Assistant Vice President, Lead Data Protection & Chief of Staff (Mumbai)

Assistant Vice President, Lead Data Protection & Chief of Staff (Mumbai)

16 Aug
|
SMFG INDIA CREDIT
|
Mumbai

16 Aug

SMFG INDIA CREDIT

Mumbai

Role & responsibilities

1. Data Protection Leadership (Information Security Lens)

a. Define and execute the enterprise Data Protection strategy and multi-year roadmap, aligned with organizational risk posture b. Translate regulatory and privacy requirements (e.g., DPDP and other applicable sectoral guidelines) into technical and operational security controls c. Drive data protection implementation of controls including (but not limited to): Data classification & discovery, Encryption & key management, Data Loss Prevention (DLP), Access governance & identity controls, Data masking, tokenization, and secure data lifecycle controls d. Ensure enterprise-wide adoption of data protection controls and principles across business and technology initiatives e. Establish data risk visibility frameworks and reporting mechanisms for leadership f. Act as the InfoSec SME for data protection and privacy enablement g. Act as the translation layer between Privacy/Regulatory requirements and Information Security control implementation.
1. CISO Office Strategy

a. Drive structured governance of Information Security initiatives through Centralized tracking of Office of CISO, Standardized reporting cadences and Outcome-based monitoring of programs b. Enable execution of the Information Security strategy and roadmap c. Improve program governance, accountability, and execution visibility across Cyber Hygiene, Cyber Defense, GRC, and Info Protection teams d. Develop and institutionalize governance frameworks, Policies, SOPs, and operating models for the CISO Office.
1. Executive Enablement & Leadership Support

a. Lead development of Leadership dashboards, Board and committee presentations, Security posture and risk insights b. Operationalise CISOs initiative in driving enterprise-wide security strategy discussions and prioritization.
1. Program & Portfolio Management





a. Oversee end-to-end lifecycle of strategic InfoSec initiatives, including Planning and prioritization, and Risk identification and escalation b. Drive cross-functional programs such as: DPDP readiness initiatives, Security strategy development and Compliance frameworks and assessments c. Ensure on-time and outcome-driven execution of key programs across Information Security domains.
1. Regulatory, Risk & Compliance Alignment

a. Drive alignment of Information Security practices with regulatory requirements (DPDP, IRDAI, RBI, etc.) b. Provide SME inputs for audits, regulatory inspections, and certifications, ensuring strong compliance posture c. Contribute to cyber maturity assessments and risk evaluations.
1. Cross-Functional Collaboration & Influence

a. Act as a bridge between CISO Office, business units, technology teams, and control functions b. Drive alignment across: Cyber Defense, Governance & Compliance, Cyber Hygiene, Information Protection and other domains c. Enable integration of data protection principles into enterprise decision-making d. Build strong stakeholder relationships to drive adoption of security and data protection practices.
1. Talent & Capability Development

a. Support development of data protection and cybersecurity capabilities across the organization b. Mentor team members and drive capability uplift in privacy, security, and governance domains c. Contribute to skill-building initiatives,



certifications, and knowledge sharing d. Support organizational capability planning and workforce readiness

Expected Core Competencies

- Data Protection and Privacy,
- Information Security Governance & Strategy,
- Regulatory & Compliance Frameworks (DPDP, ISO 27001, ISO 27701 etc.),
- Program & Portfolio Management,
- Executive Communication & Stakeholder Management,
- Risk Management & Decision Support

Preferred candidate profile

- Minimum ME/ MTech/ MBA in relevant domains (computer science, information /cyber security) from reputed universities. Research and Academic Knowledge in Cyber security is plus.
- Strong, in-depth understanding of enterprise Information Security and Data Protection domains, covering strategy, architecture, and program execution
- Ability to design and govern end-to-end data protection programs across the data lifecycle (discovery, classification, protection, monitoring)
- Broad technical knowledge across cybersecurity domains (security architecture, cyber defense, cloud security, IAM, Vulnerability Management, GRC), to enable effective CISO office oversight
- Ability to translate regulatory and data protection requirements into scalable technical security controls
- Strong understanding of security frameworks, risk management, and enterprise security governance, with a technology-agnostic approach.
- Minimum of 12+ years of experience in data protection, information security, strategic and leadership roles.
- Robust experience in enterprise security governance, regulatory compliance, and program management
- Proven track record of working in cross-functional and leadership-facing roles.

Note: This position requires working from the office in Mumbai.

Only Mumbai-based candidates are eligible to apply.

📌 Assistant Vice President, Lead Data Protection & Chief of Staff (Mumbai)
🏢 SMFG INDIA CREDIT
📍 Mumbai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: assistant vice president, lead data protection & chief of staff (mumbai) / mumbai

Subscribe to this job alert:

Get the latest job offers by email for: assistant vice president, lead data protection & chief of staff (mumbai) / mumbai