Deputy Chief Information Security Officer
1 day ago
Experience Required:
10–15 years in Information Security, IT Infrastructure, Governance, Risk & Compliance (GRC)
Position Overview:
The Deputy Chief Information Security Officer (Dy. CISO) will be responsible for
establishing, implementing, and managing the organization's information security strategy, governance framework, and cybersecurity programs
. This includes driving security initiatives across IT infrastructure, cloud environments, applications, and business operations.
The role requires strong expertise in cybersecurity, IT compliance, audits, risk management, vendor governance, and infrastructure security. The Dy. CISO will work closely with senior leadership, department heads, and technology teams to ensure that security controls, policies, and risk frameworks are embedded across the organization.
The Dy. CISO will also lead efforts in incident response, business continuity, network and server security, and regulatory compliance to ensure a robust security posture that aligns with business goals and industry standards.
Key Responsibilities:
1. Information Security Governance & Strategy
- Define, establish, and implement the organization's information security strategy, policies, and control frameworks.
- Ensure alignment with global standards such as ISO 27001, NIST CSF, SOC 2, GDPR, RBI, CERT-In, or industry-specific regulations.
- Conduct periodic reviews of security posture and drive continuous improvement.
- Lead enterprise-wide security awareness and training initiatives.
2. Risk Management & IT Compliance
- Conduct Information Security Risk Assessments (ISRA) and define mitigation strategies.
- Drive compliance with regulatory, contractual, and industry security requirements.
- Lead internal IT audits and prepare the organization for external audits (ISO, SOC 2, PCI-DSS, etc.).
- Maintain documentation of controls, audit evidence, and compliance dashboards.
3. Security Operations & Incident Response
- Oversee security operations including SIEM monitoring, endpoint protection, threat intelligence, and vulnerability management.
- Establish, maintain, and improve Incident Response Procedures (IRP).
- Lead incident handling, investigations, root cause analysis, and post-incident reporting.
- Coordinate with internal teams and external stakeholders during major incidents.
4. IT Infrastructure & Network Security
- Oversee the security of servers, networks, cloud environments, data centers, and virtual environments.
- Ensure timely patching, hardening, and secure configuration of infrastructure components.
- Manage and optimize firewalls, WAF, IDS/IPS, DLP, EDR, access management, and other security technologies.
- Support secure digitization initiatives (e.g., Zoho, SAP) ensuring compliance with security architecture principles
.
5. Asset & Inventory Security Management
- Manage the complete lifecycle of IT assets including procurement, installation, monitoring, and decommissioning.
- Ensure accurate tracking of hardware, software, licenses, and enforce asset security controls.
- Conduct periodic inventory audits and ensure compliance with internal policies.
6. Vendor & Third-Party Security Management
- Evaluate, onboard, and monitor third-party vendors from a security and compliance perspective.
- Review and negotiate SLAs, security clauses, data protection terms, and risk responsibilities.
- Ensure vendors meet performance, security, and compliance requirements.
7. Business Continuity & Disaster Recovery
- Develop, implement, and periodically test Business Continuity Plans (BCP) and Disaster Recovery (DR) frameworks.
- Coordinate backup strategies and ensure secure backup and restoration processes.
- Lead DR drills, review outcomes, and drive improvements.
8. People Leadership & Technical Oversight
- Provide leadership to IT and security teams responsible for infrastructure management and cybersecurity operations.
- Mentor team members, build capabilities, and drive a strong security culture across the organization.
- Guide teams in complex technical troubleshooting and escalate issues as needed.
9. Reporting & Documentation
- Present regular security status reports, risk dashboards, and audit summaries to senior management.
- Maintain documentation for policies, procedures, architecture diagrams, assets, controls, and incidents.
- Track KPIs, KRIs, and compliance metrics for continuous improvement.
Qualifications & Skills:
- Bachelor's degree in computer science, Information Technology, Cybersecurity, or equivalent.
- Master's degree (MBA/Information Security) is a plus.
- 10–15 years of experience in Information Security, IT Infrastructure, Audits, and Compliance.
- Preferred certifications:
- CISSP, CISM, CISA, ISO 27001 Lead Implementer/Auditor, CEH, CCSP, ITIL, PMP
or equivalent. - Strong understanding of security frameworks (ISO 27001, NIST, CIS Controls).
- Experience in cloud security, vulnerability management, and infrastructure hardening.
- Proven ability to manage multi-vendor environments and large-scale IT/security projects.
