Chief Information Security Officer (CISO)
This role is for one of Weekday’s clients
Min Experience: 8+ years
Location: Bengaluru, Karnataka
JobType: full-time
We are seeking an experienced and strategic Chief Information Security Officer (CISO) with 8–18 years of experience to lead the organization’s information security, cybersecurity, and technology risk initiatives. The ideal candidate will combine strong expertise in security research, IT security, and emerging agentic technologies with the ability to build scalable security programs, protect critical systems and data, and establish a strong security culture across the organization.
The CISO will be responsible for defining and executing the organization’s cybersecurity strategy, identifying emerging threats, strengthening security architecture, and ensuring that security practices evolve alongside rapidly changing technologies. The role requires a hands-on understanding of modern IT environments and emerging AI and agentic systems, including the security implications of autonomous AI agents, AI-enabled workflows, APIs, models, and integrations.
Requirements
Key Responsibilities
- Develop and execute a comprehensive information security and cybersecurity strategy aligned with business objectives and technology priorities.
- Lead enterprise-wide security programs covering infrastructure, applications, networks, endpoints, cloud environments, identity, data, and emerging technologies.
- Conduct and oversee security research to identify emerging vulnerabilities, attack techniques, threat vectors, and evolving cybersecurity risks.
- Monitor the rapidly evolving threat landscape and translate research findings into practical security controls, policies, and risk-mitigation strategies.
- Define security approaches for agentic AI systems, including agent identity, authorization, access controls, data protection, prompt and tool security, monitoring, and prevention of unauthorized autonomous actions.
- Evaluate security risks associated with AI models, agents, APIs, third-party integrations, automation platforms, and machine-to-machine interactions.
- Establish security architecture principles and ensure that IT systems and applications follow secure-by-design practices.
- Lead vulnerability management, penetration testing, incident response, threat detection, security monitoring, and security operations.
- Develop and maintain information security policies, standards, procedures, and governance frameworks.
- Establish effective security metrics, dashboards, risk reporting, and executive-level communication.
- Partner closely with engineering, IT, product, legal, compliance, and business teams to integrate security into technology and operational processes.
- Lead investigations and coordinate responses to security incidents, breaches, vulnerabilities, and other cybersecurity events.
- Assess third-party and vendor security risks and establish appropriate security requirements and controls.
- Build, mentor, and manage high-performing cybersecurity and information security teams.
- Drive security awareness and training programs to promote responsible security practices throughout the organization.
- Evaluate emerging security technologies and recommend solutions that improve the organization’s security posture without unnecessarily impacting business agility.
Must-Have Skills
- Security Research: Strong understanding of cybersecurity research, vulnerability analysis, threat intelligence, attack methodologies, and emerging security risks.
- Agentic / AI Security: Experience or strong technical understanding of agentic AI, autonomous systems, AI security, model risks, AI-enabled applications, and securing AI-driven workflows.
- IT Security: Deep knowledge of IT infrastructure, networks, cloud environments, identity and access management, endpoint security, application security, and security architecture.
- Strong experience designing and implementing enterprise cybersecurity strategies and security governance programs.
- Proven leadership experience managing security teams and working with senior technology and business stakeholders.
- Strong understanding of risk management, incident response, vulnerability management, security monitoring, and security operations.
- Ability to communicate complex technical security issues clearly to executives and non-technical stakeholders.
Good-to-Have Skills
- Experience working with SaaS platforms, cloud-native environments, and multi-tenant architectures.
- Exposure to security standards and frameworks such as ISO 27001, SOC 2, NIST, CIS, or similar frameworks.
- Experience securing AI/ML platforms, APIs, automation systems, or large-scale distributed applications.
- Relevant cybersecurity certifications such as CISSP, CISM, CCSP, or equivalent qualifications.
Experience
8–18 years of overall experience in cybersecurity, information security, IT security, or related technology leadership roles, with demonstrated experience leading security initiatives, teams, and enterprise technology risk programs.
Skills
As published by workable · 2 questions
First name, Last name, Email, Phone, Resume
- What’s your current salary? (in lakhs per annum)
- How many days is your notice period?