Chief Information Security Officer (CISO)
Company Overview
White Oak Capital is an investment management firm managing over $11 billion of Assets Under Management (AUM) across India and Global Emerging Markets. Founded by Prashant Khemka, former CIO of Emerging Markets Equity and India Equity at Goldman Sachs Asset Management, the firm operates with a global presence including offices in India, Singapore, Switzerland, Dubai, Mauritius, and the UK. The company fosters a dynamic and professional environment focused on strategic investment and financial excellence.
Job Summary
The Chief Information Security Officer (CISO) will provide strategic and operational leadership for White Oak Capital’s cybersecurity and information security functions. The role involves developing and maintaining a comprehensive security framework to safeguard sensitive data, digital assets, investor information, applications, and technology infrastructure. The CISO will ensure compliance with regulatory standards such as SEBI and AMFI, manage cyber risks, lead incident response efforts, and promote a security-aware culture across the organization. This position is critical in aligning cybersecurity initiatives with the firm’s business objectives and regulatory requirements.
Responsibilities
- Develop and implement the organization’s cybersecurity and information security strategy, policies, standards, and frameworks, ensuring continuous improvement.
- Establish and oversee security governance, controls, and monitoring mechanisms across all organizational units.
- Identify emerging cybersecurity threats and implement appropriate mitigation measures to protect organizational assets.
- Ensure compliance with regulatory requirements such as SEBI cybersecurity guidelines, AMFI standards, and other relevant industry regulations.
- Lead cyber risk management, including assessment and mitigation of risks associated with third-party vendors and technology partners.
- Build and maintain a robust threat intelligence program, proactively identifying vulnerabilities and attack vectors.
- Establish and manage incident detection, response, escalation, and recovery processes to ensure rapid and effective handling of cybersecurity incidents.
- Oversee Business Continuity Planning (BCP) and Disaster Recovery (DR) strategies, conducting regular testing and updates.
- Drive organization-wide cybersecurity awareness and training programs, including mock drills and phishing simulations.
- Ensure protection of sensitive data related to investors, employees, and organizational operations, maintaining data privacy and confidentiality.
- Collaborate with senior management, internal teams, external auditors, regulators, and third-party vendors to embed security best practices into business processes.
- Provide regular updates and reports on cybersecurity risks, incidents, and compliance status to executive leadership and governance forums.
Qualifications
- 15+ years of relevant experience in Information Security, Cybersecurity, Technology Risk, or related fields.
- Strong knowledge of cybersecurity frameworks, principles, and risk management practices.
- In-depth understanding of regulatory requirements related to information security, including SEBI, AMFI, and other financial industry standards.
- Experience in cyber risk assessment, threat intelligence, vulnerability management, and incident response.
- Proven expertise in third-party/vendor cybersecurity risk management.
- Knowledge of Business Continuity Planning (BCP), Disaster Recovery (DR), and cyber resilience.
- Excellent stakeholder management, communication, and leadership skills.
- Ability to work effectively with senior management, technology teams, auditors, regulators, and external partners.
- Educational qualifications such as BTech, BSc, MSc, or equivalent in relevant fields.
Preferred Skills
- Professional certifications such as CISSP, CISM, CRISC, CISA, ISO 27001, or equivalent.
- Experience in Financial Services, Mutual Funds, Asset Management, or Banking industries.
- Prior experience managing cybersecurity within regulated financial environments.
- Strong understanding of international cybersecurity standards and best practices.
- Ability to develop and execute cybersecurity awareness and training programs.
Experience
- Minimum 15 years of relevant experience in Information Security, Cybersecurity, or Technology Risk Management.
- Prior experience in regulated financial sectors such as Mutual Funds, Asset Management, Banking, or Financial Services is preferred.
- Demonstrated success in leading cybersecurity initiatives in complex organizational settings.
Environment
The role is based in a professional office environment, with potential for hybrid work arrangements depending on organizational policies. The position involves collaboration with global teams and external stakeholders, requiring adaptability to different time zones and regulatory environments. The work may involve occasional travel for audits, training, or strategic meetings.
Salary
Salary details are not specified and will be commensurate with experience and qualifications.
Growth Opportunities
Opportunities for career advancement include Senior Leadership roles within the organization’s risk and compliance functions, or broader executive positions such as Chief Risk Officer or Chief Operating Officer, depending on organizational growth and individual performance.
Benefits
Benefits details are not specified in the provided information. Typically, such roles include health insurance, performance bonuses, professional development support, and other standard corporate benefits.