Job Description

  • 7+ years in Information Security, with a strong focus on Governance, Risk, Compliance, Data Privacy,and Cloud Security.
  • Deep, working knowledge ofISO 27001:2022, SOC 2 Type II, ISO 42001, ISO/IEC 27701, India's DPDPA, RBI regulations (e.g.,V-CIP, outsourcing guidelines), and sector-specific requirements like SAR reporting and data localization.
  • A solid understanding of cloud security including the ability to contribute to cloud architecture reviews and offer security design recommendations across multi-cloud environments (AWS, GCP).
  • Working fluency in application security, SIEM/SOC,VAPT, security & privacy by design, leveraging AI for security - enough to be a credible partner to Engineering.
  • Strong privacy program exposure - DPIAs, consent management, data subject rights handling, breachnotification, and privacy-by-design.
  • Genuine comfort with client-facing security conversations articulating controls, handling auditor scrutiny, and building trust with BFSI, fintech, and enterprise customers.Confidence reviewing MSAs, DPAs, RFPs, TPRM, DPIA,AI questionnaires, and aligning contractual obligations with internal security practices.
  • The judgment to balance compliance rigor with business agility, and the ability to translate complex regulatory requirements into practical, actionable controls.

Here’s what your day will look like...

  • Lead GRC & own the compliance roadmap -Own our compliance roadmap across ISO 27001:2022,SOC 2 Type II, ISO 42001, ISO/IEC 27701, and DPDPA.
  • Build client trust - Represent security in customer calls, audits, assessments, and RFPs articulating our controls and compliance stance clearly to some of the most scrutinising buyers inBFSI and enterprise.
  • Partner with engineering on cloud & application security - Provide governance oversight across cloud security posture, application security (SAST/DAST/SCA),VAPT, SIEM/SOC operations, and the use of AI for security.
  • Champion cloud security, shift-left, secure-by-default, and privacy-by-design with Engineering andDevSecOps making security the path of least resistance,
  • Lead the team & the conversation -Build, mentor, and grow the GRC & Privacy team. Regularly brief senior leadership and business units on compliance posture ,top risks, and mitigation plans.


Job Details

Role Level: Mid-Level Work Type: Full-Time
Country: India City: Mumbai
Company Website: http://www.idfy.com Job Function: Cybersecurity
Company Industry/
Sector:
IT Services And IT Consulting Software Development And Technology Information And Internet

What We Offer


About the Company

Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.

Report

Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@talentmate.com.


ad 1
Talentmate Instagram Talentmate Facebook Talentmate YouTube Talentmate LinkedIn