29 Sep
|
Iconic IT Consulting Services
|
India
29 Sep
Iconic IT Consulting Services
India
Job Title: Senior Manager - Data Privacy
Duration: 12 Months Contract
Location: Remote across India
Job Purpose
Management:
- To Strategize, develop and implement Data Privacy and Privacy and protection Controls in coordination with stakeholders across the Organization globally.
- To ensure compliance of the Organization with the defined policy & framework with a data driven approach
Execution
- To ensure that the privacy and protection operations are executed effectively in a timely manner and with required quality
- Assists in the development and implementation of Data Privacy and protection strategic initiatives. Leads all Data privacy and protection related tasks with effective monitoring and privacy and protection of information security assets.
Manager Data Privacy and protection has overall responsibility to coordinate and support the Head of Data Privacy and Privacy and protection to achieve organizations Privacy and protection strategy and goals.
He/she is a T-Shaped expert with proven skills in most core capability areas of Data Privacy and protection and security: Policy, Governance, Privacy and protection Strategy & Program Management.
Performance evaluation of the role will be based on the positive impact on the bank in terms of Data privacy and protection posture enhancement rather than the effort put in place.
Key Result Areas
Drive various Data Privacy and protection Initiatives to improve overall maturity
Data Encryption & Anonymization
- Lead enterprise-wide initiatives for data encryption at rest, in transit, and in use, ensuring alignment with regulatory and internal security requirements.
- Drive the design and implementation of data anonymization and masking strategies to protect PII, PCI, and other sensitive data across non-production environments.
- Collaborate with cross-functional teams including Application Development, Infrastructure, Legal, and Compliance to define and enforce encryption and data privacy and protection standards.
- Oversee vendor evaluation and integration of encryption key management and tokenization solutions, ensuring proper lifecycle management.
- Establish governance models and control frameworks for effective implementation and monitoring of data anonymization processes.
Data Loss/Leak Prevention
- Establish the Incident Response framework for GSOC and consult with various business units and legal counsel on developing and improving data leakage privacy and protection processes. Maintain and update investigation handling expectations and service level expectations.
- Development and maintenance of DLP Policies, Standards, Procedures, and Guidelines. Ensure compliance with regulations required for DLP.
- Conduct regular audits and assessments to ensure compliance with data privacy and protection regulations and internal policies.
- Ensure metrics (Key Performance / Risk Indicators) for measuring the effectiveness of the DLP solution are in place.
- Identify stakeholders in IT, legal, and compliance teams to ensure secure data handling practices across the organization. Plan awareness material for sessions for the stakeholders. Data Security Posture Management
- Ensure data discovery exercise across the bank using automated techniques and create data flow diagrams for relevant departments across the bank.
- Ensure maintenance of an accurate inventory of all data assets and management of the entire lifecycle of data, from creation to deletion.
- Develop and implement data masking and anonymization strategies and use of encryption protocol for to encrypt data before transmission.
- Ensure keys are generated using solid random number generators to prevent predictability and implement key rotation policies to periodically change keys and secrets, reducing the impact of compromised keys.
- Designing and implementing a secure architecture for data storage, processing, and transmission.
- Evaluating and recommending security tools and technologies.
- Implementing and maintaining security standards and frameworks (e.g., ISO 27001, NIST Cybersecurity Framework, PDPL, PDPO, PCI). Database Activity Monitoring
- Manage daily operations of database activity monitoring (DAM) systems, ensuring continuous monitoring and alerting. Regularly review system logs and performance metrics.
- Track KPIs to measure DAM effectiveness and conduct regular risk assessments of database systems and create mitigation strategies. Track and report on identified risks.
- Regularly review database logs and reports to identify and address potential security incidents. Implement preventative measures to address recurring issues.
- Ensure database security configurations adhere to best practices and organizational policies. Conduct regular security audits.
