Flexiloans - Chief Information Security Officer
FlexiLoans · Mumbai, Maharashtra, India
FlexiLoans · Mumbai, Maharashtra, India
**Chief Information Security Officer** **Who We Are** FlexiLoans is a technology based Digital financing platform started with an endeavor to solve the problems that small businesses face in accessing Quick, Flexible and Adequate funds for growing their Businesses. Our vision is to give "Financial access at a click". Our talent pool has rockstars from diverse backgrounds exFounders, investment bankers, e-commerce and payments with the passion to make a difference to the lives of 70 mn+ MSME businesses in India. FlexiLoans.com is a pioneer in the ecosystem-based digital lending for small businesses in India. Till date, we have disbursed over 100,000+ loans worth over Rs. 5,000 Crs+ to small sized businesses across 3,200+ cities without having a single branch! We are the leaders in using technology and risk models that focus on alternate / surrogate methods for scoring customers. Our origination is 100% digital with over 100 embedded partnerships like Amazon, Flipkart, Nykaa, Paytm, Paisabazaar, META, etc. for providing credit access to MSME businesses. Founded by CA/ISB alumni, FlexiLoans is funded by marquee funds and HNIs in the form of MAJ invest, Fasanara Capital, Sanjay Nayar (Founder Sorin Investments, Chairman KKR India and Ex-CEO, Citibank South Asia), Dr. Harry Banga (Founder, Caravel group), Yogesh Mahansaria (Founder, Alliance Tyres) Gunit Chaddha (Ex-CEO, Deutsche Bank, Asia Pacific), Anil Jaggia (Ex-CIO, HDFC Bank), Vikram Sud (Ex-COO, Kotak Mahindra Bank), Narayan Seshadri (Ex-Managing Partner, KPMG), Gopal Srinivasan (Chairman, TVS Capital) and Siddharth Parekh (Co-Founder, Paragon Partners) to name a few. Our product offerings and value proposition can be accessed on our website: join us? A six-times certified Great Place to work workplace, at FlexiLoans you will be working with top tier talent from diverse backgrounds hungry to make a dent in the MSME universe. We believe in people owning what you do and providing support to folks for making decisions (sometimes even wrong decisions!) all the while learning and growing with the organization. FlexiLoans is your front row seat to the MSME Fintech revolution in India! **The Role In a Gist** The Chief Information Security Officer (CISO) is a senior executive role responsible for defining, driving, and overseeing the enterprise information security strategy of FlexiLoans. The CISO will ensure the confidentiality, integrity, and availability of all information assets across the organisation, while ensuring full compliance with RBI Master Directions on IT Framework for NBFCs, the Digital Personal Data Protection (DPDP) Act 2023, and evolving global cybersecurity standards. **What We Are Looking For In The Role** **Strategic Leadership & Governance :** - Develop, implement, and continuously evolve a comprehensive Enterprise Information Security Program aligned to the company's business strategy, growth objectives, and risk appetite. - Establish and maintain the Information Security Governance framework including policies, standards, procedures, and controls in line with ISO 27001, NIST CSF, and RBI guidelines. - Serve as the primary executive interface for the Board of Directors, Risk Committee, and Audit Committee on all matters related to cybersecurity risks, threat landscape, and mitigation roadmaps. - Define and manage the Information Security budget, ensuring optimal allocation of resources across preventive, detective, and corrective controls. - Partner with the CEO, CTO, CFO, and COO to embed security as an enabler of business growth rather than a constraint. **Regulatory Compliance & Audit** - Ensure full and timely compliance with RBI Master Directions on IT Framework for NBFCs, including requirements on IT Governance, IS Audit, Cyber Security Framework, Business Continuity, and Outsourcing Risk. - Ensure compliance with the Digital Personal Data Protection (DPDP) Act, including appointment and coordination with the Data Protection Officer (DPO), consent management, and data principal rights. - Maintain compliance with PCI-DSS for payment data handling, CERT-In incident reporting mandates, and applicable ISO/IEC standards. - Oversee all IS Audits, both internal and external, as mandated by RBI - including Information Systems Audit by CERT-In empanelled auditors. - Manage and lead the organisation's Vulnerability Assessment & Penetration Testing (VAPT) programme on a scheduled and on-demand basis. - Track all audit findings, drive time-bound remediation, and present closure reports to the Audit Committee. - Liaise proactively with RBI, CERT-In, and other regulatory bodies on cybersecurity disclosures, incident reporting, and policy consultations. **Security Operations & Incident Management** - Direct the Security Operations Center (SOC) - whether in-house or managed - ensuring 24x7 monitoring, threat detection, and real-time response capability. - Implement and maintain a SIEM (Security Information and Event Management) platform within defined use cases, correlation rules, and escalation thresholds. - Develop, test, and maintain a robust Cyber Incident Response Plan (CIRP) covering detection, containment, eradication, recovery, and post-incident review. - Lead all major security incident responses, including coordinating forensic investigations, regulatory notifications (CERT-In within 6 hours as per mandate), and customer/partner communications. - Establish and track Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) for security operations - reporting regularly to management and the Board. - Conduct regular cyber drills, tabletop exercises, and red team / blue team exercises to test and improve incident preparedness. **Architecture & Risk Management** - Oversee the secure design and review of FlexiLoans' digital lending applications, APIs, mobile platforms, and cloud infrastructure (AWS / Azure / GCP). - Implement and main