IT Compliance and Security Manager

RGP

Pune District

On-site

INR 900,000 - 1,500,000

Full time

Just now
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

RGP in Pune, India is seeking an IT Compliance & Security Manager to safeguard the organization’s cybersecurity framework, ensure SOX controls, and uphold data privacy programs.

You will lead privacy governance, ITGC/SoD, audits, and vendor risk, while driving security awareness across staff and implementing compliant, scalable processes.

This role partners with legal and IT to respond to incidents, manage DPIA/PIA, data mapping, and training, shaping a security-first culture.

Qualifications

  • Bachelor’s degree in IT, cybersecurity, CS or related field.
  • 10+ years in IT security, audit, or compliance with SOX environments.
  • Professional certifications such as CISSP, CISM, or CISA.
  • Familiarity with privacy management software and LMS.
  • Ability to educate non-technical staff on complex security and privacy risks.

Responsibilities

  • Develop privacy policies to comply with global data privacy laws.
  • Lead data mapping and PIAs to locate PII.
  • Oversee DSAR processing and right to be forgotten workflows.
  • Design and deploy company-wide security and privacy awareness training.
  • Run phishing simulations and report metrics to leadership.
  • Provide targeted training for developers and finance teams.
  • Liaise with auditors and remediate control gaps.
  • Ensure ITGC and SoD to support SOX 404.
  • Manage vendor SOC reports and privacy practices.
  • Coordinate incident response with legal and IT.

Skills

IT security
SOX compliance
Data privacy
GRC platforms
Security training
Audits
Phishing simulations
Vendor risk
Incident response

Education

Bachelor's degree in IT/CS/Cybersecurity

Tools

OneTrust
GRC platforms
LMS

Job description

TheIT Compliance & Security Manager is responsible for the integrity of the organization’s cybersecurity framework, regulatory compliance (including SOX), and data privacy programs. This role ensures that our technical systems are secure, our financial reporting controls are airtight, and our data handling practices meet global privacy standards while fostering a security-first culture through comprehensive employee training.

What you will work on
  • Privacy Governance: Develop and maintain policies to ensure compliance with global data privacy regulations (e.g., GDPR, CCPA/CPRA, HIPAA).
  • Data Mapping: Lead data discovery and classification efforts to identify where sensitive and personal identifiable information (PII) resides.
  • Privacy Impact Assessments (PIA): Conduct assessments for new projects or vendors to evaluate risks to individual privacy.
  • DSAR Management: Oversee the process for fulfilling Data Subject Access Requests and ensuring "right to be forgotten" protocols are functional.
  • Program Development: Design and deploy a mandatory company-wide security and privacy awareness curriculum.
  • Phishing Simulations: Execute regular simulated phishing campaigns to test and improve employee vigilance; report on metrics to leadership.
  • Targeted Training: Provide specialized training for high-risk groups, such as developers (secure coding) and finance teams (wire fraud/BEC prevention).
  • Culture Leadership: Act as the internal champion for security, turning compliance requirements into understandable, everyday best practices for all staff.
  • ITGC Management: Design and monitor General IT Controls (GITCs) and Segregation of Duties (SoD) to support SOX 404 requirements.
  • Audit Liaison: Lead walkthroughs and evidence collection for internal and external auditors; manage the remediation of any identified control gaps.
  • Change Control: Ensure all system changes follow a documented lifecycle of authorization, testing, and approval to maintain the integrity of financial systems.
  • Third-Party Risk: Evaluate vendor SOC reports and privacy practices during the procurement process.
  • Incident Response: Partner with legal and IT teams to manage security incidents, focusing specifically on data breach notification requirements.
WHAT YOU WILL BRING
  • Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or a related field.
  • 10+ years in IT security, audit, or compliance, with a proven track record in SOX environments and Data Privacy programs.
  • Professional certifications such as CISSP, CISM, or CISA.
  • Familiarity with GRC platforms, Privacy Management software (e.g., OneTrust), and Learning Management Systems (LMS).
  • Exceptional ability to educate non-technical employees on complex security and privacy risks.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security and Data Privacy Manager
Information Security and Data Privacy Manager

Tiger Analytics • Chennai District

Hybrid
INR 2,500,000 - 6,000,000
Director - Data Privacy & Information Security
Director - Data Privacy & Information Security

Indegene • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Comprehensive health insurance
Retirement benefits
Professional development opportunities
Governance, Risk & Compliance (GRC) Manager
Governance, Risk & Compliance (GRC) Manager

TeamsWork.In • India

On-site
INR 1,500,000 - 2,100,000
Data Protection and Cybersecurity Manager
Data Protection and Cybersecurity Manager

Stamford International School • Hyderabad

On-site
INR 1,800,000 - 3,000,000
Data Privacy Specialist
Data Privacy Specialist

Tata Communications • Mumbai

On-site
INR 1,200,000 - 1,800,000
DTDC - Practice Head - Data Security & Privacy
DTDC - Practice Head - Data Security & Privacy

DTDC Express Limited • Bengaluru

On-site
INR 3,000,000 - 4,500,000
Data Protection Consultant/Assistant Manager
Data Protection Consultant/Assistant Manager

Privacypillar • Bengaluru, Mumbai

On-site
INR 900,000 - 1,200,000
Security and Compliance
Security and Compliance

Getvisitapp • Dadri

On-site
INR 1,500,000 - 2,500,000
Governance, Risk, and Compliance Engineer
Governance, Risk, and Compliance Engineer

Herman Miller • Bengaluru

On-site
INR 1,500,000 - 2,300,000
Assistant Manager - Data Privacy projects
Assistant Manager - Data Privacy projects

Tata Communications • Mumbai

On-site
INR 1,200,000 - 1,600,000