AVP - DATA PRIVACY AND BUSINESS INFORMATION SECURITY - LEADING MNC - CISSP, CISA, CRISC, CISM
CairnMartin
Posted: March 5, 2025
Interested in this position?
Create a free account to apply with AI-powered matching
Quick Summary
Understand the key assets and processes, identify and evaluate risks and controls, and suggest incremental controls or risk mitigation strategies for complex privacy and/or security matters in compliance with ISO 27001, GDPR, and other global privacy laws and regulations, with additional consideration for sector-specific experience in financial services, insurance, education, telecom, biometrics, or other industries.
Required Skills
Job Description
• A leading financial company
AVP - DATA PRIVACY AND BUSINESS INFORMATION SECURITY - LEADING MNC - 8-12 YRS - MUMBAI
B.E./ B.Tech./ MCA in IT or CS.
 
ROLE:
• Understand the key assets and processes, identify and evaluate risks and controls, and suggest incremental controls or risk mitigation strategies
• Responsible for complex privacy and/or security matters and privacy programs in compliance ISO 27001, #GDPR and other global privacy laws and regulations (with additional consideration for sector-specific experience in financial services, insurance, education, telecom, biometrics, or digital advertising
• Drive data breach preparation, risk mitigation, coordination and responses
• Drive Technology transactions related to privacy and security-related due diligence and advising.
• Ensure business compliance with Information Security Policies and Standards while continuously monitoring and reporting on risks and documented exceptions
• Develop and maintain in depth understanding of region/business unit processes, systems, technologies, data, customers, consumers, partners
• Review and audit the Information Security Policies and Standards and technical implementations of security solutions required to meet business objectives
• Identify noncompliance and areas of potential improvement, and issue corrective actions
• Provide escalation path for security issues, incidents and inquiries
• Review work of the Security Incident Response and Crisis Management teams to ensure effectively driving incidents to acceptable resolution; assist with investigations as needed
• Work with the Compliance and Information Risk Management team to drive policy and regulatory compliance.
EXPERIENCE:
• Certification pertaining to information security and data privacy protection (#CISSP, #CISA, #CRISC, #CISM, etc.)
• Experience in the design and implementation of information security programs
• Experience in compliance, government or financial industry.
• Expert level understanding of key network and technical security controls
• Security best practices including experience with #ISO27001 and PCI DSS
Certifications: CISA/ CISSP/ COBIT/ ITILv3/ CISM/ CRISC/ ISO27001