Description
The Associate Director will lead the design, implementation, governance, and continuous improvement of Information Security and Data Privacy programs across the organization. The role is responsible for ensuring compliance with global security standards, regulatory requirements, and client contractual obligations while enabling business growth through secure and resilient technology practices.
The individual will partner with senior leadership, technology teams, business stakeholders, legal, risk, and global member firms to strengthen the firm's security posture, manage cyber risks, and drive strategic security initiatives.
Responsibilities
Information Security Governance----
Lead the implementation and continuous enhancement of the Information Security Management System (ISMS).
Develop, review, and maintain enterprise information security policies, standards, procedures, and guidelines.
Drive security governance aligned with ISO 27001, NIST CSF, CIS Controls, and industry best practices.
Present security metrics, risk posture, and strategic updates to executive leadership.
Data Privacy & Regulatory Compliance---
Ensure compliance with applicable privacy regulations including GDPR, DPDP Act (India), UK GDPR, and other global privacy requirements.
Collaborate with Legal, Compliance, and business teams on privacy impact assessments and data protection initiatives.
Oversee data classification, retention, secure disposal, and data handling practices.
Support client due diligence, privacy assessments, and regulatory audits.
Security Risk Management--
Lead enterprise risk assessments and third-party security reviews.
Manage remediation of security findings and monitor risk treatment plans.
Provide strategic guidance on emerging cyber threats and security controls.
Evaluate security implications of current technologies and business initiatives.
Security Operations & Incident Management---
Provide executive oversight of security incidents, investigations, and root cause analysis.
Coordinate incident response activities with internal and external stakeholders.
Ensure lessons learned are incorporated into security controls and processes.
Monitor key security performance indicators and drive continual improvement.
Security Architecture & Technology--
Review and approve security architecture for cloud, applications, infrastructure, and digital transformation initiatives.
Promote Secure-by-Design and Privacy-by-Design principles across projects.
Provide strategic oversight on identity and access management, endpoint security, network security, encryption, DLP, and cloud security.
Audit & Assurance...
Lead internal and external security audits.
Coordinate responses to client security questionnaires and assurance requests.
Track audit observations and ensure timely remediation.
Support certifications and compliance initiatives.
Qualifications
Bachelor's degree in Computer Science, Information Technology, Cyber Security, or a related discipline.
Master's degree or MBA preferred.
12–15+ years of experience in Information Security, Cyber Security, Risk Management, or Data Privacy.
At least 5 years of leadership or people management experience.
Preferred Certifications
CISSP
CISM
ISO/IEC 27001 Lead Implementer or Lead Auditor
CCSP or equivalent cloud security certification
Privacy certifications such as CIPP/E or CIPP/A are desirable.
Information Security Governance
Cyber Risk Management
Data Privacy & Regulatory Compliance
Security Operations & Incident Response
Business Continuity & Disaster Recovery
Data Loss Prevention (DLP)
Strong communication and presentation skills
📌 Senior Manager (Gurugram)
🏢 BSR
📍 Gurugram