Regional Chief Information Security Officer

4 days ago


Mumbai, Maharashtra, India Boku Full time ₹ 12,00,000 - ₹ 36,00,000 per year

Boku Inc. (BOKU.L) is the leading global provider of local mobile-first payments solutions. Global brands including Amazon, DAZN, Meta, Google, Microsoft, Netflix, Sony, Spotify, and Tencent rely on Boku to reach millions of new paying consumers who do not use credit cards with our purpose-built payment network of more than 300 local payment methods across 70+ countries. Every year, Boku processes over $10 billion in value for our customers. Incorporated in 2008, Boku is headquartered in London and San Francisco and has employees in over 39 countries around the world, including Brazil, China, Estonia, Germany, Ireland, Japan, Singapore, and the UAE. Boku is a truly global company that takes pride in its diversity and thriving equal opportunity workplace.Role Title: Regional Chief Information Security Officer (CISO)Department: Security (India)Reports to:  MD, VP - Security and ITRole Purpose Lead and mature the India cybersecurity program for our alternative payment's platform—protecting customer data and transaction integrity, reducing operational and regulatory risk, and enabling compliant growth. The Regional CISO (India) partners closely with Group Security, Group GRC, local Compliance, and Operational Resilience (OpRes) to align policies and controls, uplift the India resilience programme, and drive the ongoing maturity of security capabilitiesKey ResponsibilitiesGovernance, Risk & Compliance (India)Establish and maintain a Board-approved information & cyber security policy and India risk appetite.Chair security governance forums; brief the India Board/Risk Committee quarterly on posture, incidents, and remediation status.Run security awareness programs, secure-by-design training for engineering, and executive tabletop exercises.Work in lockstep with Group Security and GRC to align policies, standards, control objectives, and risk taxonomies; coordinate with local Compliance to ensure country-specific obligations are embedded in the ISMS.Regulatory compliance (India)Ensure compliance with applicable RBI expectations for payment system operators and PA/PG entities, including data localisation, digital payment security, outsourcing, incident reporting, and system audit requirements.Maintain an annual regulatory calendar; deliver all required filings, attestations, and audit artefacts on time.Serve as the primary security point of contact for regulatory queries, inspections and supervisory engagements.Partner with local Compliance to interpret new circulars and embed them into controls; collaborate with Group GRC to track compliance status and manage policy exceptions and dispensations.Incident response & reporting (India) Define and maintain a 24×7 incident response capability in coordination with Group Security (people, playbooks, tooling, SLAs).Coordinate triage, contain/eradicate/recover, customer/merchant communications, RCA, corrective actions, and formal notifications to authorities when required.Track MTTD/MTTR/MTTRc and other resilience metrics, drive lessons-learned and continuous improvement across teams.Integrate crisis management and business continuity with Group reliance function; conduct appropriate tabletop exercisesAudit, assurance & continuous improvementAct as the cybersecurity point of contract to lead communication with internal and external auditors.Plan and deliver the annual system audit and independent assessments, track issues to sustainable closure with control owners.Maintain audit-ready evidence repositories; partner with Group to run an audit readiness and inspection preparation program.Define and enhance Cybersecurity dashboard and management reportingLead the India Cybersecurity & IT Steering Committee, ensuring prioritised remediation, funding, and accountable ownership.Collaborate with Group Security on a multi-year capability roadmap and measure maturity against a recognised model.Operational Resilience & Capability Maturity (India)Support the India resilience programme with Operational Resilience and Group SecurityPublish a security capability maturity plan for India, report progress to the Steering Committee and India Board.Measures of Success Audit & Regulatory Compliance100% on-time RBI/NPCI filings, attestations, and responses.Annual System Audit completed with 0 repeat findings; ≥95% of issues closed by agreed due dates (no >90-day aged items).Policy alignment: India ISMS fully aligned to Group standards; 0 unmanaged policy exceptions (all have owners/expiries). Regulatory Engagement & InspectionsInspection outcomes: No supervisory penalties or adverse observations; all regulatory queries answered within 5 business days (or per notice).Change readiness: New circulars assessed and embedded with evidence within 60 days (risk-based). Operational Resilience & BCP/DRRTO/RPO met in ≥99% of BCP/DR tests for critical payment flows.2 executive tabletop exercises/year (one regulator-style, one customer-impact scenario). Third-Party & Outsourcing Risk100% of critical vendors reviewed annually, medium risk on cycle.Contracts: Security clauses & right-to-audit in 100% of critical vendor contracts; exit/contingency plans documented.Issues: ≥90% vendor findings closed by due date; RBI outsourcing register current. Governance & ReportingQuarterly Board/Risk Committee packs delivered on schedule; top risks with trendlines and treatment plans.Risk posture: Reduction in Top-5 India risks severity or likelihood within 12 months; exception backlog reduced by ≥50% and all exceptions have time-bound dispensations.Key Skills and Competencies 12+ years in cyber security with 5+ years leading security for regulated financial services or payments in India.Comfortable engaging with boards, senior regulators, banks, and large enterprise merchants.Deep understanding of Indian payments ecosystems (e.g., UPI, cards, wallets) and the operating realities of PA/PGs.Proven track record engaging Boards, regulators, banks/card networks, and large enterprise merchants.Practical knowledge of RBI expectations for payment system operations and PA/PG entitiesFamiliar with India data-localisation norms, outsourcing oversight, digital payment security controls, tokenisation, and system audit expectations.Experience preparing for and responding to regulatory inspections and audit queries; comfortable coordinating with CERT-In empanelled auditors.Excellent written and verbal communication; able to simplify complex risk.Willingness to travel for regulator and audit engagements (Mumbai)Clean regulatory record and high integrity.Clear, concise Board-level reporting and metrics; drives multi-year maturity roadmaps.Strong collaboration with Group Security, Group GRC, local Compliance, Operational Resilience, and Internal AuditNice to Have Experience with UPI, card acquiring, wallets, or direct bank integrations.Exposure to SOC 2/ISO attestations and customer security due-diligence cycles.Familiarity with fraud risk, behavioural analytics, and payments risk enginesQualifications Bachelors in computer science/IT, Engineering or related fieldRelevant certifications: CISSP, CISM, CRISC, ISO/IEC 27001 / ISO 31000 risk management certification Lead Implementer/Lead Auditor, CCSP; plus role-relevant SANS GIAC (e.g., GCIH/GCIA/GMON).Cloud security certifications (e.g., AWS/Azure Security Specialty) and familiarity with PCI DSS (ISA/QSA exposure helpful).Equivalent risk credentials also welcome: IRM International Diploma/Certificate in Risk Management, ISACA, PMI-RMP



