Senior Lead - Security
Fibe · Pune, Maharashtra, India
Free to search · AI fit score against your CV · tailor your résumé in one click
Fibe · Pune, Maharashtra, India
We are seeking a Senior Security Manager with strong technical depth and proven leadership capability to own and drive Fibe's information security strategy. You will work closely with the current CISO, engineering, product, compliance, and business leadership to build a resilient, scalable, and future-ready security organization for a regulated fintech environment. Key Responsibilities Security Strategy & Governance • Define, implement, and continuously evolve Fibe's information security strategy, policies, and frameworks in line with business growth and regulatory expectations (RBI guidelines, ISO 27001, PCI-DSS, SOC 2, etc.) • Own the enterprise security roadmap covering cloud security, application security, data protection, identity & access management, and third-party risk • Partner with the CISO to present security posture, risks, and investment priorities to senior leadership and the board Security Operations & Risk Management • Lead vulnerability management, threat detection, and incident response programs • Own security incident management from detection and containment to root cause analysis and post-incident reporting • Drive proactive risk assessments across products, infrastructure, and vendor ecosystems • Oversee security monitoring (SOC/SIEM), penetration testing, and red-teaming exercises Compliance & Regulatory • Ensure compliance with RBI digital lending guidelines, data protection regulations (DPDP Act), and industry certifications (ISO 27001, PCI-DSS, SOC 2) • Act as a key point of contact during regulatory audits, customer security reviews, and compliance assessments • Build and maintain a strong audit-readiness culture across engineering and business teams Leadership & Team Building • Build, mentor, and lead a high-performing security team (security engineers, analysts, and specialists) • Foster a security-first culture across the organization through training, awareness programs, and cross-functional collaboration • Act as a trusted advisor to engineering and product leaders, embedding security into the SDLC (DevSecOps) • Deputize for the CISO in leadership forums, external representation, and strategic decision-making as needed Stakeholder & Vendor Management • Collaborate with legal, compliance, engineering, and business teams to balance security requirements with business velocity • Manage relationships with external auditors, security vendors, and regulatory bodies • Evaluate and onboard security tools and technologies to strengthen Fibe's defense posture Requirements Experience & Technical Skills • 510 years of experience in information security, with at least 2–3 years in a leadership or managerial capacity • Experience with security frameworks and standards: ISO 27001, PCI-DSS, NIST CSF, SOC 2, CIS Benchmarks • Working knowledge of RBI regulations for digital lending / fintech and data protection laws (DPDP Act) is highly desirable • Familiarity with DevSecOps practices and integrating security into CI/CD pipelines (Jenkins, GitLab CI, GitHub Actions) • Cloud Security: Hands-on experience securing AWS/GCP/Azure environments — IAM policies, VPC/network segmentation, CSPM tools (Wiz, Prisma Cloud, AWS Security Hub), Kubernetes/container security (EKS/GKE, Aqua, Trivy), and cloud-native logging (CloudTrail, GuardDuty) • Application & Product Security: SAST/DAST/SCA tooling (Checkmarx, Veracode, Snyk, Semgrep, OWASP ZAP, Burp Suite), secure code review, API security, threat modeling (STRIDE), and OWASP Top 10 / Mobile Top 10 remediation • Network & Infrastructure Security: Firewalls, IDS/IPS, WAF (Cloudflare, AWS WAF, Akamai), network segmentation, VPN, DDoS mitigation, and secure architecture design • Identity & Access Management: SSO/IAM platforms (Okta, Azure AD, AWS IAM), MFA, privileged access management (CyberArk, HashiCorp Vault), and role-based/least-privilege access design • Security Operations & Monitoring: SIEM (Splunk, Microsoft Sentinel, ELK), SOAR, EDR/XDR (CrowdStrike, SentinelOne, Microsoft Defender), threat intelligence platforms, and 24x7 SOC oversight • Incident Response & Forensics: IR playbooks, digital forensics, malware analysis fundamentals, breach containment, and coordination with CERT-In for regulatory incident reporting • Vulnerability & Risk Management: Vulnerability scanning (Qualys, Nessus, Tenable), patch management, penetration testing coordination (internal/external), and bug bounty program oversight • Data Security & Cryptography: Encryption (at-rest/in-transit), key management (KMS/HSM), tokenization, DLP tools, and data classification frameworks — critical given handling of financial and PII data • GRC Tooling: Experience with GRC platforms (Archer, ServiceNow GRC, OneTrust) for policy management, risk registers, and audit workflows • Scripting & Automation: Working knowledge of Python, Bash, or similar for security automation, log analysis, and tool integration is a plus Leadership & Soft Skills • Demonstrated ability to build, mentor, and scale a security team • Strong stakeholder management and communication skills — able to translate technical risk into business language for leadership and the board • Sound judgment and decisiveness in high-pressure incident scenarios • Strategic mindset with the ability to balance security rigor with business agility Preferred Certifications • CISSP, CISM, CEH, or equivalent Education • Bachelor's / Master's degree in Computer Science, Information Security, or a related field