Chief Information Security Officer
Credence HR Services · Mumbai, Maharashtra, India
Apply & track with Apply EdgeRole: Senior Director - CISO (Chief Information Security Officer)Location: Mumbai, Pune, BengaluruRole Summary:Own the security strategy, governance, and risk posture across the AI Platforms (AIP) portfolio, including Engineering Platforms (Flowsource, Neuro IT Ops, Neuro AI Engineering, Skygrade, Ignition) and Business Platforms (TriZetto, Meritsoft, OrderServ), with a mandate to implement a modern AI-native and cloud-native security operating model.This is a governance and risk-ownership role. The CISO defines policy, standards, and risk tolerance, partners with engineering leadership on implementation, and works closely with Corporate Security organization and the Cognizant CISO to ensure AIP remains aligned with enterprise security standards.Key Responsibilities:Define and own AIP’s security strategy, control framework, and risk-acceptance policy, addressing gaps where foundational policies do not exist.Secure Cloud & AI Engineering EnablementDefine and continuously evolve security architecture standards for cloud-native platforms, including Zero Trust, Defense in Depth, Secure by Design, and embedded threat modeling throughout the SDLC.Provide security architecture guidance for identity and key-management designs, including encryption-at-rest, application-layer/envelope encryption, workload identity separation, and SAS/token issuance models.Establish standards for securing AI-native and agentic capabilities, including model and data access controls, prompt and tool-use guardrails, human-in-the-loop requirements, and the secure use of AI providers and code assistants.Define secure-by-default patterns for AWS, Azure, and GCP environments, covering network design, identity and RBAC controls, secrets management, key management, and policy-as-code guardrails.Track and interpret emerging regulatory and industry frameworks relevant to healthcare and financial-services technology platforms.Threat & Vulnerability ManagementLead proactive threat-intelligence efforts to anticipate emerging threats, including supply-chain, identity-based, and AI-specific attack vectors.Define the security tooling strategy across endpoint, network, cloud posture management, and AI/ML security domains, ensuring solutions are effective, cost-justified, and fit for purpose.Serve as a trusted advisor to business and engineering leaders, balancing risk management with delivery and commercial priorities.Required Qualifications20+ years of experience in information and cybersecurity, including 5+ years in a CISO or CISO-1 role within a software product company operating in a highly regulated industry, preferably Healthcare or Financial Services.10+ years of hands-on cloud and application security experience, including threat modeling, Secure by Design, Zero Trust, Defense in Depth, and SAST/DAST/SCA practices.5+ years of direct experience managing regulatory requirements in Healthcare and/or Financial Services, including frameworks such as HIPAA, HITRUST, SOC 2, and PCI-DSS.Demonstrated experience securing solutions across AWS, Azure, GCP, modern AI platforms, GitHub, and AI code assistants.Experience with enterprise security tools such as CrowdStrike, Prisma/Cortex, Zscaler, Checkmarx, Veracode, and Blackduck, as well as AI/ML security platforms such as Prisma AIRS, Protect AI, HiddenLayer, and Lakera.Experience conducting or overseeing penetration testing and adversary simulations using frameworks such as MITRE ATT&CK, MITRE ATLAS, and OWASP Top 10 for LLM Applications.Proven ability to anticipate emerging security trends and risks.Experience of implementing and operating automated threat-intelligence, detection, and response capabilities at scale.If you wish to explore this opportunity, kindly write to me at "shalu@credencehrservices.com"