
Role Summary:
We are seeking a seasoned Information Security & Data Privacy professional responsible for managing IT General Controls (ITGC), Cyber Security governance, and Data Privacy risk frameworks. The role will focus on strengthening security posture, ensuring regulatory compliance, managing cyber risks, and safeguarding sensitive data across systems and processes.
The incumbent will partner with Technology, Risk, Compliance, and Business teams to ensure robust controls, audit readiness, and effective privacy governance.
Key Responsibilities:
IT General Controls (ITGC):
Design, implement, and monitor ITGC controls across applications, infrastructure, and databases.
Manage controls around:
- User Access Management (UAM)
- Privileged Access Monitoring
- Change Management
Logical Access & Segregation of Duties (SoD):
- Backup & Recovery Controls
- Support internal and external audits (SOX / IFC / RBI / ISO audits).
- Drive remediation of audit findings and control gaps.
Cyber Security Governance:
- Develop and maintain cybersecurity policies, standards, and procedures.
- Conduct cyber risk assessments and vulnerability management reviews.
Oversee:
- Security incident management
- Threat & vulnerability assessments
- Third-party security risk assessments
Monitor adherence to frameworks such as:
- ISO 27001
- NIST CSF
- COBIT
- CIS Controls
- Provide periodic risk reporting to senior management.
Data Privacy & Risk Management:
Implement and manage data privacy controls aligned with:
- DPDP Act (India)
- GDPR (if applicable)
- Other regulatory requirements
- Conduct Data Protection Impact Assessments (DPIAs).
- Maintain data inventory and data classification framework.
Ensure:
- Consent management compliance
- Cross-border data transfer governance
- Vendor data protection due diligence
- Manage data breach response and regulatory notifications.
Risk & Compliance Management:
- Perform enterprise IT risk assessments.
- Maintain risk register and track mitigation plans.
- Collaborate with Legal, Compliance, and Business stakeholders.
- Drive awareness programs on information security and privacy.
Required Qualifications:
- Bachelor's degree in Information Security, Computer Science, IT, or related field.
- 6-12+ years of experience in IT Risk, ITGC, Cyber Security, and/or Data Privacy.
- Experience in regulated environments (Banking / Financial Services preferred).
Preferred Certifications
- CISA
- CISM
- CISSP
- CRISC
- ISO 27001 LA/LI
- Certified Data Privacy Professional (CDPP / CIPP)
Key Skills & Competencies:
- Strong understanding of ITGC controls and audit processes
- Deep knowledge of cyber risk frameworks
- Data privacy governance and regulatory knowledge
- Stakeholder management and board reporting
- Strong analytical and documentation skills
- Ability to manage cross-functional teams
Didn’t find the job appropriate? Report this Job