Lead-Information Security & Data Protection

Riskcovry

Bengaluru

On-site

INR 4,000,000 - 7,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Riskcovry is seeking a Lead-Information Security & Data Protection to own the security program across product and data platforms in fintech/insurtech contexts. You will drive privacy by design, policy development, incident response, and regulatory alignment for India's DPDP Act 2023.

You will collaborate with engineering, legal, and compliance teams, implement ISO 27001 controls, manage data subject requests, conduct risk assessments, and lead data breach response in a fast-paced, AI-first

Qualifications

  • 3+ years of experience in information security, data privacy, or a combined role.
  • Knowledge of India's DPDP Act 2023 and hands-on experience implementing data protection programmes.
  • Strong working knowledge of ISO 27001.
  • Proven experience managing security incidents, data breaches, and regulatory notifications.
  • Excellent communication skills — able to translate complex security and legal concepts for non-technical stakeholders.

Responsibilities

  • Act as the designated DPO under India's DPDP Act 2023 and other applicable privacy laws.
  • Maintain a data processing inventory with a documented lawful basis for all activities under the DPDPA Act 2023.
  • Support the development and maintenance of privacy policies, data retention schedules, and consent management frameworks.
  • Monitor the Privacy by Design and Privacy by Default into the SDLC and data engineering practices.
  • Review DPAs, data sharing agreements, and privacy clauses in vendor contracts.
  • Data Subject Rights & Incident Management
  • Lead the data breach response: detection, containment, regulatory notification, and post-incident review.
  • Cyber Security Strategy & Governance
  • Establish cybersecurity policies, standards, and guidelines based on industry best practices and regulatory frameworks (ISO 27001).
  • Collaborate with HR and the compliance team to build a cybersecurity-aware culture through regular training and education programmes.
  • Lead risk assessments to identify potential security threats and vulnerabilities, and propose effective mitigation measures.
  • Develop and maintain an incident response programme, managing cybersecurity incidents and data breaches from detection to remediation.

Skills

Information security
Data privacy
Regulatory compliance
Incident response
ISO 27001 knowledge
Security governance
Communication skills

Education

B.Tech/M.Tech in CS/IT

Job description

Lead-Information Security & Data Protection

Insurance is one of the largest financial products in the world, yet it remains one of the hardest to distribute digitally. We’re changing that!

Riskcovry is an AI-first insurtech infrastructure platform that enables banks, lenders, fintechs, telecom companies, and digital platforms to embed insurance directly into their products and customer journeys.

Our API-first platform powers the full lifecycle of digital insurance distribution — from product configuration and policy issuance to commissions, claims, and reporting. This allows enterprises to launch and scale insurance programs quickly without building complex insurance infrastructure or managing multiple insurer integrations.

Today, businesses use Riskcovry to embed protection products like credit life, motor, device protection, and microinsurance into lending, payments, mobility, and digital ecosystems.

We’re building the infrastructure layer that makes insurance programmable, globally, much like how payment infrastructure transformed digital commerce.

Riskcovry is a venture-funded company backed by leading fintech investors and recognized by the industry for innovation, including awards such as “Insurtech of the Year” and “Best AI Innovation for Insurance Distribution.” Our platform powers digital insurance distribution across India, the Middle East, the UK, and expanding global markets.

Behind the platform is a team of builders, operators, and problem-solvers working at the intersection of insurance, technology, and financial services. We move fast, think boldly, and are driven by the opportunity to solve complex real-world problems at scale.

Act as the designated DPO under India's DPDP Act 2023 and other applicable privacy laws.

Maintain a data processing inventory with a documented lawful basis for all activities under the DPDPA Act 2023.

Support the development and maintenance of privacy policies, data retention schedules, and consent management frameworks.

Monitor the Privacy by Design and Privacy by Default into the SDLC and data engineering practices.

Review DPAs, data sharing agreements, and privacy clauses in vendor contracts.

Data Subject Rights & Incident Management

Manage data subject requests — access, correction, erasure, portability, and grievance redressal — within regulatory timelines.

Lead the data breach response: detection, containment, regulatory notification, and post-incident review.

Cyber Security Strategy & Governance

Establish cybersecurity policies, standards, and guidelines based on industry best practices and regulatory frameworks (ISO 27001).

Collaborate with HR and the compliance team to build a cybersecurity-aware culture through regular training and education programmes.

Lead risk assessments to identify potential security threats and vulnerabilities, and propose effective mitigation measures.

Develop and maintain an incident response programme, managing cybersecurity incidents and data breaches from detection to remediation.

Requirements

3+ years of experience in information security, data privacy, or a combined role, preferably in fintech, insurtech, BFSI, or a regulated industry.

Knowledge of India's DPDP Act 2023 and hands-on experience implementing data protection programmes.

Strong working knowledge of ISO 27001.

Proven experience managing security incidents, data breaches, and regulatory notifications.

Excellent communication skills — able to translate complex security and legal concepts for non-technical stakeholders.

Technical degree (B.Tech/M.Tech in CS/IT or MBA in Information Security, or related field).

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Data Security Manager (SaaS background) - Reports to CTO - General Insurance
Data Security Manager (SaaS background) - Reports to CTO - General Insurance

datavruti • Chennai

On-site
INR 1,800,000 - 2,500,000
Cyber - DPT | Assistant Manager | Data Privacy
Cyber - DPT | Assistant Manager | Data Privacy

Embark • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Privacy Lead
Privacy Lead

Paytm • Dadri

On-site
INR 4,000,000 - 8,000,000
Stashfin - Manager/Senior Manager - Operational Risk & Data Privacy
Stashfin - Manager/Senior Manager - Operational Risk & Data Privacy

Stashfin • Gurugram District

On-site
INR 1,500,000 - 2,600,000
Software Engineer
Software Engineer

Riskcovry • Bengaluru

On-site
INR 800,000 - 1,200,000
Manager
Manager

HDB Financial Services Ltd. • Mumbai

On-site
INR 1,200,000 - 1,800,000
Associate Data Privacy and Protection
Associate Data Privacy and Protection

MethodHub Consulting Inc • Mumbai

On-site
INR 900,000 - 1,500,000
Privacy Consultant
Privacy Consultant

IQWorks Technologies Private Limited • Bengaluru

On-site
INR 900,000 - 1,300,000
Privacy Consultant
Privacy Consultant

IQWorks Technologies Private Limited • Mumbai

Hybrid
INR 1,200,000 - 2,100,000
System Engineer
System Engineer

Riskcovry • Bengaluru

On-site
INR 600,000 - 900,000