Senior - Information Security & Privacy

Posted 3 Days Ago
Be an Early Applicant
Mumbai, Maharashtra, IND
In-Office
Senior level
Fintech • Payments • Financial Services
The Role
Leads market-wide information security, cyber resilience, privacy governance, risk management, regulatory compliance, and assurance for India’s digital payments ecosystem. The role develops security frameworks, coordinates cyber drills and incident preparedness, drives privacy and DPDP readiness, manages systemic and third-party risk, engages regulators and industry stakeholders, and reports cybersecurity, privacy, and resilience metrics to executives and boards.
Summary Generated by Built In

About the Role

NPCI is seeking an accomplished leader to Lead the Market Information Security, Cyber Resilience and Privacy function for India's critical digital payments ecosystem. This is a high-impact strategic leadership opportunity for a seasoned professional who can influence not only enterprise security but also the cybersecurity, privacy, resilience, and trust posture of an entire financial ecosystem.

The role is responsible for defining and driving market-wide cybersecurity strategy, information security governance, cyber resilience, privacy governance, regulatory compliance, and risk management initiatives across banks, payment system participants, fintechs, third-party service providers, and other ecosystem stakeholders connected to NPCI platforms.

As a trusted advisor to regulators, industry bodies, financial institutions, and senior leadership, the incumbent will drive initiatives that strengthen ecosystem resilience against cyber threats, technology disruptions, privacy risks, systemic vulnerabilities, and evolving regulatory expectations. The role requires a forward-looking leader capable of anticipating emerging risks, shaping industry standards, and fostering a culture of security, resilience, privacy, and trust across the payments ecosystem.


​

Key Responsibilities

Market Security & Cyber Resilience Leadership

  • Define and execute the Market Information Security, Cyber Resilience, and Privacy strategy aligned with NPCI's vision and regulatory expectations.
  • Lead development and implementation of ecosystem-wide security standards, policies, frameworks, and control requirements.
  • Drive initiatives to enhance cyber maturity, resilience, and operational readiness across market participants.
  • Provide strategic leadership on emerging technology risks, cloud security, AI security, digital trust, and cyber-defense capabilities.

Cyber Risk & Governance

  • Lead market-level cyber risk management and systemic risk assessment programs.
  • Establish governance mechanisms for identifying, measuring, monitoring, and mitigating cybersecurity and technology risks.
  • Drive third-party risk management, supply-chain security, and critical dependency assessments across ecosystem participants.
  • Develop risk-based frameworks and assurance mechanisms to strengthen overall ecosystem security.

Privacy Governance & DPDP Readiness

  • Drive privacy governance initiatives across ecosystem participants aligned with applicable privacy and data protection laws.
  • Collaborate with stakeholders on privacy risk assessments, Privacy Impact Assessments (PIAs), Data Protection Impact Assessments (DPIAs), data classification, cross-border data sharing, consent management, and privacy-by-design principles.
  • Support implementation and monitoring of privacy controls, accountability frameworks, and data governance standards.
  • Assess emerging privacy regulations and translate regulatory expectations into practical security and privacy controls.
  • Partner with business, legal, compliance, and technology teams to strengthen privacy compliance and data protection maturity.

Regulatory Compliance & Assurance

  • Lead engagement with regulators, supervisory authorities, auditors, and industry bodies.
  • Drive ecosystem-wide compliance assessments, security reviews, regulatory examinations, audits, and remediation programs.
  • Ensure alignment with applicable cybersecurity, resilience, privacy, and regulatory requirements.
  • Influence industry standards and contribute to regulatory consultations, working groups, and sector-wide initiatives.

Incident Preparedness & Resilience

  • Lead cyber resilience programs including crisis management, cyber drills, tabletop exercises, threat simulations, and incident-response preparedness.
  • Strengthen ecosystem readiness against cyberattacks, large-scale disruptions, systemic failures, and privacy-related incidents.
  • Drive coordinated response mechanisms and information-sharing initiatives across market participants.

Stakeholder Management & Industry Collaboration

  • Build strong relationships with regulators, banks, fintechs, payment ecosystem participants, technology providers, auditors, and industry forums.
  • Act as NPCI's representative in cybersecurity, resilience, privacy, and governance engagements.
  • Foster collaboration and collective defense strategies to address evolving threats and privacy challenges.

