Apply Edge Start your job search

Chief Information Security Officer

Bengal Airlift Limited · Dhaka, Bangladesh

Apply & track with Apply Edge

Protecting Enterprise SecurityFounded on the principle that every organization deserves enterprise-grade security, regardless of size.AboutBengal InfoSec Limited is an enterprise cybersecurity firm and a strategic business unit of the Bengal Airlift Group. We deliver comprehensive Security Operations Center (SOC) services, combining advanced open-source technologies with a team of 200+ certified security professionals across L1-L3 tiers.Our MissionDeliver enterprise-grade cybersecurity at accessible costs — without compromising capability, compliance, or coverage. We serve organizations across banking, telecom, logistics, and government sectors.Our VisionA world where cyber threats are detected and mitigated before they can impact business operations, and where security is a competitive advantage, not a burden.Key ResponsibilitiesDevelop, implement, and continually improve a company-wide information security strategy aligned with business objectives, risk appetite, and emerging threats.Establish the Information Security Management Program (ISMP) covering governance, policies, technical controls, risk management, compliance, monitoring, and reporting.Translate technical security challenges into executive-level, business-aligned risk communication for senior leadership and the board.Build and maintain governance framework: policies, procedures, standards, guidelines, and security controls.Lead periodic risk assessments, business impact analyses (BIA), and enterprise risk mitigation plans; maintain a centralized risk register.Ensure alignment with legal, privacy, and audit teams on data protection obligations.Maintain vendor risk management program: Third-Party Risk Assessments, SOC 2 Type II reviews, international accreditation, and security clause negotiation.Define and implement secure-by-design principles across cloud, network, application, and endpoint infrastructure.Lead architecture of security controls and hardening for cloud, SaaS, and hybrid environments.Implement and manage open source and enterprise security tools.Ensure SDLC/DevSecOps integrates security testing (SAST, DAST, IAST), code reviews, and secure design reviews.Establish and oversee a 24/7 Security Operations Center for detection, analysis, and response.Define alert thresholds, incident triage protocols, escalation paths, and incident reporting workflows.Ensure threat intelligence integration and proactive threat hunting.Monitor internal/external threat intelligence sources and prepare defenses against evolving threats.Develop and lead a comprehensive Incident Response Program: IR policies, playbooks, RACI matrices, crisis communication protocols.Lead cyber incident investigations; coordinate with forensics teams, regulators, and law enforcement as needed.Conduct tabletop exercises and red team simulations to validate readiness.Lead post-incident analysis and root cause investigation to drive corrective action plans.Define business continuity and disaster recovery strategy, including RTO/RPO.Oversee testing of DR environments, failover processes, and recovery capabilities.Ensure backups, redundancies, and restoration processes meet business expectations.Lead enterprise-wide security awareness and training programs, including phishing simulations and executive briefings.Drive cultural transformation toward a security-first mindset.Collaborate with HR/Legal/People Ops on investigations and secure onboarding/offboarding protocols.Serve as primary advisor to the Board on cybersecurity risk, posture, and strategic initiatives; deliver quarterly board-level briefings.Participate in executive committees (enterprise risk, technology steering, compliance leadership).Build, grow, and manage the global Information Security team (Security Engineering, GRC, Security Operations, Identity).Define team structure, performance management, and skill development programs.Own and manage the security program budget, vendor contracts, and tool procurement/cost optimization.Education Qualification: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field from a recognized university.Special Qualification/Skill: Must have proven experience establishing, operationalizing, and managing a national-level CSIRT and SOC, with demonstrated expertise designing and implementing security capabilities using open technologies.Training: Must hold at least one of the following: OSEE, GREM, or CFCE — AND at least one of the following: ISSAP, ISSEP, or ISSMP.Experience (in specific field): Minimum 10 (ten) years of relevant hands-on experience in a cybersecurity role, with practical exposure to security analysis, incident response, and threat hunting.Other Benefits:As Per Company Policy