Chief Information Security Officer

4 days ago


Mumbai, Maharashtra, India Weaver Full time

๐—๐—ผ๐—ฏ ๐—ง๐—ถ๐˜๐—น๐—ฒ: Chief Information Security Officer (CISO)

๐—Ÿ๐—ผ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป: ๐— ๐˜‚๐—บ๐—ฏ๐—ฎ๐—ถ, ๐— ๐—ฎ๐—ต๐—ฎ๐—ฟ๐—ฎ๐˜€๐—ต๐˜๐—ฟ๐—ฎ, ๐—–๐—ผ๐—บ๐—ฝ๐—ฎ๐—ป๐˜†: ๐—ช๐—ฒ๐—ฎ๐˜ƒ๐—ฒ๐—ฟ

๐—”๐—ฏ๐—ผ๐˜‚๐˜ ๐—ช๐—ฒ๐—ฎ๐˜ƒ๐—ฒ๐—ฟ:

At Weaver, we are redefining affordable housing finance in India. Launched in 2025, we are not patching legacy systems; we are building the future from a clean slate. Backed by over $170M from leading investors like Lightspeed and Premji Invest, we have acquired two profitable NBFCs to solve the cold-start problem, giving us an established business and the capital to build the right way. Our mission is to leverage technology and data to make homeownership fast, transparent, and accessible for families in Tier-2 and Tier-3 cities.

๐—ง๐—ต๐—ฒ ๐—ข๐—ฝ๐—ฝ๐—ผ๐—ฟ๐˜๐˜‚๐—ป๐—ถ๐˜๐˜†:

This is a foundational leadership role where you will design and own the entire security, compliance, and risk posture of an AI-native financial institution. As the CISO, you will be the ultimate "Weaver," responsible for balancing the agility of our in-house development team with the strict regulatory needs of the financial services sector. This requires not just setting policies, but integrating modern DevSecOps practices and cloud security to ensure compliance with mandates from the RBI and NHB is seamless, automated, and non-blocking. You will build a security program that enables scale and innovation rather than hinders it.

๐—ž๐—ฒ๐˜† ๐—ฅ๐—ฒ๐˜€๐—ฝ๐—ผ๐—ป๐˜€๐—ถ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐—ถ๐—ฒ๐˜€:

Security Strategy & Governance


โ€ข Develop, implement, and manage a comprehensive, multi-year Information Security Program aligned with business objectives and risk appetite.


โ€ข Establish and maintain effective security governance, policies, standards, and guidelines for the entire organization.


โ€ข Report on security posture, compliance status, and key risk indicators to the Executive Team and the Board.

Regulatory Compliance & Risk Management


โ€ข Act as the primary point of contact for security audits, examinations, and regulatory inquiries.


โ€ข Ensure continuous compliance with mandates issued by the Reserve Bank of India (RBI), the National Housing Bank (NHB), and other relevant regulatory bodies governing the financial sector.


โ€ข Lead comprehensive Security Risk Assessments and drive remediation efforts across all domains.

DevSecOps & Agility Integration (The Weaver Role)


โ€ข Champion the DevSecOps methodology, integrating security testing, threat modeling, and vulnerability management early and continuously into the CI/CD pipelines ("Shift Left").


โ€ข Oversee the review process for the security architecture of new products and cloud implementations (AWS).


โ€ข Implement pragmatic security controls that enable rapid development speed while ensuring security and compliance mandates are met.

Security Operations & Cloud Defense


โ€ข Lead and mature Security Operations Center (SOC) capabilities, including monitoring, detection, and analysis using SIEM tools.


โ€ข Develop and regularly test the Incident Response Plan (IRP) and Disaster Recovery (DR) protocols.


โ€ข Ensure robust security for our AWS-native stack, including IAM, network segmentation (VPC), and serverless security (Lambda).

Team Leadership & Awareness

Lead, mentor, and grow the information security team.

Drive a strong, positive security-aware culture across the organization through continuous training and effective communication.

"๐—ช๐—ฒ๐—ฎ๐˜ƒ๐—ฒ๐—ฟ" ๐—ฃ๐—ฟ๐—ถ๐—ป๐—ฐ๐—ถ๐—ฝ๐—น๐—ฒ ๐—™๐—ผ๐—ฐ๐˜‚๐˜€:

Embrace and promote the "Weaving" concept, ensuring seamless integration between Development, QA, and Operations to make security an enabler of the unified, end-to-end software delivery lifecycle, preventing security roadblocks and minimizing manual overhead.

๐—ฅ๐—ฒ๐—พ๐˜‚๐—ถ๐—ฟ๐—ฒ๐—ฑ ๐—ฆ๐—ธ๐—ถ๐—น๐—น๐˜€ ๐—ฎ๐—ป๐—ฑ ๐—ค๐˜‚๐—ฎ๐—น๐—ถ๐—ณ๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€

Experience: 8โ€“12 years of progressive experience in Information Security, with significant leadership experience (minimum 3 years) in a senior security leadership role.


โ€ข Financial Services Expertise (Mandatory): Deep, practical understanding of the security and compliance requirements specific to the Financial Services Industry, with a strong preference for candidates having direct experience with Non-Banking Financial Companies (NBFCs).


โ€ข Regulatory Knowledge: Expert knowledge of mandates from the RBI, NHB, and other relevant regulatory bodies is essential.


โ€ข Modern Security Practices: Proven experience with cloud security (AWS), microservices security, container security (Docker/Kubernetes), and implementing DevSecOps principles.


โ€ข Certifications: Relevant security certifications are highly desirable (e.g., CISSP, CISM, CRISC).


โ€ข Technical Depth: Hands-on experience with SIEM, vulnerability management tools (DAST/SAST), and advanced threat protection tools.


