IT Compliance and Security Manager

RGP

Pune District

On-site

INR 3,200,000 - 5,200,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

RGP is seeking an IT Compliance & Security Manager to safeguard the organization’s cybersecurity framework, regulatory compliance (SOX), and data privacy programs in a global context. You will drive privacy governance, data mapping, PIA, and DSAR efforts while building a security-first culture.

You will lead audits, training, and incident response, ensuring effective ITGCs and SoD, vendor risk management, and compliant change control. CISSP/CISM/CISA and 10+ years of experience are highly valued.

Qualifications

  • Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or related field.
  • 10+ years in IT security, audit, or compliance with proven SOX experience.
  • CISSP, CISM, or CISA certifications.
  • Familiarity with privacy management software and LMS (e.g., OneTrust, LMS).

Responsibilities

  • Develop and maintain privacy governance policies to ensure global data privacy regulatory compliance.
  • Lead data mapping and classification to locate PIIs and sensitive data.
  • Conduct Privacy Impact Assessments for new projects or vendors.
  • Oversee DSAR processing and ensure right to be forgotten protocols are functional.
  • Design and deploy a company-wide security and privacy awareness curriculum.
  • Run phishing simulations and report metrics to leadership.
  • Provide specialized training for developers and finance teams on security risks.
  • Act as security culture champion and translate compliance requirements into practical staff practices.
  • Design and monitor ITGCs and SoD to support SOX 404 requirements.
  • Lead audit walkthroughs and remediation of control gaps with auditors.
  • Manage change control lifecycle for system changes to protect financial integrity.
  • Evaluate vendor SOC reports and privacy practices during procurement.
  • Coordinate incident response with legal and IT teams for data breach notification requirements.

Skills

IT security
Audit
Compliance
SOX
Data privacy
Security training
Regulatory compliance
GRC platforms

Education

Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or related field

Tools

OneTrust
LMS

Job description

TheIT Compliance & Security Manager is responsible for the integrity of the organization’s cybersecurity framework, regulatory compliance (including SOX), and data privacy programs. This role ensures that our technical systems are secure, our financial reporting controls are airtight, and our data handling practices meet global privacy standards while fostering a security-first culture through comprehensive employee training.

What you will work on
  • Privacy Governance: Develop and maintain policies to ensure compliance with global data privacy regulations (e.g., GDPR, CCPA/CPRA, HIPAA).
  • Data Mapping: Lead data discovery and classification efforts to identify where sensitive and personal identifiable information (PII) resides.
  • Privacy Impact Assessments (PIA): Conduct assessments for new projects or vendors to evaluate risks to individual privacy.
  • DSAR Management: Oversee the process for fulfilling Data Subject Access Requests and ensuring "right to be forgotten" protocols are functional.
  • Program Development: Design and deploy a mandatory company-wide security and privacy awareness curriculum.
  • Phishing Simulations: Execute regular simulated phishing campaigns to test and improve employee vigilance; report on metrics to leadership.
  • Targeted Training: Provide specialized training for high-risk groups, such as developers (secure coding) and finance teams (wire fraud/BEC prevention).
  • Culture Leadership: Act as the internal champion for security, turning compliance requirements into understandable, everyday best practices for all staff.
  • ITGC Management: Design and monitor General IT Controls (GITCs) and Segregation of Duties (SoD) to support SOX 404 requirements.
  • Audit Liaison: Lead walkthroughs and evidence collection for internal and external auditors; manage the remediation of any identified control gaps.
  • Change Control: Ensure all system changes follow a documented lifecycle of authorization, testing, and approval to maintain the integrity of financial systems.
  • Third-Party Risk: Evaluate vendor SOC reports and privacy practices during the procurement process.
  • Incident Response: Partner with legal and IT teams to manage security incidents, focusing specifically on data breach notification requirements.
WHAT YOU WILL BRING
  • Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or a related field.
  • 10+ years in IT security, audit, or compliance, with a proven track record in SOX environments and Data Privacy programs.
  • Professional certifications such as CISSP, CISM, or CISA.
  • Familiarity with GRC platforms, Privacy Management software (e.g., OneTrust), and Learning Management Systems (LMS).
  • Exceptional ability to educate non-technical employees on complex security and privacy risks.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director - Data Privacy & Information Security
Director - Data Privacy & Information Security

Indegene • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Comprehensive health insurance
Retirement benefits
Professional development opportunities
Lead Compliance Specialist
Lead Compliance Specialist

TAC Security • Chandigarh

On-site
INR 2,600,000 - 3,200,000
Data Protection and Cybersecurity Manager
Data Protection and Cybersecurity Manager

Stamford International School • Hyderabad

On-site
INR 1,800,000 - 3,000,000
Data Protection Consultant/Assistant Manager
Data Protection Consultant/Assistant Manager

Privacypillar • Bengaluru, Mumbai

On-site
INR 900,000 - 1,200,000
Compliance Analyst
Compliance Analyst

INTECH Creative Services Pvt. Ltd. • Mumbai, Navi Mumbai

On-site
INR 900,000 - 1,500,000
Governance, Risk, and Compliance Engineer
Governance, Risk, and Compliance Engineer

Herman Miller • Bengaluru

On-site
INR 1,500,000 - 2,300,000
Manager IT Governance & Compliance
Manager IT Governance & Compliance

Sabpaisa • Delhi

On-site
INR 1,500,000 - 2,500,000
Data Consultant Risk Mandate
Data Consultant Risk Mandate

Wsne Consulting • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Information Security GRC Manager
Information Security GRC Manager

Mount Talent Consulting • Mumbai

On-site
INR 3,000,000 - 5,000,000
Senior GRC Analyst
Senior GRC Analyst

Exotel • Bengaluru

On-site
INR 1,200,000 - 1,800,000