SBI opens Group CISO role with ₹2.5 crore package amid rising BFSI cyber risks

SBI opens Group CISO role with ₹2.5 crore package amid rising BFSI cyber risks

The public-sector lender is looking for one vacancy under Advertisement No. CRPD/SCO/2026-27/21. As per the bank’s recruitment notice, the job applications have been open since 4th September 2026 and will close on 24th September 2026. 

 

Initially, the role of Group CISO is being offered for a three-year term, with an extended provision of up to two additional years, depending on the bank’s requirements and the officer’s performance. The appointed candidate might be posted in Mumbai or Navi Mumbai. 

 

The maximum age limit for selection is 57 years as on 31st Aug 2026, with a degree holder in B. Tech/ B.E. in Computer Science/ Computer Science & Engineering/ Software Engineering/ Information Technology/ Electronics/ Electronics & Communications Engineering/Cyber Security or Equivalent Degree in the above specified disciplines with a minimum score of 50%.  Or MCA or M. Tech/ M. Sc in Computer Science/ Computer Science & Engineering/ Information Technology/ Software Engineering/ Electronics/ Electronics & Communications Engineering/Cyber Security or Equivalent Degree in above specified disciplines. (From a University/ Institution/ Board recognized by Govt. Of India/ approved by Govt. Regulatory Bodies .

 

The KRAs of the Group CISO would be: 

  1. Leading the bank’s cybersecurity strategy and governance, 
  2. Overseeing cyber-risk management, threat intelligence, security operations, incident response, and regulatory compliance. 
  3. Engaging with the Board, senior management, regulators, auditors and other stakeholders.
  4. Managing security risks related to cloud environments, identity and access management, privileged access management, third-party and supply-chain ecosystems, business continuity, disaster recovery and emerging technologies such as artificial intelligence and machine learning.

 

This job profile showcases the increasing need for cyber resilience across banking operations. The professional is expected to work closely with regulators and government agencies, including the Reserve Bank of India, CERT-In and NCIIPC, while ensuring the SBI’s information-security programme remains aligned with applicable regulatory and statutory requirements.

 

This appointment by SBI points to the board-level concern for financial institutions. RBI’s IT governance directions require regulated entities to assign the CISO responsibility for driving cybersecurity strategy and compliance, while placing regular cyber-risk and preparedness reviews before the Board or relevant board-level committees.

 

The wider BFSI sector is also confronting a rapidly changing threat environment. MeitY, CERT-In, CSIRT-Fin and SISA’s Digital Threat Report 2025–26 have highlighted threats including AI-enabled attacks, identity compromise, business-logic abuse, supply-chain vulnerabilities and attacks targeting trust in digital financial systems.

 

Candidates will be shortlisted and called for an interview. SBI said the compensation offered to the selected candidate will be negotiable and determined based on experience, suitability, and the bank’s assessment.

Chat with CIONow.in

Sequencing AI, Data and Factory 5.0...