14 Aug
|
Unthinkable Solutions
|
Gurugram
14 Aug
Unthinkable Solutions
Gurugram
UNTHINKABLE SOLUTIONS LLP OPEN ROLE
Cybersecurity & Compliance Lead
ISO 27001 • Data Protection • Client Assurance • Security Governance
Full-TimeContract / Fractional5+ Years ExperienceNew Delhi / Remote
PROFILE OVERVIEW
We are a custom software development company delivering enterprise-grade web, mobile, desktop, cloud, and AI-enabled solutions to clients across multiple industries. In addition to custom software development, we maintain a portfolio of SaaS products.
We are looking for an experienced Cybersecurity & Compliance qualified who can establish, govern, and continuously improve our organisation's information security and data protection practices. The ideal candidate should possess strong expertise in ISO 27001, Data Protection Agreements (DPA), privacy regulations, client security compliance, and organisational security governance.
The role is primarily focused on governance, compliance, risk management, and client assurance rather than hands-on penetration testing or security operations.
SKILLS REQUIRED
ISO 27001 ISMS governance and implementation
Data Protection Agreement (DPA) review and negotiation
GDPR, DPDP Act (India) and privacy regulation fluency
Acting as Data Protection Officer (DPO)
Security audit and compliance assessment
Security policy and SOP drafting
Awareness training and employee education
Vendor and client compliance management Cyber insurance questionnaire support Client-facing communication and documentation
ROLES & RESPONSIBILITIES
01ISO 27001 Compliance Enforcement
Ensure all teams adhere to our ISO 27001 policies and controls.
Continuously review and improve the ISMS, identify compliance gaps, and drive corrective actions across the organisation.
02DPA Review & Client Engagement
Review all Data Protection Agreements shared by clients, flag conditions that are not applicable or need modification, and engage clients directly with suggested changes. Ensure project teams comply with all agreed contractual security obligations throughout delivery.
03Data Protection Officer (DPO)
Serve as the single point of contact for all privacy and security communications from clients. Handle inquiries, security questionnaires, audit requests, and coordinate response in the event of any incident or breach.
04Project Security Audits
Conduct regular audits across active projects to verify adherence to security and data protection policies. Identify missing controls and ensure new additions are incorporated on an ongoing basis.
05Security Awareness & Training
Plan and run regular cybersecurity awareness workshops for all employees covering secure development practices, phishing, data handling, password hygiene, and policy updates. Maintain attendance records and training evidence for client audit purposes.
06Ongoing Cybersecurity Advisory
Continuously assess our security posture and recommend improvements to policies, tools, and operational practices. Work with leadership to raise security maturity over time.
07Cyber Insurance Support
Assist during procurement and renewal of cybersecurity insurance. Respond to insurer questionnaires and coordinate the collection of compliance evidence required by insurers.
DESIRED EXPERIENCE
5+ years in Information Security, Compliance, Risk Management, or Privacy Governance
Prior experience with software development companies or SaaS organisations
Familiarity with SDLC, cloud environments (AWS / Azure / GCP), and modern dev practices
Certifications preferred: ISO 27001 Lead Implementer / Auditor, CISM, CISA, CISSP, CDPSE, CIPM, or equivalent
ENGAGEMENT MODELS
We are open to multiple engagement structures. Whether you are looking for a full-time role or a flexible contractual arrangement, we are happy to discuss what works for your situation as long as you are reachable during our standard business hours for meetings, client communications, and any time-sensitive compliance matters.
Full-Time
Standard employment Full availability
Part-Time / Hourly
~3 hrs/day or fixed hours per week
Monthly Retainer
Fixed hours per month advisory basis
Compensation is structured on an hourly, monthly retainer, or annual CTC basis depending on the model agreed. Business-hours availability is mandatory across all engagement types.
📌 Data Security Consultant (Gurugram)
🏢 Unthinkable Solutions
📍 Gurugram