Executive Reporting & Governance

  • Develop board-level dashboards, cybersecurity metrics, privacy metrics, risk indicators, and resilience maturity reports.
  • Present strategic insights and recommendations to executive management, Board Committees, and governance forums.
  • Provide thought leadership on cyber threats, data protection, regulatory developments, and emerging technology risks.
​






Requirements
  • Bachelor's or Master's degree in Engineering, Computer Science, Information Security, Cybersecurity, Privacy, Technology, or related disciplines.
  • Minimum 15+ years of experience in Information Security, Cybersecurity, Privacy, GRC, Technology Risk, Audit, Regulatory Compliance, or Cyber Resilience.
  • Proven leadership experience within BFSI, Payments, Financial Market Infrastructure, FinTech, or other highly regulated sectors.
  • Strong expertise in cybersecurity governance, information security, cyber resilience, privacy management, regulatory compliance, risk management, and audit.
  • Deep understanding of financial-sector regulations, cybersecurity frameworks, privacy laws, DPDP requirements, resilience frameworks, and industry standards.
  • Proven experience engaging with regulators, auditors, Boards, senior executives, and external stakeholders.
  • Demonstrated ability to influence policy, drive industry-wide initiatives, and lead complex transformation programs.
  • Excellent strategic thinking, analytical capability, stakeholder management, and leadership skills with the ability to operate effectively at CXO, Board, and regulatory levels.
  • Professional certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor/Lead Implementer, CIPT, CIPM, CIPP, CDPSE, or equivalent will be an added advantage.


Skills Required

  • Bachelor’s or Master’s degree in Engineering, Computer Science, Information Security, Cybersecurity, Privacy, Technology, or a related discipline.
  • Minimum 15+ years of experience in Information Security, Cybersecurity, Privacy, GRC, Technology Risk, Audit, Regulatory Compliance, or Cyber Resilience.
  • Leadership experience within BFSI, payments, financial market infrastructure, fintech, or another highly regulated sector.
  • Expertise in cybersecurity governance, information security, cyber resilience, privacy management, regulatory compliance, risk management, and audit.
  • Deep understanding of financial-sector regulations, cybersecurity frameworks, privacy laws, DPDP requirements, resilience frameworks, and industry standards.
  • Experience engaging with regulators, auditors, boards, senior executives, and external stakeholders.
  • Ability to influence policy, drive industry-wide initiatives, and lead complex transformation programs.
  • Strong strategic thinking, analytical capability, stakeholder management, and leadership skills at CXO, board, and regulatory levels.
  • Professional certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor or Lead Implementer, CIPT, CIPM, CIPP, CDPSE, or equivalent.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Mumbai, Maharashtra
2,124 Employees
Year Founded: 2005

What We Do

NPCI is an umbrella organisation for all retail payment systems in India. It was set up with the support & guidance from Reserve Bank of India (RBI) & Indian Banks Association (IBA). A registered company under Section 8 of the Companies Act, 2013. Watch the NPCI Corporate AV - https://youtu.be/RGl9YQ6CB20 Products & Services Unified Payments Interface Unique payment solution which empowers a recipient to initiate the payment request from a smartphone. It facilitates 'virtual payment address'​ as a payment identifier for sending & collecting money & works on single click 2 factor authentication. Immediate Payment Service A 24X7, real time, cost effective, independent channel, retail payment service, introduced by NPCI, empowering customers to transfer money instantly with banks & RBI authorised PPIs across India. RuPay Robust card scheme designed to offer payment products with superior features & processes specifically designed to cater to diverse consumer needs. *99# USSD based mobile banking platform that makes banking services accessible to all the bank account holders on their mobile phones. National Automated Clearing House Centralised payment system developed with an aim to consolidate multiple ECS systems running across the country & provide a framework for the removal of local barriers/inhibitors. Aadhaar Enabled Payment System Bank led model which allows online financial inclusion transactions at micro-ATMs through the business correspondent of any bank using the Aadhaar authentication. e-KYC Electronic way of conducting authentic & real time KYC of a customer using Aadhaar authentication. Cheque Truncation System Electronic image of the cheque is transmitted to the drawee bank by the clearing house, along with relevant information. National Financial Switch Facilitates routing of ATM transactions through inter-connectivity between its member institutions thereby enabling the citizens of the country to utilise any ATM of a connected entity

Similar Jobs

Mastercard Logo Mastercard

Manager, Product Management, Scheme and Regulatory Compliance

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Pune, Maharashtra, IND
38800 Employees

ServiceNow Logo ServiceNow

Client Director

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Hybrid
Mumbai, Maharashtra, IND
29000 Employees

Mastercard Logo Mastercard

Software Engineer

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Navi Mumbai, Thane, Maharashtra, IND
38800 Employees

Mastercard Logo Mastercard

Manager, Product Management

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Pune, Maharashtra, IND
38800 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account