Chief Information Security Officer
Valeo · Bengaluru
- Experience8–9 yrs
- SalaryNot disclosed
- Work modeonsite
- Levelexecutive
- Posted2 Sept 2026
About Valeo
Valeo is hiring in Bengaluru in automotive mobility. This role looks for around 8+ years of experience.
Skills
- RBI Cybersecurity Guidelines
- ISO 27001
- NIST
- RBI
- CERT-In
- DPDP Act
- IT Act
- VAPT
- Risk Assessment
- Security Operations Center
- Threat Intelligence
- Incident Response
- Zero Trust
- IAM/PAM
- Encryption
- DLP
- EDR/XDR
- WAF
- CASB
- Cloud Security
- API Security
- ERP Security
- SIEM
- Network Security
- CISSP
- CISM
- CISA
- ISO 27001 Lead Auditor
- CEH
The role
A chief information security officer works in a banking and financial services company. They establish RBI-aligned security governance, oversee SOC operations and cyber-fraud response, and secure cloud, API, ERP, and digital platforms with Zero Trust architecture. Their defining skills include RBI frameworks, SOC operations, cyber-fraud response, Zero Trust architecture, IAM/PAM, SIEM, DLP, and cloud security.
Full job description
Responsibilities:
Information Security Strategy and Governance: Create and maintain a comprehensive security framework aligned to RBI Cybersecurity Guidelines, ISO 27001 and NIST standards.
Regulatory Compliance and Risk Management: Ensure compliance with RBI, CERT-In, DPDP Act, and IT Act, and conduct regular audits, VAPT, and risk assessments.
Security Operations and Incident and Scam Response: Establish and oversee a 24/7 SOC, including threat intel and monitoring. Lead incident and scam response covering phishing, fraud attempts, and cyberattacks.
Tech Security and Architecture: Implement Zero Trust architecture, IAM/PAM, encryption, DLP, EDR/XDR, WAF, and CASB. Secure cloud, API, ERP, fintech platforms, and digital apps.
Third-Party Risk Management: Run vendor security evaluations, audits, and contract compliance.
Risk Testing and Assurance: Conduct VA/PT, red teaming, and internal audits, and report findings timely.
Security Awareness and Culture: Deliver employee training and simulate phishing/fraud scenarios. Scale awareness campaigns to customers and frontline staff.
Reporting and Metrics: Define and regularly track KRIs/KPIs covering incident response, risk exposure, compliance, and fraud metrics.
Reporting and Governance:
Reports directly to the CEO/MD and presents regularly to the Board or IT/Risk Committee.
Independent from IT, risk, and compliance heads to maintain objective security oversight.
Drive cybersecurity-friendly culture, policy approval, and leadership visibility.
Fraud and Scam Prevention:
Prevent, detect, and respond to cyber fraud and scams impacting the organization, its customers, employees, and partners. This includes controls to mitigate risks from phishing, vishing, smishing, identity theft, account takeover, digital lending frauds, payment frauds, social-engineering attacks, fake applications, and misuse of customer data.
Design monitoring mechanisms, fraud analytics, early-warning indicators, and incident response workflows in coordination with Risk, Compliance, IT, and Business teams.
Lead investigations, ensure root-cause analysis, corrective actions, and regulatory reporting to RBI, CERT-In, and law enforcement agencies, and drive employee and customer awareness programs.
Requirements:
Education: BE/B. Tech in IT/CS or MCA.
Certifications: CISSP, CISM, CISA, ISO 27001 Lead Auditor, CEH, or equivalent.
Experience: Minimum 8+ years of overall experience in information security, with at least 4+ years in a senior leadership role (CISO/Deputy CISO or equivalent) within BFSI/NBFC organizations, including hands-on exposure to or direct experience working in RBI and/or SEBI-regulated environments.
Skills and Competencies:
Expert in RBI, CERT-In, ISO, and NIST frameworks.
Hands-on knowledge of SIEM, DLP, IAM, EDR/XDR, and network/cloud security tools.
Strong leadership, project management, and communication skills to influence senior stakeholders.
Demonstrated ability to align security initiatives with business objectives and growth plans.