Description
The Associate Director will lead the design, implementation, governance, and continuous improvement of Information Security and Data Privacy programs across the organization. The role is responsible for ensuring compliance with global security standards, regulatory requirements, and client contractual obligations while enabling business growth through secure and resilient technology practices.
The individual will partner with senior leadership, technology teams, business stakeholders, legal, risk, and global member firms to strengthen the firm's security posture, manage cyber risks, and drive strategic security initiatives.
Responsibilities
Information Security Governance----
Lead the implementation and continuous enhancement of the Information Security Management System (ISMS).
Develop, review, and maintain enterprise information security policies, standards, procedures, and guidelines.
Drive security governance aligned with ISO 27001, NIST CSF, CIS Controls, and industry best practices.
Present security metrics, risk posture, and strategic updates to executive leadership.
Data Privacy & Regulatory Compliance---
Ensure compliance with applicable privacy regulations including GDPR, DPDP Act (India), UK GDPR, and other global privacy requirements.
Collaborate with Legal, Compliance, and business teams on privacy impact assessments and data protection initiatives.
Oversee data classification, retention, secure disposal, and data handling practices.
Support client due diligence, privacy assessments, and regulatory audits.
Security Risk Management--
Lead enterprise risk assessments and third-party security reviews.
Manage remediation of security findings and monitor risk treatment plans.
Provide strategic guidance on emerging cyber threats and security controls.
Evaluate security implications of recent technologies and business initiatives.
Security Operations & Incident Management---
Provide executive oversight of security incidents, investigations, and
📌 Senior Manager (Gurugram)
🏢 BSR
📍 Gurugram