Chief Information Security Officer (CISO)
DoubleTick
- Experience
- 10+ yrs
- Location
- Mumbai
- Job type
- Full-time
Required skills
- Chief Information Security Officer (CISO)
- Information Security Leadership
- Security Governance
About the role
About the Role
DoubleTick is a WhatsApp Business API–based CRM and enterprise messaging platform serving large regulated enterprises, including leading banks and Fortune 500 brands. We are looking for a CISO to own our end-to-end security and compliance posture — building the security organization, driving certifications and enterprise client security assessments, and running day-to-day security operations across our cloud infrastructure.
Key Responsibilities
Security Strategy & Governance
- Define and own the organization-wide information security strategy, policies, standards, and roadmap
- Establish security governance, risk management, and reporting processes for leadership and the board
- Build, mentor, and lead the security and IT compliance team
Security Compliance & IT Compliance
- Lead and maintain compliance certifications: SOC 2 Type II and ISO 27001, including GRC platform operations (Sprinto / Vanta / Drata)
- Ensure compliance with Indian regulatory requirements: DPDP Act 2023, CERT-In directives, RBI cybersecurity and outsourcing guidelines applicable to BFSI clients, and the IT Act
- Own internal and external audits — scoping, evidence collection, gap remediation, and auditor coordination
- Respond to enterprise client security questionnaires, RFP security sections, and vendor risk assessments (BFSI-grade due diligence)
- Run the third-party / vendor risk management program, including SBOM and supply chain security reviews
Security Operations (SIEM / SOC)
- Own deployment, tuning, and operations of the SIEM — hands-on experience with Wazuh (or equivalent: Splunk, ELK, QRadar), including agent rollout, rule and decoder tuning, alerting, dashboards, and log retention
- Build incident detection, response, and escalation processes; lead incident response, forensics, and post-incident reviews
- Oversee vulnerability management, periodic VAPT cycles, and patch governance
Privileged Access Management (PAM)
- Design and enforce PAM controls: privileged account discovery, credential vaulting, session recording, just-in-time access, and least privilege
- Evaluate and operate PAM tooling (CyberArk, BeyondTrust, Delinea, Teleport, or AWS-native controls)
- Own IAM governance: periodic access reviews, RBAC, SSO/MFA enforcement, and joiner-mover-leaver processes
Data Loss Prevention (DLP)
- Define and implement the DLP strategy across endpoints, email, SaaS, and cloud workloads
- Classify sensitive data (PII, financial, client data) and enforce handling policies aligned to DPDPA and enterprise client contracts
- Monitor, investigate, and respond to data exfiltration and insider-risk events
Cloud & Application Security
- Secure AWS environments (ap-south-1 / Mumbai region): network security, encryption and KMS, GuardDuty / Security Hub, CloudTrail logging
- Embed security in the SDLC: secure code review, SAST/DAST, container and Kubernetes security
- Own business continuity, disaster recovery, and backup governance, including periodic DR testing
Required Qualifications
- 10+ years in information security, with 3+ years leading security or compliance functions
- Hands-on SIEM experience, ideally with Wazuh, including production deployment and tuning
- Proven track record delivering SOC 2 Type II and/or ISO 27001 certification programs
- Strong implementation experience with PAM and DLP technologies
- Deep familiarity with the Indian regulatory landscape: DPDP Act, CERT-In, RBI guidelines
- Experience facing enterprise / BFSI clients in security assessments and audits
- Strong AWS cloud security expertise
Preferred Qualifications
- Certifications: CISSP, CISM, CISA, ISO 27001 Lead Auditor / Lead Implementer, CCSP, or OSCP
- Experience at a SaaS / product company serving banking or regulated clients
- Exposure to WhatsApp Business API / messaging platform security and Meta platform compliance
- Experience operating GRC platforms (Sprinto, Vanta, Drata)
About DoubleTick
DoubleTick is a mobile-first conversational CRM built on the official WhatsApp Business API. It helps businesses scale sales, marketing, and support with automation, chatbots, broadcasting, analytics, and a centralized team inbox across India and UAE. Learn more: https://doubletick.io/
This page is fully interactive when JavaScript is enabled. Please enable JavaScript to apply or browse related roles.