- Excellent leadership, communication, and problem-solving skills
Key Skills
- Information Security Governance
- Cybersecurity Strategy & Leadership
- IT Compliance & Audits
- Risk Management (GRC)
- Security Operations & Incident Response
- IT Infrastructure & Network Security
- Vendor & Asset Management
- Business Continuity & Disaster Recovery
- Team Leadership & Stakeholder Collaboration
-
Chief Information Security Officer
2 weeks ago
Bengaluru, Karnataka, India Arcana Full time US$ 6,00,000 - US$ 18,00,000 per yearRole: Chief Information Security Officer (CISO)Location: Hybrid (Bangalore) / Remote (with travel as needed)Arcana is hiring a CISO to own cybersecurity end-to-end strategy, execution, operations, and culture. This is a high-impact leadership role responsible for designing and scaling a global security program across our data, and platform ecosystem.We're...
-
Chief Information Security Officer
4 days ago
Bengaluru, Karnataka, India Tazapay Pte Ltd Full timeAbout Tazapay Tazapay is a global cross-border payment platform that enables businesses to seamlesslytransact across fiat and stablecoins. With a robust Pay-in and Pay-out network spanningmultiple geographies, Tazapay offers unparalleled flexibility in payment methods, includingnamed virtual accounts, alternative payment methods (APMs), and...
-
Chief Information Security Officer
2 weeks ago
Bengaluru, Karnataka, India, Karnataka Quess Corp Limited Full timeJob Title: Chief Information Security Officer (CISO)Location: BangaloreThe CISO will provide strategic vision and leadership across the entire technology and cybersecurity landscape for Quess. This role integrates responsibility for technology innovation, digital transformation, IT operations, enterprise architecture, and end-to-end cybersecurity governance....
-
Information Security Officer
2 days ago
Bengaluru, Karnataka, India Peko Full timeJob Title: Information Security OfficerCompany: Peko Payments Private LimitedLocation: Bangalore (Hybrid)About Peko PaymentsPeko is an all‑in‑one platform for small and medium sized businesses (SMBs) to manage payments, expenses, travel, insurance and automate their multiple operations. Peko provides best‑in‑class payment and operations management...
-
Business Information Security Officer
2 days ago
Bengaluru, Karnataka, India Lufthansa Systems Full timeReady to be our digital guardian? Join Lufthansa Systems as a Business Information Security Officer (BISO) and protect what matters most.You'll safeguard our information assets, shape security strategies, and strengthen our cyber defenses across the organization.If security is your passion and impact is your goal, this is your moment — apply...
-
Information Security Officer
2 days ago
Bengaluru, Karnataka, India Open Financial Technologies Full timeDescriptionOPEN is a leading connected finance platform that empowers finance teams to manage their cashflow better by managing all their business finance systems, right from banking to accounting ERP, payments,CRM, HRMS etc. in one place.OPEN, India's 100th Unicorn, has been awarded the Best Workplace 2024 by IEEE in 2024.And was recognised by Forbes India...
-
Information Security Officer
2 days ago
Bengaluru, Karnataka, India Open Financial Technologies Full timeAbout Open:OPEN is a leading connected finance platform that empowers finance teams to manage their cashflow better by managing all their business finance systems, right from banking to accounting ERP, payments,CRM, HRMS etc. - in one place.OPEN, India's 100th Unicorn, has been awarded the 'Best Workplace 2024' by IEEE in 2024. And was recognised by Forbes...
-
Senior Specialist-Information Security
7 days ago
Bengaluru, Karnataka, India Amadeus Full timeJob TitleSenior Specialist-Information SecuritySummary of the RoleYou'll join a collaborative team of Information Security Architects and Engineers within the Group Chief Information Security Office (CISO). Your focus will be on enhancing email security posture across platforms by designing enterprise controls, embedding security by design, and supporting...
-
Senior Specialist-Information Security
7 days ago
Bengaluru, Karnataka, India Amadeus Full timeJob TitleSenior Specialist-Information Security Summary of the RoleYou'll join a collaborative team of Information Security Architects and Engineers within the Group Chief Information Security Office (CISO). Your focus will be on enhancing email security posture across platforms by designing enterprise controls, embedding security by design, and supporting...
-
Information Security Officer
2 weeks ago
Bengaluru, Karnataka, India dentsu Full time ₹ 6,00,000 - ₹ 18,00,000 per yearYou will be responsible for delivering information security initiatives through the region, for ensuring controls and culture are maintained, and for supporting business security requirements, leveraging global and regional capabilities. Led by the APAC CISO, our APAC Security team are responsible for driving global security initiatives across the APAC...