Posted on: 09/09/2025
About the Role :
We are looking for a seasoned Information Security Officer to lead our enterprise-wide information security and compliance initiatives. This role is critical in safeguarding sensitive data, ensuring regulatory compliance, and embedding a culture of security across the organization.
The ideal candidate brings deep technical expertise combined with a strong grasp of evolving legal and regulatory frameworks.
Key Responsibilities :
Regulatory & Compliance Oversight :
- Ensure compliance with DPDP Act, IT Act, SEBI, KRA, IRDAI, and ISO 27001 frameworks.
- Define and enforce data classification protocols for sensitive information (KYC, Aadhaar, financial records).
- Manage third-party/vendor risk assessments and oversee contractual compliance for data processors/controllers.
- Monitor regulatory changes and cybersecurity threats; implement proactive countermeasures.
Security Architecture & Operations :
- Design and enforce enterprise-wide security controls including credential management, multi-factor authentication, and privileged access.
- Oversee device and network protection mechanisms : MDM, VPN-only access, domain restrictions, USB lockdowns.
- Establish advanced logging and auditing frameworks (AAA - Authentication, Authorization, Accounting) for threat detection and incident tracing.
- Lead vulnerability management, penetration testing, and breach incident response.
Governance, Risk & Training :
- Develop and implement data security governance policies across business units.
- Act as the final escalation authority during breaches or compliance conflicts.
- Drive organization-wide security awareness, employee training, and certifications.
- Align security initiatives with business strategy while mitigating regulatory and reputational risks.
Qualifications & Skills :
- 8 - 12 years of progressive experience in Information Security, Cybersecurity, or IT Compliance.
- Strong command over data privacy and enterprise security standards (ISO 27001, SOC 2, NIST frameworks).
- Expertise in infrastructure security, access management, SIEM solutions, and endpoint/device controls.
- Strong analytical skills with the ability to balance regulatory enforcement and business enablement.
- Excellent stakeholder management, communication, and leadership skills
Did you find something suspicious?
Posted By
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1543058
Interview Questions for you
View All