HamburgerMenu
hirist

IT Compliance Manager - Cyber Security & Privacy

Etaash Consultants
7 - 10 Years
Anywhere in India/Multiple Locations

Posted on: 26/06/2026

Job Description

Job Title : Compliance Manager - Cyber Security & Privacy

Reporting Structure : Reports to AVP - Cyber Security - CSEAP

Education :

University graduate or post graduate degree with specialisation in the field of Cyber Law, Privacy, Computer Science/IT or Engineering Graduate/PG in CS/IT.

Experience/ Qualifications :

- A Minimum 7 - 10 years in data privacy, legal compliance, or information security, ideally within the BFSI or IT/ITES sectors.

- Deep understanding of IT infrastructure, Cyber Security Standards/Frameworks (ISO 27001/NIST), Application Security (OWASP, SANS, and MITRE) and data security controls (Access Control, Data Classification, DLP, Data Discovery, Masking & Encryption etc.).

- Strong working knowledge of the DPDP Act 2023 and Rules 2025, with the ability to translate requirements into actionable workflows.

- Exposure of GDPR or other privacy compliance laws preferred.

- Ability to act independently and provide unbiased advice to management and the Board.

- Excellent verbal and written communication skills is mandatory with management or stakeholder interaction exposure to bridge technical, legal, and regulatory requirements.

- Strong problem-solving abilities and should prioritize tasks effectively

- Comfortable working in a fast-paced environment and able to adapt to changing priorities

Role & Responsibilities :

- Serve as the primary architect of the company's privacy governance framework and lead privacy CoE.

- Oversee the secure and lawful processing of personal data, ensuring absolute compliance with India's DPDP Act and preparing the organization for other global privacy laws such as the EU GDPR.

- Conduct regular internal audits and Data Protection Impact Assessments (DPIAs) for high-risk processing activities.

- Develop, maintain, and update privacy & data protection policies, including Privacy by Design and default principles.

- Evaluate Privacy Enhancing Technologies and co-ordinate for selection and implementation of it.

- Drive Privacy related standards and best practices adoption such as ISO 27701.

- Align with sectoral regulators (e.g., RBI) on Cyber Security and data handling regimes.

- Act as the Point of Contact for the Data Protection Board of India and global supervisory authorities.

- Serve as the nodal officer for Grievance Redressal, managing requests from data principals regarding access, correction, or erasure.

- Collaborate with Business Teams, IT and Cyber Security teams to implement procedural and technical safeguards like encryption, anonymization, and access controls.

- Support to do vendor due diligence from Privacy Compliance perspective.

- Lead privacy breach incident investigation and response to personal data breaches, ensuring mandatory notifications to regulators and affected individuals within statutory timelines (e.g., 72 hours).

- Advises management of critical issues that may affect the overall compliance and risk posture of organization.

- Demonstrate skills by upgrading self-knowledge quickly and transferring it to peers.

- Stay up to date on emerging compliance requirements, and trends in technology security and apply that knowledge.

- Provide training and guidance to staff on privacy compliance & security best practices and procedures.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...