Chief Information Security Officer
FatakPay · Mumbai, Maharashtra, India
Apply & track with Apply EdgeThe role involves end-to-end ownership of security strategy, operations, regulatory compliance and information security risk reporting to the Board. The ideal candidate will have a strong understanding of RBI IT and cyber security directions, CERT-In, DPDP Act and securing high-scale digital platforms within the Fintech/NBFC/InsurTech space.
Key Responsibilities
Strategy and governanceSet the information security strategy, policy framework and 3-year roadmap, approved by the Board.Convene the Information Security Committee and report cyber risk to the Board at least quarterly.Own the cyber risk register, risk appetite and security budget.Ensure compliance with RBI IT Governance Master Direction, RBI Digital Lending Directions, the IT Outsourcing Master Direction, RBI cyber security guidelines for NBFCs, CERT-In, DPDP Act, PCI DSS and ISO 27001.Lead compliance with the Digital Personal Data Protection Act, 2023 and its Rules: consent, data minimisation, retention, breach notificationHandle RBI inspections and IS audits, VAPT cycles, and close audit findings on time.Fraud, identity, Security operations and incident responseRun a 24x7 SOC (in-house or managed) with SIEM, EDR and threat intelligence.Own the incident response and cyber crisis management plan; lead drills and live incidents.Partner with technology and business teams on BCP/DR, RTO/RPO targets, and ransomware resilienceRun fraud-adjacent security controls: account takeover, synthetic identity, deepfake and social engineering defences, working closely with the fraud risk function.Report incidents to CERT-In within 6 hours and to RBI within its timelines.Application, cloud and infrastructure securityEmbed DevSecOps: secure SDLC, code review, SAST/DAST, and API security for the mobile apps and lending stack.Own application and API security, mobile app security (including anti-tampering and device-binding).Lead security reviews and threat modelling for new products, features, and partner integrations.Secure the customer data lifecycle across LSPs, DLAs, co-lending partners, credit bureaus, payment aggregators, and bank interfaces, and manage data localisation requirements.Own cloud security posture (CSPM, workload protection, encryption, key management, secrets management).Lead identity and access management: privileged access, zero-trust principles, MFA, and access reviews.Oversee network and endpoint security, email security, and secure configuration baselines.Secure the physical-touchpoint extension of the journey: field agents, branch/partner devices, document handling, and cash/instrument-related processes.Run regular VAPT, red-team exercises and a responsible disclosure / bug bounty program.Fraud, identity and data protectionPartner with Risk and Product on fraud controls: device fingerprinting, account takeover, synthetic identity and loan fraud.Protect KYC, bank and credit bureau data with encryption, tokenisation, DLP and data classification.Ensure all customer data is stored on servers located in India.Third-party and partner riskAssess and monitor vendors, cloud providers, lending partners and API integrations before and after onboarding.Set security clauses and audit rights in outsourcing and partner contracts.Culture and teamBuild and lead a security team across engineering, SOC, GRC and privacy.Run security awareness and phishing programs for all staff and collections agents.Key Skills & Requirements:Bachelor’s degree in Computer Science, IT or Engineering; Master’s or MBA preferred.15+ years of experience in Information Security / Cyber Security, with 5+ years leading security at a Bank / NBFC / Fintech.Strong knowledge of RBI cyber security and IT frameworks, CERT-In directions, DPDP Act, PCI DSS and ISO 27001.Proven track record in building SOCs, handling live incidents and managing regulatory audits.Hands-on expertise in cloud security (AWS / GCP / Azure), application, API and mobile app security.Certifications such as CISSP, CISM or CISA (OSCP, CCSP or CRISC preferred).Excellent stakeholder management with the ability to explain cyber risk to the Board and regulators.Strategic thinker with strong execution skills and calm, decisive judgment under pressure. Key Outcomes (First 12 Months)Complete a baseline assessment of security posture and compliance gaps, with a prioritised roadmap approved by the Board.Close all critical and high findings from regulatory and internal audits.Establish a functioning SOC with measurable detection and response times.Integrate security into the SDLC, with security sign-off for all major releases.Roll out a vendor and partner risk framework covering all critical third parties.Conduct at least two full incident response and crisis simulations, including one with the Board or senior management