Apply Edge Start your job search

Chief Information Security Officer

Emeritus · Mumbai, Maharashtra, India

Apply & track with Apply Edge

About Emeritus:Emeritus is committed to teaching the skills of the future by making high-quality education accessible and affordable to individuals, companies, and governments around the world. It does this by collaborating with more than 90 top-tier universities across the United States, Europe, Latin America, Southeast Asia, India and China. Emeritus’ short courses, degree programs, professional certificates, and senior executive programs help individuals learn new skills and transform their lives, companies, and organizations. Its unique model of state-of-the-art technology, curriculum innovation, and hands-on instruction from senior faculty, mentors and coaches has educated more than 250,000 individuals across 80+ countries.Founded in 2015, Emeritus, part of Eruditus Group, has more than 2,000 employees globally and offices in Mumbai, New Delhi, Singapore, Palo Alto, Mexico City, New York, Boston, London, and Dubai. Following multiple funding rounds, including a $650 million Series E round in 2021 and a $150 million Series F round in 2024 led by TPG, the company is valued at approximately ~$3 billion and is backed by Accel, SoftBank Vision Fund 2, CPP Investments, and other leading global investors.Role Overview:We are seeking a Chief Information Security Officer to lead information security, cyber risk and resilience across the Emeritus Group. The CISO will set the Group’s security strategy and translate it into an effective, measurable operating program. This leader will protect learner, employee and partner information; strengthen the security of our technology and products; and ensure that security supports commercial growth and innovation.The ideal candidate combines sound risk judgment, technical depth and executive influence. They can communicate clearly with the Board and university partners, work closely with engineering and business teams, and build proportionate controls in a fast-moving global organization.Key ResponsibilitiesGroup security strategy and governanceDefine and execute a risk-based security strategy aligned with the Group’s business priorities, geographic footprint and growth plans.Establish Group-wide security policies, minimum standards and clear accountability across businesses and functions.Maintain an actionable view of cyber risk, with explicit ownership, remediation priorities and escalation of material exposures.Provide executive leadership and the Board with clear reporting on security posture, significant risks, investment priorities and incident readiness.Own the security budget, team structure and vendor portfolio, balancing risk reduction, operating effectiveness and cost.Security operations and resilienceLead security monitoring, threat detection, vulnerability management and incident response across cloud, corporate and application environments.Strengthen identity and access management, endpoint security, data protection and the security of critical business systems.Establish and rehearse incident response plans, including executive decision-making, communications and coordination with Legal, Privacy and business leaders.Partner with Technology and Operations to validate disaster recovery and business continuity readiness for critical services.Oversee third-party security providers and ensure services deliver measurable protection.Product, cloud and AI securityEmbed security into product development and engineering workflows through secure design, threat modeling, automated checks and timely remediation.Strengthen cloud security, application security, API protection and software supply-chain controls.Establish security requirements for AI-enabled products and internal AI use, including data handling, access boundaries, model-provider risk and testing for misuse.Ensure SaaS products and university integrations meet appropriate standards for tenant isolation, access control, data protection and auditability.Work with engineering teams to make secure practices practical and repeatable.Data protection, assurance and partner trustPartner with Legal and Privacy to translate applicable data-protection obligations and contractual commitments into effective technical and organizational controls.Own the security assurance roadmap, including relevant certifications, independent assessments, penetration testing and audit readiness.Support university and enterprise customer due diligence, security reviews and procurement processes with credible, consistent evidence.Build a scalable third-party risk program covering critical vendors, service providers and technology partners.Ensure material security commitments made to partners and customers are understood, achievable and maintained.Leadership and security cultureBuild and develop a high-performing security team with clear ownership and strong partnerships across the organization.Establish a shared security operating model across Technology, Product, Operations, HR, Finance and Legal.Deliver role-specific security education and improve employee readiness to identify and report threats.Act as a trusted adviser during new-business launches, market expansion, major technology changes and acquisitions, where applicable.Experience and qualificationsSubstantial progressive experience in information security, including senior leadership accountability for an enterprise-wide security program.Experience operating in a global, distributed organization with cloud-based technology and digital products.Demonstrated ability to build and improve security programs, prioritize material risks and deliver results within defined budgets.Strong working knowledge of cloud security, application security, identity and access management, security operations, incident response and data protection.Experience leading significant incident response efforts and communicating effectively with executives during high-pressure situations.Familiarity with recognized security frameworks and assurance standards, including ISO 27001, NIST CSF and SOC 2.Experience supporting enterprise customer or institutional-partner security assessments and contractual requirements.Ability to assess emerging AI security risks and work with product and engineering teams on practical controls.Excellent communication and influencing skills, including the ability to present technical risks in business terms.PreferredExperience in education technology, SaaS, consumer digital platforms or other businesses handling substantial personal data.Experience supporting university, enterprise or other institution-led procurement processes.Experience developing security programs across multiple businesses and jurisdictions.Relevant professional credentials such as CISSP, CISM or equivalent demonstrated expertise.