Posted on: 26/06/2026
Job Title : Compliance Manager - Cyber Security & Privacy
Reporting Structure : Reports to AVP - Cyber Security - CSEAP
Education :
University graduate or post graduate degree with specialisation in the field of Cyber Law, Privacy, Computer Science/IT or Engineering Graduate/PG in CS/IT.
Experience/ Qualifications :
- A Minimum 7 - 10 years in data privacy, legal compliance, or information security, ideally within the BFSI or IT/ITES sectors.
- Deep understanding of IT infrastructure, Cyber Security Standards/Frameworks (ISO 27001/NIST), Application Security (OWASP, SANS, and MITRE) and data security controls (Access Control, Data Classification, DLP, Data Discovery, Masking & Encryption etc.).
- Strong working knowledge of the DPDP Act 2023 and Rules 2025, with the ability to translate requirements into actionable workflows.
- Exposure of GDPR or other privacy compliance laws preferred.
- Ability to act independently and provide unbiased advice to management and the Board.
- Excellent verbal and written communication skills is mandatory with management or stakeholder interaction exposure to bridge technical, legal, and regulatory requirements.
- Strong problem-solving abilities and should prioritize tasks effectively
- Comfortable working in a fast-paced environment and able to adapt to changing priorities
Role & Responsibilities :
- Serve as the primary architect of the company's privacy governance framework and lead privacy CoE.
- Oversee the secure and lawful processing of personal data, ensuring absolute compliance with India's DPDP Act and preparing the organization for other global privacy laws such as the EU GDPR.
- Conduct regular internal audits and Data Protection Impact Assessments (DPIAs) for high-risk processing activities.
- Develop, maintain, and update privacy & data protection policies, including Privacy by Design and default principles.
- Evaluate Privacy Enhancing Technologies and co-ordinate for selection and implementation of it.
- Drive Privacy related standards and best practices adoption such as ISO 27701.
- Align with sectoral regulators (e.g., RBI) on Cyber Security and data handling regimes.
- Act as the Point of Contact for the Data Protection Board of India and global supervisory authorities.
- Serve as the nodal officer for Grievance Redressal, managing requests from data principals regarding access, correction, or erasure.
- Collaborate with Business Teams, IT and Cyber Security teams to implement procedural and technical safeguards like encryption, anonymization, and access controls.
- Support to do vendor due diligence from Privacy Compliance perspective.
- Lead privacy breach incident investigation and response to personal data breaches, ensuring mandatory notifications to regulators and affected individuals within statutory timelines (e.g., 72 hours).
- Advises management of critical issues that may affect the overall compliance and risk posture of organization.
- Demonstrate skills by upgrading self-knowledge quickly and transferring it to peers.
- Stay up to date on emerging compliance requirements, and trends in technology security and apply that knowledge.
- Provide training and guidance to staff on privacy compliance & security best practices and procedures.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1648952