Director - Data Privacy & Information Security

Indegene

Bengaluru

On-site

INR 2,000,000 - 3,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Comprehensive health insurance
Retirement benefits
Professional development opportunities

Job summary

A global information security firm seeks a Director / Associate Director for Data Privacy & Information Security. The role involves leading information security governance and data protection programs globally, ensuring compliance with regulations like GDPR and the India DPDP Act. Candidates should have 12–14+ years of experience in cybersecurity and strong abilities in vendor security management. The position requires collaboration with key functions across the organisation to enhance cybersecurity posture and promote responsible data handling practices.

Qualifications

  • Extensive experience in managing information security or privacy programs.
  • Strong understanding of global data protection regulations.
  • Experience handling enterprise cybersecurity incidents.

Responsibilities

  • Lead the organisation's information security governance initiatives.
  • Implement and manage the Information Security Management System.
  • Ensure compliance with data protection regulations.

Skills

Information Security Governance
Cybersecurity Risk Management
Data Privacy Compliance
Vendor Security Assessment
Cross-functional Leadership

Education

12–14+ years in relevant fields

Tools

ISO 27001
NIST Cybersecurity Framework
CIS Controls

Job description

The Director / Associate Director – Data Privacy & Information Security will lead the organisation’s information security governance and data protection programs, ensuring that enterprise systems, digital assets, and personal data are protected across global operations.

The role is responsible for designing, implementing, and managing the organisation’s Information Security Management System (ISMS) and data privacy governance frameworks, ensuring compliance with global security standards, regulatory requirements, and client security expectations.

Working closely with Enterprise Risk, Legal & Compliance, Technology, Internal Audit, and business leadership, the role will strengthen the organisation’s cybersecurity posture, safeguard personal data, manage cyber risk exposure, and embed security and privacy principles across technology platforms and business processes.

Key Responsibilities
Information Security Governance
  • Establish and maintain the organisation’s Information Security Management System (ISMS) aligned with global standards such as ISO 27001, NIST Cybersecurity Framework, and CIS Controls.
  • Develop and enforce enterprise-wide information security policies, standards, and procedures.
  • Ensure the confidentiality, integrity, and availability of enterprise information assets and IT systems.
  • Conduct periodic security risk assessments and support enterprise security control reviews.
Cybersecurity Operations & Risk Management
  • Monitor cybersecurity threats, vulnerabilities, and enterprise cyber risk exposure.
  • Oversee vulnerability management programs, threat monitoring, and security control implementation.
  • Lead response and remediation activities for cybersecurity incidents and security breaches.
  • Track security incidents and coordinate with Enterprise Risk Management to ensure cyber risks are reflected in enterprise risk registers.
Data Privacy & Personal Data Protection
  • Implement and manage the organisation’s data privacy governance program.
  • Ensure compliance with applicable data protection regulations including GDPR, UK GDPR, India DPDP Act, and other global privacy frameworks.
  • Maintain records of processing activities, privacy policies, and data protection governance documentation.
  • Conduct Data Protection Impact Assessments (DPIAs) for new systems, technologies, and data processing initiatives.
  • Ensure appropriate safeguards for cross-border data transfers and vendor data processing activities.
Vendor Security & Data Protection Risk Management
  • Conduct security and privacy risk assessments for third-party vendors and service providers handling company systems or data.
  • Evaluate vendor cybersecurity practices and privacy controls against enterprise security standards.
  • Ensure vendors comply with organisational security and data protection requirements.
  • Collaborate with procurement and legal teams to ensure appropriate security and data protection clauses are included in vendor contracts.
Privacy & Security by Design
  • Embed security-by-design and privacy-by-design principles into enterprise systems, products, and digital platforms.
  • Collaborate with engineering and IT teams to implement secure architecture, encryption, and access control mechanisms.
  • Provide guidance on data classification, data retention, and secure data handling practices.
Incident Response & Breach Management
  • Lead investigation and response to cybersecurity incidents and personal data breaches.
  • Coordinate cross-functional incident response with Legal, Enterprise Risk, and Technology teams.
  • Support regulatory breach notification processes where required.
  • Conduct post-incident reviews and implement improvements to strengthen security posture.
Security & Privacy Compliance and Audits
  • Support internal and external security and privacy audits, including ISO 27001 certification, client security assessments, and regulatory inspections.
  • Maintain documentation and evidence required for security certifications and regulatory reviews.
  • Track remediation actions arising from security and privacy audit findings.
Security & Privacy Awareness
  • Develop and implement security and privacy awareness programs across the organisation.
  • Promote responsible data handling practices and strengthen organisational cyber awareness culture.
Cross-Functional Collaboration

The role will collaborate closely with key governance and operational functions:

Chief Legal, Risk & Compliance Officer

Overall governance oversight and regulatory alignment.

Integration of cyber and privacy risks into enterprise risk frameworks.

Compliance & Legal

Regulatory compliance, breach notification obligations, and privacy governance.

Implementation of security controls, infrastructure protection, and secure architecture.

Internal Audit

Independent assurance over security and privacy governance frameworks.

Key Qualifications
  • 12–14+ years of experience in information security, cybersecurity, data privacy, or technology risk roles.
  • Experience managing enterprise information security or privacy programs within multinational or technology-driven organisations.
  • Strong understanding of ISO 27001, NIST Cybersecurity Framework, CIS Controls, or equivalent security standards.
  • Knowledge of global data protection regulations including GDPR and emerging privacy frameworks.
  • Experience managing cybersecurity incidents, vulnerability management programs, and security governance frameworks.
  • Strong stakeholder management and cross-functional leadership capabilities.
Preferred Certifications

Candidates with the following certifications are preferred:

  • CISSP – Certified Information Systems Security Professional
  • CISM – Certified Information Security Manager
  • CISA – Certified Information Systems Auditor
  • CIPP / CIPM – Privacy Certifications

Reporting to: Chief Legal, Risk & Compliance Officer

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security and Data Privacy Manager
Information Security and Data Privacy Manager

Tiger Analytics • Chennai District

Hybrid
INR 2,500,000 - 6,000,000
Data Protection and Cybersecurity Manager
Data Protection and Cybersecurity Manager

Stamford International School • Hyderabad

On-site
INR 1,800,000 - 3,000,000
DTDC - Practice Head - Data Security & Privacy
DTDC - Practice Head - Data Security & Privacy

DTDC Express Limited • Bengaluru

On-site
INR 3,000,000 - 4,500,000
Information Security & Data Privacy Lead
Information Security & Data Privacy Lead

BIG4 • Gurugram District

On-site
INR 5,200,000 - 6,800,000
Privacy Lead
Privacy Lead

Paytm • Dadri

On-site
INR 4,000,000 - 8,000,000
Senior Consultant - Data Protection
Senior Consultant - Data Protection

Meta Infotech • Mumbai

On-site
INR 1,200,000 - 1,800,000
IT Compliance and Security Manager
IT Compliance and Security Manager

RGP • Pune District

On-site
INR 900,000 - 1,500,000
Data Protection Officer & IS Compliance lead (DPO&ISCL)
Data Protection Officer & IS Compliance lead (DPO&ISCL)

GMR Power Urban Infra • New Delhi

On-site
INR 3,200,000 - 5,200,000
Vice President - Global Head of Information Security
Vice President - Global Head of Information Security

RateGain • India

On-site
INR 2,500,000 - 3,500,000
Assistant Vice President, Lead Data Protection & Chief of Staff
Assistant Vice President, Lead Data Protection & Chief of Staff

SMFG INDIA CREDIT COMPANY • Mumbai

On-site
INR 4,000,000 - 7,500,000