IT Compliance Manager - Cyber Security & Privacy

Etaash Consultants

India

On-site

INR 2,200,000 - 4,200,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Etaash Consultants seeks a Compliance Manager - Cyber Security & Privacy to lead privacy governance and ensure regulatory compliance across data handling in the Indian market.

You will architect privacy programs, perform DPIAs, coordinate with regulators and align with global standards such as ISO 27701. Strong communication and independent advisory skills are essential in a fast-paced environment.

Qualifications

  • Minimum 7–10 years in data privacy, compliance or information security.
  • Deep knowledge of IT security frameworks (ISO 27001/NIST).
  • Strong understanding of the DPDP Act 2023 and Rules 2025.
  • Experience with GDPR or other privacy laws preferred.
  • Excellent communication with stakeholders and board-level exposure.

Responsibilities

  • Lead privacy governance and privacy CoE.
  • Oversee lawful processing of personal data and DPDP compliance.
  • Conduct DPIAs and internal privacy audits.
  • Develop and update privacy policies including Privacy by Design.
  • Coordinate with regulators and align with ISO 27701 standards.
  • Act as privacy advisor to management and cross-functional teams.
  • Lead breach response and regulatory notifications within timelines.

Skills

Data privacy
Legal compliance
Information security
IT infrastructure
DPDP Act 2023
GDPR exposure
Stakeholder communication
Problem solving
Prioritization
Adaptability

Education

Cyber Law / Privacy education

Job description

Job Title : Compliance Manager - Cyber Security & Privacy
Reporting Structure

Reports to AVP - Cyber Security - CSEAP

Education

University graduate or post graduate degree with specialisation in the field of Cyber Law, Privacy, Computer Science/IT or Engineering Graduate/PG in CS/IT.

Experience/Qualifications
  • A Minimum 7 - 10 years in data privacy, legal compliance, or information security, ideally within the BFSI or IT/ITES sectors.
  • Deep understanding of IT infrastructure, Cyber Security Standards/Frameworks (ISO 27001/NIST), Application Security (OWASP, SANS, and MITRE) and data security controls (Access Control, Data Classification, DLP, Data Discovery, Masking & Encryption etc.).
  • Strong working knowledge of the DPDP Act 2023 and Rules 2025, with the ability to translate requirements into actionable workflows.
  • Exposure of GDPR or other privacy compliance laws preferred.
  • Ability to act independently and provide unbiased advice to management and the Board.
  • Excellent verbal and written communication skills is mandatory with management or stakeholder interaction exposure to bridge technical, legal, and regulatory requirements.
  • Strong problem-solving abilities and should prioritize tasks effectively
  • Comfortable working in a fast-paced environment and able to adapt to changing priorities
Role & Responsibilities
  • Serve as the primary architect of the company's privacy governance framework and lead privacy CoE.
  • Oversee the secure and lawful processing of personal data, ensuring absolute compliance with India's DPDP Act and preparing the organization for other global privacy laws such as the EU GDPR.
  • Conduct regular internal audits and Data Protection Impact Assessments (DPIAs) for high-risk processing activities.
  • Develop, maintain, and update privacy & data protection policies, including Privacy by Design and default principles.
  • Evaluate Privacy Enhancing Technologies and co-ordinate for selection and implementation of it.
  • Drive Privacy related standards and best practices adoption such as ISO 27701.
  • Align with sectoral regulators (e.g., RBI) on Cyber Security and data handling regimes.
  • Act as the Point of Contact for the Data Protection Board of India and global supervisory authorities.
  • Serve as the nodal officer for Grievance Redressal, managing requests from data principals regarding access, correction, or erasure.
  • Collaborate with Business Teams, IT and Cyber Security teams to implement procedural and technical safeguards like encryption, anonymization, and access controls.
  • Support to do vendor due diligence from Privacy Compliance perspective.
  • Lead privacy breach incident investigation and response to personal data breaches, ensuring mandatory notifications to regulators and affected individuals within statutory timelines (e.g., 72 hours).
  • Advises management of critical issues that may affect the overall compliance and risk posture of organization.
  • Demonstrate skills by upgrading self-knowledge quickly and transferring it to peers.
  • Stay up to date on emerging compliance requirements, and trends in technology security and apply that knowledge.
  • Provide training and guidance to staff on privacy compliance & security best practices and procedures. .
Get your free, confidential resume review.
or drag and drop your file here.