Data Officer and Compliance Lead Information Security

IDfy · Mumbai Metropolitan Region

  • Experience10–11 yrs
  • SalaryNot disclosed
  • Work modeonsite
  • Levelexecutive
  • Posted17 Sept 2026

About IDfy

IDfy is hiring in Mumbai Metropolitan Region in technology software. This role looks for around 10+ years of experience.

Skills

  • Governance, Risk, and Compliance
  • Data Privacy
  • Cloud Security
  • ISO 27001:2022
  • SOC 2 Type II
  • ISO 42001
  • ISO/IEC 27701
  • Digital Personal Data Protection Act
  • RBI regulations
  • V-CIP
  • SAR reporting
  • data localization
  • AWS
  • Google Cloud Platform
  • Application Security
  • SIEM
  • Security Operations Center
  • Vulnerability Assessment and Penetration Testing
  • Security by Design
  • Privacy by Design
  • Data Protection Impact Assessments
  • Consent Management
  • Data Subject Rights
  • Breach Notification
  • Master Service Agreements
  • Data Processing Agreements
  • Requests for Proposal
  • Third-Party Risk Management
  • Artificial Intelligence Security Questionnaires

The role

A governance, risk and compliance professional at a technology product company leads information security and privacy programs, applying ISO 27001:2022, SOC 2 Type II and DPDPA across cloud environments and enterprise customers. The role reviews security architecture, manages privacy assessments and regulatory controls, and partners with engineering on practical security design.

Full job description

10+ years in Information Security, with a strong focus on Governance, Risk, Compliance, Data Privacy,

and Cloud Security.

Deep, working knowledge ofISO 27001:2022, SOC 2 Type II, ISO 42001, ISO/IEC 27701, India's DPDPA,

RBIregulations (e.g.,V-CIP, outsourcing guidelines), and sector-specific requirements like SAR reporting

and data localization.

Asolid understanding of cloud security including the ability to contribute to cloud architecture reviews

and offer security design recommendations across multi-cloud environments (AWS, GCP).

Working fluency in application security, SIEM/SOC,VAPT, security & privacy by design, leveragingAIfor

security - enough to be a credible partnerto Engineering.

Strong privacy program exposure - DPIAs, consent management, data subjectrights handling, breach

notification, and privacy-by-design.

Genuine comfort with client-facing security conversations articulating controls, handling auditor scrutiny,

and building trust withBFSI,fintech, and enterprise customers.

Confidence reviewing MSAs, DPAs, RFPs, TPRM, DPIA,AI questionnaires, and aligning contractual

obligations with internal security practices.

The judgmentto balance compliance rigor with business agility, and the ability to translate complex

regulatory requirements into practical, actionable controls.

Acollaborative, cross-functional style, and experience building and mentoring a team.