India Regional Chief Information Security Officer - Managing Director
State Street · Hyderabad, India
Free to search · AI fit score against your CV · tailor your résumé in one click
State Street · Hyderabad, India
India Regional Chief Information Security Officer - Managing Director The India Regional Chief Information Security Officer - Managing Director, serves as the accountable executive for information security risk management and cyber resilience across India‑based operations and global delivery hub. The role ensures adherence to applicable India cyber and data protection regulations while aligning with the global cybersecurity strategy, enterprise risk appetite, and client obligations. Operating at the intersection of business, technology, operations, and cybersecurity, the role partners with India leadership and global executives whose functions have a significant presence in India to strengthen cyber resilience, support regulatory compliance, enable strategic transformation initiatives, and promote a strong security culture. The Senior BISO acts as the primary cybersecurity advisor to India executives, regulators, legal entities, risk committees, and business leaders, while coordinating closely with global cybersecurity functions to drive consistent security outcomes and regulatory compliance across the India region. The role balances global cybersecurity standards with regional business and regulatory requirements while driving execution across complex environments. The Senior BISO is expected to operate as a trusted advisor to executive leadership, while being able to translate complex cybersecurity issues into business-oriented risk decisions. Key Responsibilities • Serve as the primary cybersecurity advisor for State Street's India operations and one of the firm's largest global delivery hubs, partnering with both India leadership and global business, operations, and technology leaders whose organizations have significant presence in India • Lead cybersecurity engagement for strategic business and technology initiatives, ensuring security, resilience, privacy, and regulatory requirements are incorporated into major transformation programs and operational change activities • Act as the liaison between Global Cyber Security and business leadership, translating enterprise security strategy, technology changes, incidents, and risk priorities into actionable outcomes for stakeholders. • Lead cybersecurity support for India-specific regulatory, audit, and compliance requirements including CERT-IN Directions, DPDP Act, RBI, and SEBI. • Lead cybersecurity assessments and establish partnerships with business and technology teams to remediate cyber risk in India. • Actively work with Operational Risk and Compliance teams to translate India regulations into actionable enterprise security controls aligned with global standards. • Manage India cyber risk posture, risk assessments, and material risk reporting into global governance forums. • Provide executive risk advisory services and issue escalation recommendations. • Senior escalation points for cybersecurity incidents impacting India‑based systems, data, and clients. • Support business growth by enabling compliant cloud, digital, outsourcing, and third‑party models within India regulatory requirements. • Take an active role in assessing India‑based vendors, service providers, and intra‑group outsourcing arrangements working locally and with global third-party risk management teams. • Ensure service providers comply with India regulatory expectations for data localization, logging, monitoring, and incident reporting as part of the global cybersecurity standards. • Represent cybersecurity in India executive leadership forums. Required Experience & Qualifications • 15+ years in information security / cyber risk, including senior leadership experience in regulated environments. • Proven experience operating at a leadership level, engaging regulators, boards, and senior business leadership. • Demonstrated hands‑on experience with India cyber regulations, including CERT‑In directives and sector‑specific frameworks. • Experience supporting regulatory exams, audits, and enforcement actions in India. • Strong preference for financial services, payments, asset management, banking, or similarly regulated industries. • Experience in global operating models and matrixed organizations. Technical and Cyber Depth • Strong firsthand experience with incident response and crisis management. • Thorough understanding of data protection principles and privacy engineering standards. • Understanding of Multi-Cloud and SaaS risk models. • Experience with architecture patterns and cyber engineering concepts (i.e., Defense in Depth, zero trust, network segmentation, etc.) • Control knowledge into identity and access management, logging and monitoring requirements, and cyber resiliency controls. • Functional experience with frontier large language Models (LLMs) i.e. GPT, Claude, Gemini, etc. • Familiar with threat model applicability (i.e., SDLC integration, security design reviews, etc.) • Ability to translate technical risk into executive‑level decision frameworks. • Experience with conceptual security processes surrounding Generative AI (GenAI) and Agentic AI models. Highly Desirable Attributes • Ability to quickly earn trust and credibility with regulators and senior stakeholders. • Ability to multi-task and pass along sound judgment. • Pragmatic, business – enabling security mindset. • Being curious into ways that both processes and technology can improve to gain better visibility while ensuring better s