Module Lead Information Security

IDfy

Mumbai

On-site

INR 350,000 - 550,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

IDfy in Mumbai hires a senior security leader to drive governance, risk, and privacy across ISO 27001:2022, SOC 2 Type II, and DPDPA. You will steer cloud security reviews, guide privacy-by-design, and engage with clients and auditors to ensure robust security posture.

This role blends deep regulatory knowledge with practical security engineering collaboration. You will mentor the GRC & Privacy team, translate complex regulatory requirements into actionable controls, and report risks and

Qualifications

  • 7+ years in information security with focus on governance, risk and compliance.
  • Strong knowledge of privacy by design and data protection standards.
  • Experience with cloud security across multi-cloud environments (AWS, GCP).

Responsibilities

  • Lead GRC & own the compliance roadmap for ISO standards, SOC 2, and DPDPA.
  • Build client trust by articulating controls and compliance to customers.
  • Partner with engineering on cloud/app security, VAPT, and security operations.
  • Champion privacy by design and secure-by-default practices with DevSecOps.
  • Lead and mentor the GRC & Privacy team and brief senior leadership on posture.

Skills

GRC
Privacy
Cloud security
Application security
VAPT
SIEM/SOC
Auditing

Tools

AWS
GCP

Job description

Job Description:
  • 7+ years in Information Security, with a strong focus on Governance, Risk, Compliance, Data Privacy,and Cloud Security.
  • Deep, working knowledge ofISO 27001:2022, SOC 2 Type II, ISO 42001, ISO/IEC 27701, India's DPDPA, RBI regulations (e.g.,V-CIP, outsourcing guidelines), and sector-specific requirements like SAR reporting and data localization.
  • A solid understanding of cloud security including the ability to contribute to cloud architecture reviews and offer security design recommendations across multi-cloud environments (AWS, GCP).
  • Working fluency in application security, SIEM/SOC,VAPT, security & privacy by design, leveraging AI for security - enough to be a credible partner to Engineering.
  • Strong privacy program exposure - DPIAs, consent management, data subject rights handling, breachnotification, and privacy-by-design.
  • Genuine comfort with client-facing security conversations articulating controls, handling auditor scrutiny, and building trust with BFSI, fintech, and enterprise customers.Confidence reviewing MSAs, DPAs, RFPs, TPRM, DPIA,AI questionnaires, and aligning contractual obligations with internal security practices.
  • The judgment to balance compliance rigor with business agility, and the ability to translate complex regulatory requirements into practical, actionable controls.
Here’s what your day will look like...
  • Lead GRC & own the compliance roadmap -Own our compliance roadmap across ISO 27001:2022,SOC 2 Type II, ISO 42001, ISO/IEC 27701, and DPDPA.
  • Build client trust - Represent security in customer calls, audits, assessments, and RFPs articulating our controls and compliance stance clearly to some of the most scrutinising buyers inBFSI and enterprise.
  • Partner with engineering on cloud & application security - Provide governance oversight across cloud security posture, application security (SAST/DAST/SCA),VAPT, SIEM/SOC operations, and the use of AI for security.
  • Champion cloud security, shift-left, secure-by-default, and privacy-by-design with Engineering andDevSecOps making security the path of least resistance,
  • Lead the team & the conversation -Build, mentor, and grow the GRC & Privacy team. Regularly brief senior leadership and business units on compliance posture ,top risks, and mitigation plans.
Requirements:
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Lead
GRC Lead

Baldor Technologies • Mumbai

On-site
INR 300,000 - 600,000
GRC Lead / Security Compliance Lead
GRC Lead / Security Compliance Lead

Gnani Innovations Private Limited. • India

On-site
INR 350,000 - 600,000
Lead Information Security and Data Privacy US
Lead Information Security and Data Privacy US

Tiger Analytics • Chennai District

On-site
INR 3,000,000 - 6,000,000
Information Security and Data Privacy - Lead
Information Security and Data Privacy - Lead

Tiger Analytics • Chennai District

On-site
INR 3,000,000 - 5,200,000
Security and Compliance Lead
Security and Compliance Lead

Quadrant Technologies • Hyderabad

On-site
INR 2,400,000 - 4,000,000
Security, Risk & Compliance Lead
Security, Risk & Compliance Lead

RedDoorz • Dadri

On-site
INR 2,400,000 - 4,800,000
Lead - Information Security Governance & Compliance
Lead - Information Security Governance & Compliance

Larsen & Toubro (L&T) • Mysuru, Bengaluru

On-site
INR 1,400,000 - 2,000,000
Security Compliance & GRC Lead
Security Compliance & GRC Lead

Cybrilla • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Information Security & Compliance Lead
Information Security & Compliance Lead

Infra360 Solutions Pvt. Ltd. • Haryana

On-site
INR 1,000,000 - 1,500,000
Information Security and Data Privacy Manager
Information Security and Data Privacy Manager

Tiger Analytics • Chennai District

Hybrid
INR 2,500,000 - 6,000,000