Director of corporate Information Security
2 days ago
Role PurposeThe Director / Head of Information Security will lead Chargebee’s Corporate Information Security function, working in close partnership with the Enterprise Cyber security (ECS) which manages product and infrastructure security and Corporate IT (which manages employee systems, devices, and operations) teams.This role focuses on strengthening enterprise-wide governance, compliance, and risk management by designing new security capabilities while leveraging existing technical and operational controls across the broader ecosystem.The leader will own the ISMS (ISO 27001 Program), Incident Management, Data Protection, Endpoint Security, and other GRC (Governance, Risk & Compliance) programs that protect our people, systems, and customers.The ideal candidate will enable Chargebee to stay audit-ready, resilient, and trusted by customers as we continue to scale globally.Key Responsibilities1. Information Security Strategy & GovernanceLead the design and execution of Chargebee’s enterprise security strategy aligned with business goalsOwn and continuously improve the Information Security Management System (ISMS) under ISO 27001, SOC 2, PCI DSS, and GDPR.Establish and maintain the security governance framework, policies, and standards across business units.Drive adoption of a unified security maturity model and track progress across all security domains.Report quarterly to senior leadership on posture, risks, incidents, and roadmap progress.2. Program Ownership Across Core AORsOwn and mature the following functions and teams:ISMS & ISO 27001 Program – Governance, internal audits, controls, SoA, and certification management.Corporate Incident Management (CIM) – Centralized IR process, playbooks, RCA/CAPA, and coordination of each incident, coordinating Product security, Global Technology Infrastructure and internal operations teamData Leakage Prevention (DLP) – Policy, enforcement, and insider data risk management of corporate systems and corporate technology (Collaboration and knowledge management systems).AI information Security Governance – AI risk reviews, usage policy, vendor evaluation, and compliance oversight of corporate information systems and Corporate Technology. Security Awareness Program – Continuous education, phishing simulation, and behavioral improvement of corporate information systems and Corporate Technology. Corporate IT Risk Management – Risk register, reviews, and treatment lifecycle of corporate information systems and Corporate Technology.Business Continuity Program (BCP) & Data Recovery (DR) (Corporate) – Continuity governance, simulation testing, recovery validation of corporate information systems and Corporate Technology. Policy Governance – Centralized authoring, review, communication, and adoption tracking of corporate information systems and Corporate Technology. Access Governance (RBAC) – Access policy, JML automation, and certification reviews of all systems, product operations and corporate systems and technology.Endpoint Security (Systems & Hardware) – Device hardening, monitoring, and compliance visibility of corporate information systems and Corporate Technology. GTM Trust Enablement (RFP/RFI) – Customer trust documentation, security questionnaires, SLAs in response to processes and governance related questions referring to Chargebee’s corporate information systems and Corporate Technology. 3. Operational Execution & OversightEstablish a centralized incident classification and escalation model for all business functions.Drive RCA & CAPA closure across incidents and audits; ensure risks are documented and tracked.Maintain audit and evidence readiness for customer and external certifications.Oversee DLP and endpoint monitoring, ensuring response workflows are automated and integrated.Partner with ECS and IT to embed security by design into products, infrastructure, and employee systems.Assist in responding to customer RFP’s to clarify and confirm Chargebee’s information security and corporate systems compliance 4. Risk, Compliance, and ReportingMaintain the enterprise security risk register; ensure high/critical risks have defined treatment and ownership.Manage ISO internal audits and, surveillance reviews, and customer due diligence requests.Develop and publish quarterly security KPIs and KRIs, including metrics on incidents, risk aging, compliance, and awareness.Lead regular security governance reviews with senior leadership, providing updates on posture, risks, and strategic initiatives5. People Leadership & CultureBuild and lead a high-performing infosec team across GRC, Risk, DLP, IR, and Awareness.Partner cross-functionally with IT, ECS, Legal, HR, Comms, Risk & Compliance, and GTM enablement functions..Promote a culture where security is everyone’s responsibility through communication, enablement, and collaboration.Mentor, coach, and grow internal talent to scale the security program sustainably.
