An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Sumitomo Mitsui Banking Corporation (SMBC) seeks a privacy and information security professional to support DPDP compliance, data protection controls and DPIA work streams across processes and vendors.
The role requires strong knowledge of privacy laws (DPDP/GDPR), risk management, and incident response, with collaboration across DPO and governance forums. Prior experience in financial services privacy is preferred.
Select how often (in days) to receive an alert:
Headquartered in Tokyo, Sumitomo Mitsui Banking Corporation (SMBC) is a leading global financial institution and a core member of Sumitomo Mitsui Financial Group (SMBC Group). Built upon our rich Japanese heritage since 1876, we put our customers first and provide seamless access to, from and within the Asia Pacific region. SMBC is one of the largest Japanese banks by assets and maintain strong credit ratings across our global integrated network. We work closely as one SMBC Group to offer personal, corporate and investment banking services to meet the needs of our customers.
With sustainability embedded within our strategy and operations, we are committed to creating a society in which today’s generation can enjoy economic prosperity and well-being, and pass it on to future generations.
These are the key work activities to achieve the position objective. Limit this section to essential responsibilities.
List of duties that are marginal or infrequent.
20%
Maintain control inventories, evidence records and exception trackers.
20%
Prepare compliance status inputs and maintain supporting documentation for DPO review.
15%
Record risks, control gaps, mitigating actions, owners and target dates.
15%
Monitor implementation evidence and elevate overdue or unresolved matters.
15%
Maintain incident files, chronology, decisions and closure evidence.
10%
Maintain assessment results, exceptions and remediation records.
5%
Coordinate periodic reporting inputs and training records.
100%
Education & Qualifications: Relevant Graduate or post-graduate qualification. Relevant certifications such as Certified Information Privacy Professional (CIPP), Certified Information Privacy Manager (CIPM), Certified Information Privacy Technologist (CIPT), Certified Information Systems Security Professional (CISSP), ISO 27001, Security+, or equivalent may be preferred depending on grade.