Chief Information Security Officer (CISO)
DoubleTick · Mumbai
Job description
About the role
DoubleTick is a WhatsApp Business API‑based CRM and enterprise messaging platform serving large regulated enterprises, including banks and Fortune 500 brands. The CISO will own the end‑to‑end security and compliance posture, building the security organization, driving certifications, and running day‑to‑day security operations across our cloud infrastructure.
Key responsibilities
- Define and own the enterprise information security strategy, policies, standards and roadmap.
- Establish governance, risk management and reporting processes for leadership and the board.
- Lead and maintain SOC 2 Type II and ISO 27001 certifications, and operate GRC platforms (Sprinto, Vanta, Drata).
- Ensure compliance with Indian regulations (DPDP Act 2023, CERT‑In, RBI cybersecurity guidelines) and manage internal and external audits.
- Run third‑party/vendor risk management, including SBOM and supply‑chain security reviews.
- Deploy, tune and operate a SIEM solution (Wazuh, Splunk, ELK, QRadar) and lead incident detection, response and forensics.
- Oversee vulnerability management, periodic VAPT cycles and patch governance.
- Design and enforce privileged access management (CyberArk, BeyondTrust, Delinea, Teleport, AWS controls) and IAM governance (RBAC, SSO/MFA, access reviews).
- Define and implement data loss prevention across endpoints, email, SaaS and cloud workloads.
- Secure AWS environments (GuardDuty, Security Hub, CloudTrail) and embed security into the SDLC (secure code review, SAST/DAST, container and Kubernetes security).
- Own business continuity, disaster recovery and backup governance, including regular DR testing.
Required profile
- Proven experience building and leading security and compliance teams in a regulated, cloud‑first environment.
- Deep knowledge of Indian data protection and cybersecurity regulations.
- Track record of achieving SOC 2 and ISO 27001 certifications.
- Strong audit, risk assessment and vendor‑risk management expertise.
- Hands‑on incident response and forensic investigation experience.
Required skills
- SIEM platforms: Wazuh, Splunk, ELK, QRadar
- Privileged Access Management tools: CyberArk, BeyondTrust, Delinea, Teleport, AWS native controls
- GRC platforms: Sprinto, Vanta, Drata
- Cloud security: AWS (GuardDuty, Security Hub, CloudTrail), KMS, encryption
- Vulnerability management and VAPT tools
- Identity and Access Management: RBAC, SSO, MFA, IAM governance
- Data Loss Prevention solutions
- Secure SDLC practices: SAST, DAST, container security, Kubernetes security
- Incident response, forensics and post‑incident review processes
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in India.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 1 month ago
Expires 2 weeks from now
57 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
DoubleTick
Mumbai