โ€ข Leadership: Demonstrated ability to communicate effectively with the Board, regulators, executive management, and highly technical teams.

๐—ข๐˜‚๐—ฟ ๐—ง๐—ฒ๐—ฐ๐—ต ๐—ฆ๐˜๐—ฎ๐—ฐ๐—ธ (Security Context)

Our stack is modern, AI-native, and built for scale on a clean slate. The CISO will be responsible for securing:


โ€ข Cloud & Infrastructure (AWS): Fully AWS-native, leveraging serverless (Lambda), AI services (SageMaker, Bedrock), and robust data lake infrastructure (S3, Lake Formation).


โ€ข Architecture & Principles: API-first, Event-Driven Automation, Data Mesh.


โ€ข Languages: Python, React/React Native.

๐—ช๐—ต๐˜† ๐—๐—ผ๐—ถ๐—ป ๐—ช๐—ฒ๐—ฎ๐˜ƒ๐—ฒ๐—ฟ?


โ€ข Greenfield Work: Design the security architecture of a modern AI-native financial institution from scratch, free from legacy constraints.


โ€ข Outsized Impact: Your decisions will directly shape our regulatory standing, competitive advantage, and customer trust.


โ€ข Profit with Purpose: Lead security efforts for a company helping families achieve homeownership while building a scalable, profitable business.


โ€ข Leadership: Join the core foundational leadership team with significant influence across the entire organization.



  • Mumbai, Maharashtra, India Adani Electricity Full time โ‚นย 12,00,000 - โ‚นย 36,00,000 per year

    Role PurposeThe Chief Information Security Officer (CISO) will lead the cybersecurity strategy and operations for Adani Electricity Mumbai, ensuring the protection of critical infrastructure, customer data, and operational technologies. This role is pivotal in safeguarding the organization's digital assets, aligning with Adani Group's commitment to...


  • Mumbai, Maharashtra, India, Maharashtra Weaver Full time

    : Chief Information Security Officer (CISO): , , : :At Weaver, we are redefining affordable housing finance in India. Launched in 2025, we are not patching legacy systems; we are building the future from a clean slate. Backed by over $170M from leading investors like Lightspeed and Premji Invest, we have acquired two profitable NBFCs to solve the cold-start...


  • Mumbai, Maharashtra, India Axentia Global Full time โ‚นย 15,00,000 - โ‚นย 60,00,000 per year

    Job DescriptionChief Information Officer (CIO) โ€” India (Mumbai, MH)Global Technology & Digital Transformation Leadership1. The OrganizationOur client is a Japan-headquartered multinational enterprise renowned for its precision technologies, scientific instrumentation, and advanced manufacturing systems that enable discovery, innovation, and industrial...


  • Mumbai, Maharashtra, India VIP (Vermont Information Processing) Full time โ‚นย 8,00,000 - โ‚นย 12,00,000 per year

    Company: Vermont Information Processing India Pvt. Ltd.VIP is the leading technology supplier for brewers, distributors, wineries, soda bottlers, and othercompanies in the beverage industry. From helping distributors improve their warehouse, delivery, andsales operations, to empowering suppliers to know where their products are and how they are selling,VIP...


  • Mumbai, Maharashtra, India Piramal Finance Full time

    Roles & Responsibilities:He/She will be responsible for managing Regulatory Information & Cybersecurity compliance requirements like RBI & IRDAIPerform risk assessment of all key applications and IT Infrastructure to ensure all risks are identified and mitigatedResponsible for handling the relevant application security practice areas like vulnerability...


  • Mumbai, Maharashtra, India, Maharashtra Career Stone Consultant Full time

    Job Description:The job purpose is to lead and implement comprehensive cybersecurity and information securityinitiatives, including policy development, risk assessment, incident management, and compliance.Responsible for data privacy protection, infrastructure security, vendor management, and fostering asecurity-conscious culture.Roles and...


  • Mumbai, Maharashtra, India BNP Paribas Full time

    Position Purpose The key objective of this role is to ensure that processes across IT operate securely. The remit extends across all aspects of IT security (i.e. policies and procedures, authorization and administration of accesses, networks and firewalls, servers and workstations, operation systems, databases and applications), wherever applicable and...


  • Navi Mumbai, Maharashtra, India SBI General Insurance Full time

    Information Security Manager (Chief Manager)Role Summary: Lead and implement the Information & Cyber Security Management Program to ensure compliance with IRDAI, SBI ISD, ISO 27001, and other regulatory requirements. Develop effective controls and processes to enforce security policies and support organizational objectives.Key Responsibilities:Maintain ISO...


  • Mumbai, Maharashtra, India Sattrix Information Security Full time โ‚นย 4,00,000 - โ‚นย 12,00,000 per year

    Job Title:Network Security Engineers (L1 / L2 / L3)Location:Chennai / Mumbai / HyderabadEmployment Type:Full-time | Client RoleShifts: Rotational ShiftsWork Mode:Work from OfficeAbout the Role:We are looking for highly skilled and motivatedNetwork Security Engineers (L1, L2 & L3). You'll be responsible for managing, operating, and optimizing a wide range of...


  • Mumbai, Maharashtra, India Sattrix Information Security Full time

    Device Management (Endpoint) Support Engineers โ€“ L1 & L2Location: Chennai, Hyderabad and MumbaiMode: work from office (5 days)Shifts: Rotational Shifts (24x7)Budget - L1: 6-7 LPA; L2: 15-18 LPASkills required (End Point Security):Sentinal OneCarbon BlackAruba - NACDAM - ImpervaDSF - ImpervaJob Overview:We are looking forDevice Management L1 and L2 Support...