
About Burger Singh:
Burger Singh is the quintessential Indian success story. Founded in November 2014, we have grown to become India's largest homegrown Quick Service Restaurant (QSR) chain, with 200+ outlets across COCO and FOFO formats nationwide. Our unique product offerings, tailored to the Indian palate, have made us a market leader in the industry.
Role Overview:
We are looking for a senior IT professional to take end-to-end ownership of our IT infrastructure, network security, and regulatory compliance function most immediately, leading technical implementation of the Digital Personal Data Protection (DPDP) Act 2023 ahead of the 13 November 2026 enforcement deadline. This role will own the organization's core infrastructure (firewall, network, endpoint management), lead a small IT team, and serve as the technical backbone for our ISO 27001 and PCI DSS readiness programs - working closely with Legal & Compliance on the governance side.
Key Responsibilities:
- DPDP Technical Implementation: Own end-to-end technical execution of DPDP compliance controls - data mapping, access controls, encryption, audit logging, breach detection and response mechanisms - working in coordination with Legal & Compliance on consent, grievance redressal, and data principal rights processes.
- Infrastructure Ownership: Manage and harden core IT infrastructure including Fortinet firewall, network architecture, Microsoft 365 administration, and Windows Active Directory/Intune.
- Security Posture: Close existing gaps in DLP, VPN, and Zero Trust architecture; lead implementation of security controls mapped to ISO 27001 Annex A and PCI DSS v4.0.1.
- Team Leadership: Directly manage the IT team (currently structured under two sub-leads handling infrastructure and support), setting priorities, reviewing work, and building technical depth on the team.
- Cloud & Banking Infrastructure Support: Partner with the Tech & Automation function on Azure infrastructure for host-to-host (H2H) bank integrations and related security/access requirements.
- Vendor & Stakeholder Management: Manage relationships with security, compliance, and infrastructure vendors; represent IT in cross-functional planning with Finance, Legal, and business teams.
- Documentation & Audit Readiness: Maintain policy documentation, control evidence, and audit trails required for ISO 27001 certification and DPDP compliance reporting.
Key Skills Required:
- Strong hands-on experience with network security, firewalls (Fortinet or equivalent), and endpoint management (AD/Intune).
- Working knowledge of DPDP Act 2023, ISO 27001, and/or PCI DSS frameworks - practical implementation experience strongly preferred over theoretical knowledge.
- Experience managing a small technical team, with clear prioritization and delegation skills.
- Familiarity with Azure cloud infrastructure (VMs, Functions, networking) is a strong plus.
- Ability to translate compliance requirements into concrete technical controls and timelines.
- Excellent communication skills: this role interfaces regularly with Legal, Finance, and senior leadership, not just technical peers.
- Demonstrated ownership mindset: someone who proactively identifies gaps rather than waiting for direction.
Didn’t find the job appropriate? Report this Job