DTDC - Practice Head - Data Security & Privacy

DTDC Express Limited

Bengaluru

On-site

INR 3,000,000 - 4,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

DTDC Express Limited in Bengaluru is seeking a Head of Information Security to oversee cyber security governance, data privacy compliance, and risk management. This position involves leading the DPDPA compliance program, managing audits, and ensuring security policies are enforced.

The ideal candidate should have 10-15 years of experience in information security, strong knowledge of DPDPA, and relevant certifications like CISSP or CISM. They’ll also foster a culture of security awareness within the organization.

Qualifications

  • 10-15 years of experience in Information Security, IT Risk, GRC, Privacy, or Cyber Security.
  • Experience leading ISO 27001, SOC, NIST, or equivalent compliance programs.
  • Hands-on experience with DPDPA, GDPR or similar frameworks.

Responsibilities

  • Lead the DPDPA compliance program and define privacy-by-design principles.
  • Develop and maintain the information security governance framework.
  • Manage compliance against ISO 27001, SOC 2, and NIST requirements.

Skills

Information Security
GRC
Data Privacy
Cyber Security

Education

Bachelor's / Master's Degree in Related Field
Preferred Certifications: CISSP, CISM, CRISC

Tools

ISO 27001 Standards
NIST
Cloud Security (AWS, Azure, GCP)

Job description

Role Purpose

The Head Information Security, GRC & Data Privacy will serve as the organization's custodian for cyber security governance, data privacy compliance, and technology risk management. The role is responsible for establishing and operating the security governance framework, driving compliance with the Digital Personal Data Protection Act (DPDPA), managing internal and external audits, ensuring regulatory compliance, and partnering with business and technology teams to embed security and privacy controls across all digital initiatives.

Key Responsibilities
  • Data Privacy & DPDPA Compliance:
    • Lead the organization's DPDPA compliance program from a technology and process perspective.
    • Define and implement privacy-by-design principles across applications, customer journeys, and operational processes.
    • Establish consent management, data retention, data minimization, purpose limitation, and data subject rights processes.
    • Drive implementation of Data Protection Impact Assessments (DPIA).
    • Maintain data inventories, data flow maps, and personal data processing records.
  • Information Security Governance & Risk Management:
    • Develop and maintain the enterprise information security governance framework.
    • Establish cyber risk assessment methodologies and periodic risk reviews.
    • Define and monitor security policies, standards, baselines, and control frameworks.
    • Maintain security risk registers and track mitigation plans.
  • IT GRC (Governance, Risk & Compliance):
    • Own the IT GRC program across applications, infrastructure, cloud, and third‑party ecosystems.
    • Lead internal control assessments and compliance reviews.
    • Manage compliance against ISO 27001, SOC 2, NIST CSF, CIS Controls, and DPDPA requirements.
    • Track audit observations and ensure timely closure of corrective actions.
  • Cyber Security Assurance:
    • Define organization‑wide cyber security requirements and control standards.
    • Oversee vulnerability management, penetration testing, and security assessments.
    • Review security architecture for critical projects and technology deployments.
    • Monitor cyber security posture through KPIs and KRIs.
  • Third‑Party & Vendor Security:
    • Establish third‑party cyber risk assessment processes.
    • Review security posture of technology vendors, SaaS platforms, partners, and outsourced service providers.
    • Define contractual security and privacy requirements.
  • Audit & Regulatory Compliance:
    • Serve as the primary owner for technology audits.
    • Coordinate internal audit, external audit, customer audits, and regulatory assessments.
    • Drive closure of audit findings and monitor remediation plans.
  • Security Awareness & Culture:
    • Build organization‑wide security and privacy awareness programs.
    • Conduct periodic training on cyber security, privacy, phishing, and data handling practices.
Desired Experience
  • 10‑15 years of experience in Information Security, IT Risk, GRC, Privacy, or Cyber Security.
  • Experience leading ISO 27001, SOC, NIST, or equivalent compliance programs.
  • Hands‑on experience with privacy regulations such as DPDPA, GDPR, or similar frameworks.
  • Experience managing technology audits and regulatory assessments.
  • Exposure to cloud security (AWS, Azure, GCP) and SaaS environments.
  • Prior experience in logistics, e‑commerce, fintech, or high‑volume digital businesses preferred.
Preferred Certifications
  • CISSP
  • CISM
  • CRISC
  • ISO 27001 Lead Implementer / Lead Auditor
  • CDPSE
  • DPO Certification
  • CISA
Success Metrics
  • DPDPA compliance maturity score
  • Number of unresolved audit findings
  • Security risk closure SLA adherence
  • Vendor security assessment coverage
  • Compliance certification status
  • Vulnerability remediation effectiveness
  • Reduction in high‑risk security findings
  • Regulatory and customer audit outcomesData privacy incident metrics

(ref:hirist.tech)

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director - Data Privacy & Information Security
Director - Data Privacy & Information Security

Indegene • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Comprehensive health insurance
Retirement benefits
Professional development opportunities
Data Protection and Cybersecurity Manager
Data Protection and Cybersecurity Manager

Stamford International School • Hyderabad

On-site
INR 1,800,000 - 3,000,000
Privacy Lead
Privacy Lead

Paytm • Dadri

On-site
INR 4,000,000 - 8,000,000
Data Protection and Security Analyst
Data Protection and Security Analyst

Isha Foundation, Inc. • Coimbatore District

On-site
INR 800,000 - 1,200,000
Data Privacy consultant
Data Privacy consultant

Keka Technologies • Bengaluru

On-site
INR 1,500,000 - 2,600,000
Data Privacy | One of the leading Big4
Data Privacy | One of the leading Big4

Acme Services • Mumbai

On-site
INR 1,800,000 - 2,400,000
Information Security and Data Privacy Manager
Information Security and Data Privacy Manager

Tiger Analytics • Chennai District

Hybrid
INR 2,500,000 - 6,000,000
Senior Manager- Data Privacy
Senior Manager- Data Privacy

IndiGo • Gurugram District

On-site
INR 1,800,000 - 3,200,000
IT Compliance and Security Manager
IT Compliance and Security Manager

RGP • Pune District

On-site
INR 900,000 - 1,500,000
Data Privacy consultant
Data Privacy consultant

Sisainfosec • Bengaluru

On-site
INR 2,800,000 - 4,200,000