Head of Information Security
airtel
10 - 12 years
Gurugram
Posted: 05/03/2026
Job Description
Job Description || Airtel Money - NBFC
Head Information Security
Experience: 710 years
Role Overview
We are a digital-first NBFC being built from the ground up. As we prepare for go-live, we are looking for a hands-on Information Security Leader to establish and manage the companys cybersecurity, data protection, and IT governance framework.
This role will be responsible for designing, implementing, and continuously improving the organizations security posture across infrastructure, applications, cloud, data, and third-party ecosystems in alignment with RBI guidelines and industry best practices.
This is an execution-oriented role suited for a high-potential professional who can build security architecture from scratch in a fast-paced environment.
Key Responsibilities
- Security Framework & Governance
Establish and implement the Information Security Policy framework in line with RBI IT Governance Directions.
Develop and maintain policies covering:
Access control
Data protection & encryption
Incident response
Vulnerability management
Third-party security
Implement a structured risk assessment and control testing framework.
- Cloud & Infrastructure Security
Design secure architecture for cloud environments (AWS/Azure/GCP).
Implement:
IAM controls
Network segmentation
Encryption (at rest & in transit)
Secure DevOps practices
Ensure production environments are hardened and monitored.
- Application & Product Security
Work closely with Product and Engineering teams to:
Integrate security-by-design
Conduct code reviews and vulnerability scans
Perform VAPT (Vulnerability Assessment & Penetration Testing)
Ensure secure API architecture and integration practices.
- Regulatory & Compliance Alignment
Ensure adherence to:
RBI IT Governance Guidelines
Data localization requirements
KYC/AML data protection norms
Support RBI inspections and provide required documentation.
Maintain compliance audit readiness at all times.
- Monitoring & Incident Response
Establish Security Operations monitoring (SIEM or managed SOC).
Develop incident response playbooks.
Lead response to any cybersecurity incidents or breaches.
Conduct periodic tabletop exercises.
- Vendor & Third-Party Risk Management
Conduct security due diligence for:
LOS/LMS vendors
Cloud providers
Collection partners
Outsourced service providers
Implement periodic third-party risk assessments.
- Awareness & Culture
Drive organization-wide security awareness training.
Ensure access controls and user privileges follow least-privilege principles.
Promote a culture of cyber hygiene across teams.
Key Requirements:
Experience
710 years of experience in cybersecurity / information security.
Experience in fintech, NBFC, bank, or regulated technology environment preferred.
Hands-on exposure to:
Cloud security
Application security
SOC implementation
Vulnerability management
Experience working with auditors and regulatory bodies preferred.
Skills
Strong understanding of:
ISO 27001
NIST framework
RBI IT governance framework
Knowledge of cloud-native security tools.
Ability to work cross-functionally with Tech, Product, Risk, and Compliance.
High ownership mindset and execution orientation.
Education & Certifications
Bachelors degree in Engineering / Computer Science.
Preferred certifications:
CISSP / CISM / CEH / ISO 27001 Lead Implementer.
Services you might be interested in
Improve Your Resume Today
Boost your chances with professional resume services!
Get expert-reviewed, ATS-optimized resumes tailored for your experience level. Start your journey now.