-
Director of Corporate Development
1 week ago
bangalore, India Grid Dynamics Full timeThe Director of Corporate Development will participate in the entire M&A lifecycle, from initial strategy development and target identification to due diligence & valuation, and post-merger integration. This role requires a candidate with strategic thinking, strong financial acumen, and prior deal experience. Preferred Location: Bangalore or Hyderabad or...
-
Director of Corporate Development
1 week ago
bangalore, India Grid Dynamics Full timeThe Director of Corporate Development will participate in the entire M&A lifecycle, from initial strategy development and target identification to due diligence & valuation, and post-merger integration. This role requires a candidate with strategic thinking, strong financial acumen, and prior deal experience. Preferred Location: Bangalore or Hyderabad or...
-
Director of Application Security
1 week ago
bangalore, India HCLSoftware Full timeHCLSW seeks a Director, Head of Product & Application Security. The successful candidate will lead the end to end Product Security portfolio within HCL Software. Maintains and strengthens the risk posture across the organization through discovery and remediation of product security vulnerabilities and supply chain security. Establishes and communicates...
-
Information Security and Risk Lead
1 week ago
Bangalore, India Dairy Day Full timeDairy Day is one of India’s largest ice cream brands. Dairy Day manufactures and supplies products across a variety of cups, cones, sticks, tubs, and other special packaging with over 30+ flavors. The company has state-of-the-art manufacturing facilities in Karnataka with a production capacity of 3 Lakh liters/day. The Information Security and Controls...
-
Director of Application Security
2 weeks ago
Bangalore, India HCLSoftware Full timeHCLSW seeks a Director, Head of Product & Application Security. The successful candidate will lead the end to end Product Security portfolio within HCL Software. Maintains and strengthens the risk posture across the organization through discovery and remediation of product security vulnerabilities and supply chain security. Establishes and communicates...
-
Director of Corporate Development
1 week ago
Bangalore Urban, India Grid Dynamics Full timeThe Director of Corporate Development will participate in the entire M&A lifecycle, from initial strategy development and target identification to due diligence & valuation, and post-merger integration. This role requires a candidate with strategic thinking, strong financial acumen, and prior deal experience. Preferred Location: Bangalore or Hyderabad or...
-
Director of Corporate Development
1 week ago
Bangalore Urban, India Grid Dynamics Full timeThe Director of Corporate Development will participate in the entire M&A lifecycle, from initial strategy development and target identification to due diligence & valuation, and post-merger integration. This role requires a candidate with strategic thinking, strong financial acumen, and prior deal experience. Preferred Location: Bangalore or Hyderabad or...
-
Information Security
2 weeks ago
bangalore, India Dairy Day Full timeCompany Description Dairy Day is one of India’s largest ice cream brands. Over the last 22+ years, we have built a formidable presence across South & West India and are continuously expanding across the country, selling to over 60,000+ retailers. Dairy Day manufactures and supplies products across a variety of cups, cones, sticks, tubs, and other special...
-
Information Security
2 weeks ago
bangalore, India Dairy Day Full timeCompany DescriptionDairy Day is one of India’s largest ice cream brands. Over the last 22+ years, we have built a formidable presence across South & West India and are continuously expanding across the country, selling to over 60,000+ retailers. Dairy Day manufactures and supplies products across a variety of cups, cones, sticks, tubs, and other special...
-
Information Security
1 week ago
Bangalore, India Dairy Day Full timeCompany Description Dairy Day is one of India’s largest ice cream brands. Over the last 22+ years, we have built a formidable presence across South & West India and are continuously expanding across the country, selling to over 60,000+ retailers. Dairy Day manufactures and supplies products across a variety of cups, cones, sticks, tubs, and other special...