Knowledge of ethical hacking and penetration testing techniques. 

∙Background in regulatory compliance and data privacy laws in the industry. 

∙Hands-on experience with SIEM tools, firewalls, DLP and intrusion detection 

systems. 

∙Expertise in secure software development and DevSecOps practices. 

∙Understanding of artificial intelligence and machine learning applications in security. 

Sign up for Job Alerts