Live opening · Posted 6 hours ago

IT Security Lead

Dalberg · Bangalore | Mumbai | Work From Home
Instahyre 4-8 yrs
You are 6 hours behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 6 hours ago
CompanyDalberg
LocationBangalore | Mumbai | Work From Home
Experience4-8 yrs
SkillsCybersecurity, GDPR, GRC, Governance Risk Compliance, ISMS, ISO27001, IT Security
SourceInstahyre
Listed6 hours ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
0 min from Instahyre publishing this role to us finding it
3 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
73,543 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

Work to ensure Dalberg's overall compliance with global and regional information security and data privacy regulations, including, but not limited to, GDPR, NIST Cybersecurity Framework, and India's Digital Personal Data Protection (DPDP) Act. Act as the Data Protection Officer (DPO) and Consent Manager, driving the implementation of robust security and privacy practices across global operations to safeguard personal and sensitive data and maintain regulatory adherence.
The candidate will have responsibilities across the following functions:
Security framework and policy management:
Develop and manage an Internal Controls framework for IT Governance.
Create operational processes, procedures, standards, and guidelines.
Maintain the firm's ISMS policy/procedure documents.
Ensure an up-to-date repository of documents on SharePoint.
Audit facilitation and compliance enforcement:
Engage with auditors, compliance teams, and regional office representatives.
Coordinate with internal and external stakeholders to close audit findings promptly.
Overseeing an organisation's compliance with data protection lawsespecially the EU's General Data Protection Regulation (GDPR)
Assist in enforcing security policies and procedures across the organisation.
Work with IT and operational teams to ensure compliance.
Support and implement IT GRC initiatives:
Support and implement global IT GRC initiatives.
Collaborate with program leadership to align with common objectives.
Develop and enhance the organisation's information security, governance, risk, and compliance strategy.
Understand structured and unstructured data types.
Cloud Security and Vulnerability Assessment:
Assess cloud environment security and conduct vulnerability assessments/penetration testing (VA/PT) to identify and mitigate risks.
Infosec awareness program: Develop and drive information security awareness through training, awareness mailers, and other channels and deliver a training program for employees to build privacy awareness.
Security process automation: Assist in automating security processes where possible.
Business impact assessment (BIA):
Conduct annual BIA exercises to ensure business continuity.
Identify critical SaaS based business applications and their Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).
Conduct Data Protection Impact Assessments (DPIAs): advising on necessity, scope, and mitigation strategies.
Industry best practices and legal monitoring:
Stay current with the industry's best practices.
Monitor legal and regulatory developments.
Stakeholder engagement:
Build and maintain strong relationships with key stakeholders to ensure alignment of risk management objectives and regulatory requirements.
Communicate complex compliance and risk issues in a clear, actionable manner, enabling stakeholders to make informed decisions and support organisational governance goals.
Requirements:
A bachelor's degree in IT, cyber security, or a related field is required (CISA, CISSP, CISM, or other ISMS/information security certifications are preferred).
4+ years of proven experience in cybersecurity, GRC, information security, or ISMS implementation/sustenance roles.
In-depth knowledge of ISO27001 standards, DPDP Act, GDPR and NIST frameworks and control requirements.
Experience in InfoSec compliance reviews and gap assessments.
Prior experience with internal/external audits related to ISMS or IT General Controls (ITGC).
Knowledge of security-related technologies such as IDAM, PAM, Patch Management tools, Encryption, DLP, Antivirus, and Firewalls.
Strong understanding of IT infrastructure, including Cloud and M365 environments.
Understanding of Data Privacy/GDPR concepts and controls.
Strong written and verbal communication skills, including proficiency with PPT.
Ability to explain technical concepts to non-technical individuals at any level.
Excellent interpersonal and relationship-building skills.

Skills
Cybersecurity, GDPR, GRC, Governance Risk Compliance, ISMS, ISO27001, IT Security, Information Security, Infosec, NIST

Experience
4-8 yrs

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App