Other Data Privacy and protection Initiatives & Collaboration with other teams
- Drive any other projects related to Data Privacy and protection such as Insider Risk Mgmt. enhanced security controls in Backup & Restoration, Data retention & Deletion, Data Discovery & Scans using Privacy Mgmt solution etc
- Provide effective governance of the projects through well-defined KPIs/KRIs
- Collaborate with other teams in ISG to ensure effective implementation of the projects
- Collaborate with Data Privacy team in reviews and assessments to cover overall Data privacy and protection requirements
- Support with Data Privacy and protection Maturity Assessment and its continuous improvement
Key Principles
- Alignment with Business Priorities: The Senior Manager - Data Privacy and protection aligns his actions and those of his departments with the strategic objectives of the business.
- Ownership and Accountability: The Senior Manager - Data Privacy and protection takes full responsibility for his activities and his departments, holding himself and his team accountable for their outcomes.
- Driving Data Privacy and protection Maturity Enhancement: The Senior Manager - Data Privacy and protection proactively drives initiatives that enhances Data Privacy and protection Maturity.
- Focus on Outputs and Impact: The Senior Manager - Data Privacy and protection focuses on delivering outputs that create meaningful impact such as enhanced security posture of the bank.
- Innovation and Automation:
The Senior Manager - Data Privacy and protection continuously seeks innovative solutions and automate processes for efficiency.
- Incident readiness: The Senior Manager - Data Privacy and protection ensures the organizations readiness to any data breaches or other similar incidents, minimizing business and customer impact.
Operating Environment, Framework and Boundaries, Working Relationships
- Operating environment consists of all Groups across the Mashreq Bank (onshore, overseas & offshore) as well as any outsourced setups.
- Leadership team to formalize and finalize the Data Privacy and protection framework for the Organization.
- Discussions in Steering Committee, Governance meetings. Meetings with Senior Management and Leadership team of Mashreq Bank.
- Manage Communication with Local Regulatory bodies.
Problem Solving
- Relevant experience in Data Breach issues and impact and provide recommended remediation plans.
- Critically analyze issues associated with the review findings and come up with effective solutions to revolve them in coordination with review units.
- Leading unstructured and complex issues relating to process design, technology controls and risk management.
- Ability to validate root causes and evaluate solutions for problem remediation.
- Ability to lead the implementation of new solutions and an effective change management.
- Deep understanding to analyze business impact for problem for effective communication to seniors.
- Ability to implement and track a long term improvement program resulting in better uptimes.
Decision Making Authority & Responsibility
- Assist the management in Planning and Forecasting of Privacy solutions to mitigate IS risks
- Coordinate deliverables for External Stakeholders like - Regulatory Bodies etc.
- Data Privacy applicability, scoping and control decision.
- Coordinates POC of relevant Data Privacy and protection solutions/technologies and submits recommendation to senior managers
- Develops processes for key security metrics related to Data Privacy and protection platforms
- Prepares Security Reference Architecture for Mashreqs Data Privacy and protection platforms
- Influences policy adherence, regulation applicability, scoping and control decision.
- Lead recommendations for investments in data security technologies, tools and systems to enhance the banks overall data privacy and protection framework.
- Cost-benefits analysis (ROI) in risk and control decision.
Knowledge, Skills, and Experience
- Graduate/ Post Graduate degree in Science/ Engineering/ IT.
- Minimum 2 Professional certifications: CIPPE / CIPM / CIPT / CDPSE, CISA, CISM, PCI-QSA, CISSP, SABSA.
- 12+ years working experience working in a large financial institution/ bank with minimum 4 years experience within a compliance, legal, audit and/or risk function, with recent experience in data privacy and protection projects/implementation.
- Familiarity with advanced Data Privacy and Privacy and protection technologies, risk, threat and vulnerability assessments, and security measures.
- Strong experience and knowledge across the Data Privacy and Privacy and protection domains including governance, policy procedures, compliance management, risk management and Data Breach response etc.
- Comprehensive knowledge of Data Privacy and Privacy and protection regulatory and compliance requirements across various industries and how they influence the bank's DPP strategy.
📌 Data Privacy and Protection Manager (India)
🏢 Iconic IT Consulting Services
📍 India