  • Mumbai, Maharashtra, India XL Advisors Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    We are seeking an experiencedChief Information Security Officer (CISO)to lead and enhance the organization's cybersecurity framework. The ideal candidate will have15+ years of experience in IT Security, preferably within theinsurance or banking sector, with exposure tomultinational environments. AB.E. degreeis preferred, along with certifications such...


  • Mumbai, Maharashtra, India, Maharashtra XL Advisors Full time

    We are seeking an experienced Chief Information Security Officer (CISO) to lead and enhance the organization’s cybersecurity framework. The ideal candidate will have 15+ years of experience in IT Security, preferably within the insurance or banking sector, with exposure to multinational environments. A B.E. degree is preferred, along with certifications...


  • Mumbai, Maharashtra, India Axentia Global Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Chief Information Officer (CIO) — India (Mumbai, MH)Global Technology & Digital Transformation Leadership1. The OrganizationOur client is aJapan-headquartered multinational enterpriserenowned for its precision technologies, scientific instrumentation, and advanced manufacturing systems that enable discovery, innovation, and industrial advancement...


  • Mumbai, Maharashtra, India Jobuss Resources Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Lead global information security & risk management strategy for CyberCorp's products. Ensure confidentiality, integrity, availability of digital assets. Drive compliance, security operations & culture. Required Candidate profile12-15 yrs cybersecurity exp, 5+ yrs CISO/leadership. Strong governance, compliance knowledge. CISSP/CISM certified. Proven program...


  • Mumbai, Maharashtra, India, Maharashtra Liberty General Insurance Full time

    Academic: B Graduation in any discipline, B.E preferred; professional certification like CISA, CISSP etc. preferableExperience: 15 years and above experience in IT security, preferably from GI or banks Experience of working with multi-national organisations, will be preferredCompetenciesGood understanding and knowledge of evolving IT technologies, frameworks...


  • Mumbai, Maharashtra, India National Institute for Smart Government (NISG) Full time ₹ 15,00,000 - ₹ 60,00,000 per year

    PositionChief Technology Officer (CTO) (On fractional basis)Location: Navi MumbaiReporting To :MD & CEOPosition Overview:UTIITSL is looking for a dynamic, visionary, and strong-willed Chief Technology Officer to spearhead its digital transformation journey. The CTO will be responsible for designing and executing a future-ready technology roadmap to...


  • Mumbai, Maharashtra, India National Institute for Smart Government (NISG) Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    PositionChief Technology Officer (CTO) (On fractional basis)Location: Navi MumbaiReporting To :MD & CEOPosition Overview:UTIITSL is looking for a dynamic, visionary, and strong-willed Chief Technology Officer to spearhead its digital transformation journey. The CTO will be responsible for designing and executing a future-ready technology roadmap to...


  • Mumbai, Maharashtra, India Caps and Pays Executive Search Full time ₹ 2,00,00,000 - ₹ 2,50,00,000 per year

    Looking for Chief Medical Officer for one of the Fastest Growing Emergency Medical Services Company in India Position : Chief Medical Officer - Emergency Medical ServicesLocation : Pune, Maharastra, At Head Office.Reporting to : CEOSalary : Best in the Industry.Education ; MBBS or equivalent degree in Medicine.Should have worked as Chief Medical Officer in...

  • chief officer

    1 week ago


    Navi Mumbai, Maharashtra, India Tangar Ship Management Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Type of VesselBULK CARRIERRankCHIEF OFFICERFlagCOOK ISLANDSJob Posted Date18-Sep-2025

  • soc analyst- l3

    16 hours ago


    Mumbai, Maharashtra, India IARM Information Security Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    JOB DESCRIPTION:Responsible for responding to  security incidents identified by internal controls or external SOC partnersStrictly adhere to  service level agreements (SLAs), metrics and business scorecard obligations for ticket handling security incidents and events.Hands-on experience with  Security Information and Event Management (SIEM) tools...