The Virtual Chief Information Security Officer (vCISO) is responsible for providing strategic cybersecurity leadership, governance, risk management, compliance oversight and advisory services to the organization. The role serves as a trusted security advisor to executive leadership, ensuring that information security initiatives align with business objectives, regulatory requirements, and industry best practices while enhancing the organization's overall security posture.
Key Responsibilities
- Develop, implement, and maintain the organization's enterprise-wide cybersecurity and information security strategy.
- Provide executive-level security guidance, recommendations, and periodic reporting to senior management and stakeholders.
- Establish and drive the long-term cybersecurity roadmap aligned with business goals and emerging threats.
- Advise leadership on security investments, priorities, and risk-based decision making.
- Ensure compliance with applicable security frameworks, standards, and regulations, including ISO 27001, NIST, IT Act, and other relevant requirements.
- Conduct enterprise-wide information security risk assessments and maintain the organizational risk register.
- Develop, review, and enforce information security policies, standards, procedures, and governance frameworks.
- Strong domain knowledge of Network security, Risk control, IAM, Encryption, Zero trust, Security operations, vulnerability management, Incident response etc.
- Support internal and external audits and ensure continuous compliance readiness.
- Develop and oversee incident response plans, processes, and coordination activities.
- Identify, assess, and mitigate cybersecurity risks across the organization.
- Provide guidance on threat intelligence, vulnerability management, security monitoring, and emerging cyber threats.
- Act as a key advisor during major security incidents and crisis management situations.
- Lead and oversee cybersecurity programs, initiatives, resources, and security teams.
- Establish security governance forums, steering committees, and reporting mechanisms.
- Define and monitor security KPIs, KRIs, metrics, and maturity improvement programs.
- Drive continuous improvement of the organization's cybersecurity capabilities and resilience.
- Design and conduct enterprise-wide security awareness and education programs.
- Develop role-based cybersecurity training initiatives for employees and leadership teams.
- Plan and execute phishing simulation campaigns and measure effectiveness. Foster a security-conscious culture across the organization. Conduct and oversee third-party and vendor security risk assessments.
- Establish security requirements and controls for suppliers, vendors, and service providers.
- Evaluate supply chain cybersecurity risks and recommend mitigation measures. Support procurement and contract reviews from a cybersecurity perspective.
- Review and assess the security of infrastructure, applications, endpoints, networks, and cloud environments.
- Provide strategic and technical recommendations to enhance security controls and architecture.
- Oversee security audits, vulnerability assessments, and penetration testing activities.
- Advise on implementation of industry best practices and security technologies.
- Conduct Operational Technology (OT) security assessments and maturity reviews.
- Provide guidance on the implementation of OT-specific security controls and frameworks.
- Identify and mitigate cybersecurity risks in industrial control systems (ICS), SCADA, and OT environments.
- Support secure integration between IT and OT environments.
Required Qualifications
- Bachelor’s degree in information security, Cybersecurity, Computer Science, Information Technology, or a related field.
- Minimum 8-10 years of experience in information security, cybersecurity, risk management, or IT leadership roles.
- Proven experience in a CISO, Deputy CISO, Security Director, or vCISO capacity.
- Strong understanding of security frameworks such as ISO 27001, NIST CSF, CIS Controls, COBIT, and regulatory compliance requirements.
- Experience in risk management, incident response, security governance, cloud security, and third-party risk management.
- Knowledge of OT/ICS security principles and industrial cybersecurity practices.
Preferred Certifications
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CRISC (Certified in Risk and Information Systems Control)
- ISO 27001 Lead Implementer / Lead Auditor
- CCSP (Certified Cloud Security Professional)
- GIAC / GICSP (for OT Security)
Key Competencies
- Strategic Leadership
- Cybersecurity Governance
- Risk Management
- Stakeholder Management
- Regulatory Compliance
- Incident Response & Crisis Management
- Security Architecture & Cloud Security
- Third-Party Risk Management
- OT Security Expertise
- Communication & Executive Reporting
- Program & Team Management
Reporting To: Executive Management / Board / CIO / CEO (as applicable) Employment Type: Full-Time / Consulting / Managed Security Services Engagement (as applicable)
Location: Pune
Pay: ₹258,055.12 - ₹1,400,000.53 per year
Work Location: In person