Information Security & Data Privacy Lead

BIG4

Gurugram District

On-site

INR 5,200,000 - 6,800,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

KPMG is seeking an Associate Director for Information Security & Data Privacy to lead a small team and drive security governance across multiple geos. The role requires deep expertise in information security, risk management, and data privacy, with responsibility for strategy, compliance, and incidents.

The position supports a flexible work pattern with partial office presence, and expects strong communication with leadership, clients, and suppliers.

Qualifications

  • Minimum 13 years’ experience in information security and risk management.
  • Familiar with GDPR and DPDPA data privacy regulations.
  • CISSP, CISM or ISO 27001 certifications preferred.
  • Experience with Secure SDLC and DevSecOps practices.
  • Knowledge of ISO 27001, NIST and SOC2 frameworks.
  • Ability to communicate business impact of infosec operations.

Responsibilities

  • Oversee information security risk management and policy compliance.
  • Manage incident response coordination with local and global teams.
  • Review technology projects for security risks and cloud environments.
  • Lead security governance across security operations.

Skills

Information Security
Risk Management
Data Privacy
Cloud Security
Security Governance
DevSecOps
ISO 27001

Education

Bachelor's degree in Computer Science/Information Technology or MCA

Tools

CASBs
Identity & Access Management
API gateways

Job description

Proposed designation: Associate Director- Information Security & Data Privacy

  • Role type: Supervisory-Managing the team consisting of 2 Managers, 1 Sr Executive and 2 CWKs.
  • Geo to be supported: US/UK/ROW/Across geos
  • Work timings: Flexible. Work from office atleast 2 days.
  • Governance: Accountability for the management of information security within the KPMG member firm, with the mandate from senior leadership, including strategy and planning, monitoring and maintenance, investments, projects and communication.
  • Information Security Risk Management: Oversight of information security risk management through risk assessment, including approval of key risks, involvement in information security related escalations, review of contractual terms, response to client questionnaires and RFP, accountability for review of suppliers and acquisitions.
  • Compliance to Policies and Standards: Responsibility for supporting ongoing information security compliance initiatives, including policies and standards related to information security, technology, data governance and privacy
  • Technology Approvals: Accountability for the review and approval of technology in relation to information security risks, including involvement and review of technology projects, approval of significant changes to technology environments, approval of cloud environments, and approval of Global Technology Standard exceptions.
  • Security Operations: Accountability for security operations, working with technology teams to ensure that technical & information security compliance standards are met on an ongoing basis.
  • Incident Management: Coordinates the local Member Firm incident response processes, including escalation to global (GSOC) where necessary and conducting readiness rehearsals within the KPMG member firm.
  • Minimum Bachelor's degree in Computer Science, Information Technology or MCA.
  • Hold industry standard accreditation or certifications. (i.e., CISSP, CISM, ISO 27001)
  • Be familiar with current data privacy regulations, including GDPR, DPDPA
  • Should have a minimum of 13 years’ experience within information security and risk management.
  • Have understanding and experience with Secure SDLC and DevSecOps or security automation.
  • Strong background in Information Security, Risk Management, and Data Privacy
  • Expertise in ISO 27001 , NIST, SOC2, GDPR, DPDPA , and related frameworks
  • Experience with Cloud Security, DevSecOps, Security Automation, Identity & Access Management, and Security Governance
  • Professional certifications such as CISSP, CISM, or ISO 27001 preferred
  • Be capable of understanding and communicating the business and profit impact that infosec operations have on the organization
  • Understand the requirements of relevant information security frameworks and attestations including for example ISO 27001, NIST, SOC2, SoQM
  • The official language of KPMG International is English; therefore, appropriate written and verbal skills in English are needed.
  • Knowledge of cloud security and governance tools, cloud access security brokers (CASBs), and server virtualization technologies.
  • Strong experience with Directories, SSO, Federation, Delegated administration, API gateways
  • Good understanding of cloud computing architecture, technical design and implementations, including Infrastructure as a Service (IaaS), Platform as a Service (PaaS) and Software as a Service (SaaS) delivery models
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director - Data Privacy & Information Security
Director - Data Privacy & Information Security

Indegene • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Comprehensive health insurance
Retirement benefits
Professional development opportunities
Senior Manager - Cybersecurity and Risk Management
Senior Manager - Cybersecurity and Risk Management

PriceWaterhouseCoopers Pvt Ltd ( PWC ) • Bengaluru

On-site
INR 900,000 - 1,300,000
Information Security and Data Privacy Manager
Information Security and Data Privacy Manager

Tiger Analytics • Chennai District

Hybrid
INR 2,500,000 - 6,000,000
IN_Manager_ IT Risk– GCC–Advisory- Bangalore
IN_Manager_ IT Risk– GCC–Advisory- Bangalore

PwC India • Bengaluru

On-site
INR 3,000,000 - 5,200,000
Assistant Vice President – Information Security
Assistant Vice President – Information Security

IndiaFirst Life • Mumbai

On-site
INR 1,000,000 - 1,500,000
SRC Generic_Senior Associate
SRC Generic_Senior Associate

PwC Acceleration Center India • Mumbai

On-site
INR 800,000 - 1,200,000
IT Risk Specialist
IT Risk Specialist

PriceWaterhouseCoopers Pvt Ltd ( PWC ) • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Senior Consultant - Data Protection
Senior Consultant - Data Protection

Meta Infotech • Mumbai

On-site
INR 1,200,000 - 1,800,000
Data Privacy consultant
Data Privacy consultant

Sisainfosec • Bengaluru

On-site
INR 2,800,000 - 4,200,000
Senior Data Governance Specialist
Senior Data Governance Specialist

Capco Technologies Pvt Ltd • Bengaluru

On-site
INR 400,000 - 700,000