Head of Information Security (HIS)

Sahamati

Advance (NC)

On-site

USD 32,000 - 63,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Opportunity to work at the interface:
Exposure to regulators and financials

Job summary

Sahamati Foundation is seeking a Head of Information Security to lead the overall security program, aligning information security with business goals and regulatory requirements. This role drives ISMS governance, risk management, and audit readiness across the organization.

You will lead incident response, security architecture, vendor security, and resilience planning while coordinating with leadership and the Security Committee.

Qualifications

  • Strong knowledge of information security management and ISO 27001 standards.
  • Experience leading security programs and cross-functional teams.
  • Familiarity with regulatory requirements (GDPR and local data protections).

Responsibilities

  • Establish and maintain ISMS governance and related policies.
  • Identify, assess and mitigate information security risks.
  • Oversee compliance with laws, standards and audits.
  • Lead incident response and crisis management activities.
  • Define security controls, architecture and resilience plans.

Skills

ISO 27001
Information security
Risk management
Leadership
Incident response
Regulatory knowledge

Job description

About Sahamati Foundation

Sahamati is the RBI-recognised Self-Regulatory Organisation (SRO) for India’s Account Aggregator ecosystem, a cross-sectoral industry alliance built to advance consent-based financial data sharing. As a not-for-profit industry alliance, we work closely with regulated entities, technology providers, and ecosystem participants to promote secure and consent-driven data sharing under the AA framework.

Role Overview

The Head of Information Security (HIS) is responsible for establishing and maintaining the enterprise vision, strategy for information security, and program to ensure information assets and technologies are adequately protected. The role ensures alignment with business objectives, regulatory requirements, and industry standards and certifications.

Key Responsibilities
  • ISMS Governance & Leadership
  • Establish, implement, maintain, and continually improve the ISMS
  • Define information security policies and standards
  • Ensure integration of ISMS into organisational processes
  • Risk Management
  • Identify, assess, and manage information security risks
  • Define risk appetite in consultation with senior management
  • Maintain the risk register and ensure timely risk treatment
  • Update the information security risk posture to the Information Security Committee
  • Compliance & Regulatory Oversight
  • Ensure compliance with applicable laws, regulations, and standards
  • Drive compliance certification and surveillance audits
  • Coordinate internal and external audits
  • Conduct vulnerability assessment and penetration testing, and ensure remediation of identified vulnerabilities.
  • Ensure third-party/vendor security compliance
  • Security Architecture & Controls
  • Define and enforce security architecture across IT and business systems
  • Ensure implementation of appropriate information security controls
  • Incident Management
  • Establish and maintain an incident response framework
  • Lead response to major security incidents and breaches
  • Ensure root cause analysis and corrective actions
  • Report significant incidents to leadership and the Information Security Committee
  • Security Operations
  • Oversight Security Operations Center(SOC) operations
  • Monitor threats, vulnerabilities, and security events
  • Ensure timely detection and response to threats
  • Business Continuity & Resilience
  • Align with Business Continuity Management (BCM) and Disaster Recovery (DR) standards and build cybersecurity resilience into the Business Continuity Management System (BCMS) process
  • Participate in crisis management
  • Security Awareness & Training
  • Develop organisation-wide security awareness programs
  • Ensure employees understand security policies and responsibilities
  • Promote security culture
  • Third-Party & Supply Chain Security
  • Assess and manage vendor/security risks
  • Ensure contractual security requirements are defined and enforced
  • Conduct vendor audits and reviews
  • Reporting & committees Engagement
  • Provide regular updates to committees on:
    • Information Security posture
    • Information security Risk exposure
    • Security Incident Trends
    • Information security Compliance status
  • Alignment of security risks with business operations
  • Budget & Resource Management
  • Develop and manage a cybersecurity budget
  • Optimise investments in security tools and resources
  • Ensure cost-effective risk mitigation
What We Offer
  • Opportunity to work at the intersection of technology, finance, and policy in one of India’s most transformative digital ecosystems.
  • Exposure to leading financial institutions, regulators, and innovators shaping the future of consent-based data sharing.
  • A collaborative and purpose-driven work environment that values initiative and learning.
Key Skills & Competencies
  • Curious to learn about the AA ecosystem and its stakeholder landscape.
  • Strong knowledge of ISO 27001 and cybersecurity frameworks
  • Information security Risk management expertise
  • Leadership and stakeholder management
  • Incident response and crisis management
  • Regulatory knowledge (e.g., GDPR, local data protection laws)

Location: Bengaluru (On-site)

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Chief Information Security & Risk Leader
Chief Information Security & Risk Leader

Sahamati • Advance (NC)

On-site
USD 32,000 - 63,000
Opportunity to work at the interface:
Exposure to regulators and financials
Information Security Program Lead
Information Security Program Lead

MSA, The Safety Company • Cranberry Township

On-site
USD 120,000 - 180,000
IT Security Manager
IT Security Manager

True North Consulting, LLC • Olathe (KS)

On-site
USD 90,000 - 120,000
Head of Cyber & Information Security Oversight (SVP)
Head of Cyber & Information Security Oversight (SVP)

The Security Executive Council • Quincy (MA)

On-site
USD 225,000 - 338,000
401(k)
Health insurance
Paid time off
Information Security Manager
Information Security Manager

Arco Solutions • Kansas

On-site
USD 120,000 - 150,000
Flexible schedule
Health insurance
Sr. Consultant, Information Security (Banking)
Sr. Consultant, Information Security (Banking)

HashCash Consultants • Palo Alto (CA)

On-site
USD 120,000 - 180,000
Senior Manager, Information Security
Senior Manager, Information Security

Uniting Holding • Houston (TX)

On-site
USD 120,000 - 150,000
Head of Cyber & Information Security Oversight (SVP)
Head of Cyber & Information Security Oversight (SVP)

The Security Executive Council • Clifton (NJ)

On-site
USD 225,000 - 338,000
Generous medical care
401K retirement savings plan
Educational support programs
ISMS Compliance Manager
ISMS Compliance Manager

Hexagon Mining • Tucson (AZ)

On-site
USD 90,000 - 120,000
CRO - Information Security & Risk Oversight Lead
CRO - Information Security & Risk Oversight Lead

Bloomberg • New York (NY)

On-site
USD 140,000 - 180,000