Module Lead Information Security

IDfy

Mumbai

On-site

INR 4,000,000 - 7,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

IDfy is seeking a seasoned Information Security leader to own GRC, privacy, and cloud security initiatives. The role interfaces with engineering, audits, and customers, translating regulatory requirements into practical controls.

You will drive ISO27001:2022, SOC 2 Type II, DPDPA compliance, and RBI guidelines, while guiding a growing GRC and Privacy team in a fast-paced BFSI/enterprise environment.

Qualifications

  • 7+ years of information security with emphasis on GRC, privacy and cloud security.
  • In-depth knowledge of ISO 27001:2022, SOC 2 Type II, ISO 42001, ISO/IEC 27701, and DPDPA.
  • Experience with RBI guidelines, data localization, SAR reporting and outsourcing rules.
  • Ability to translate regulatory requirements into practical security controls.
  • Credible in client-facing security conversations with auditors and buyers.

Responsibilities

  • Lead GRC and own the compliance roadmap across ISO 27001:2022, SOC 2 II, ISO 42001, ISO/IEC 27701, and DPDPA.
  • Build client trust by representing security in customer calls, audits, assessments, and RFPs.
  • Partner with engineering on cloud & application security posture (multi-cloud).
  • Champion cloud security, secure-by-default and privacy-by-design with DevSecOps.
  • Lead and mentor the GRC & Privacy team; brief senior leadership on risks and mitigations.

Skills

GRC
Risk Management
Compliance
Data Privacy
Cloud Security
ISO 27001:2022
SOC 2 Type II
DPDPA
RBI Regulations
Audits & Assessments
Client-facing Security
Privacy by Design

Tools

SIEM
SAST
DAST
SCA

Job description

  • 7+ years in Information Security, with a strong focus on Governance, Risk, Compliance, Data Privacy,and Cloud Security.
  • Deep, working knowledge ofISO 27001:2022, SOC 2 Type II, ISO 42001, ISO/IEC 27701, India's DPDPA, RBI regulations (e.g.,V-CIP, outsourcing guidelines), and sector-specific requirements like SAR reporting and data localization.
  • A solid understanding of cloud security including the ability to contribute to cloud architecture reviews and offer security design recommendations across multi-cloud environments (AWS, GCP).
  • Working fluency in application security, SIEM/SOC,VAPT, security & privacy by design, leveraging AI for security - enough to be a credible partner to Engineering.
  • Strong privacy program exposure - DPIAs, consent management, data subject rights handling, breachnotification, and privacy-by-design.
  • Genuine comfort with client-facing security conversations articulating controls, handling auditor scrutiny, and building trust with BFSI, fintech, and enterprise customers.Confidence reviewing MSAs, DPAs, RFPs, TPRM, DPIA,AI questionnaires, and aligning contractual obligations with internal security practices.
  • The judgment to balance compliance rigor with business agility, and the ability to translate complex regulatory requirements into practical, actionable controls.
  • 7+ years in Information Security, with a strong focus on Governance, Risk, Compliance, Data Privacy,and Cloud Security.
  • Deep, working knowledge ofISO 27001:2022, SOC 2 Type II, ISO 42001, ISO/IEC 27701, India's DPDPA, RBI regulations (e.g.,V-CIP, outsourcing guidelines), and sector-specific requirements like SAR reporting and data localization.
  • A solid understanding of cloud security including the ability to contribute to cloud architecture reviews and offer security design recommendations across multi-cloud environments (AWS, GCP).
  • Working fluency in application security, SIEM/SOC,VAPT, security & privacy by design, leveraging AI for security - enough to be a credible partner to Engineering.
  • Strong privacy program exposure - DPIAs, consent management, data subject rights handling, breachnotification, and privacy-by-design.
  • Genuine comfort with client-facing security conversations articulating controls, handling auditor scrutiny, and building trust with BFSI, fintech, and enterprise customers.Confidence reviewing MSAs, DPAs, RFPs, TPRM, DPIA,AI questionnaires, and aligning contractual obligations with internal security practices.
  • The judgment to balance compliance rigor with business agility, and the ability to translate complex regulatory requirements into practical, actionable controls.
Here’s what your day will look like...
  • Lead GRC & own the compliance roadmap -Own our compliance roadmap across ISO 27001:2022,SOC 2 Type II, ISO 42001, ISO/IEC 27701, and DPDPA.
  • Build client trust - Represent security in customer calls, audits, assessments, and RFPs articulating our controls and compliance stance clearly to some of the most scrutinising buyers inBFSI and enterprise.
  • Partner with engineering on cloud & application security - Provide governance oversight across cloud security posture, application security (SAST/DAST/SCA),VAPT, SIEM/SOC operations, and the use of AI for security.
  • Champion cloud security, shift-left, secure-by-default, and privacy-by-design with Engineering andDevSecOps making security the path of least resistance,
  • Lead the team & the conversation -Build, mentor, and grow the GRC & Privacy team. Regularly brief senior leadership and business units on compliance posture ,top risks, and mitigation plans.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Lead / Security Compliance Lead
GRC Lead / Security Compliance Lead

Gnani Innovations Private Limited. • India

On-site
INR 350,000 - 600,000
Information Security and Data Privacy Manager
Information Security and Data Privacy Manager

Tiger Analytics • Chennai District

Hybrid
INR 2,500,000 - 6,000,000
Security Compliance & GRC Lead
Security Compliance & GRC Lead

Cybrilla • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Information Security & Compliance Lead
Information Security & Compliance Lead

Infra360 Solutions Pvt. Ltd. • Haryana

On-site
INR 1,000,000 - 1,500,000
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

844 Altera Semiconductor Technology India Pvt. Ltd. • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

Altera • Bengaluru

On-site
INR 3,000,000 - 4,500,000
Cybersecurity Lead - Governance, Risk & Compliance
Cybersecurity Lead - Governance, Risk & Compliance

Scybers Inc • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Opportunities for professional development
Flexible work arrangements
Supportive team culture
Information Security Manager
Information Security Manager

SaaS Labs • Bengaluru

On-site
INR 450,000 - 800,000
Cybersecurity Lead - Governance, Risk & Compliance
Cybersecurity Lead - Governance, Risk & Compliance

Scybers • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Career Growth opportunities
Innovative Environment
Flexible work arrangements
Director - Data Privacy & Information Security
Director - Data Privacy & Information Security

Indegene • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Comprehensive health insurance
Retirement benefits
Professional development opportunities