Data Protection and Cybersecurity Manager

CognitaIndia
Adzuna INPosted -55m agoOriginal Listing
it-jobs

Job Description

CHIREC INTERNATIONAL SCHOOL CHIREC International is a leading K-12 school located in Hyderabad, India offering International Baccalaureate Diploma Programme (IBDP), Cambridge International Examinations (CIE) and Central Board of Secondary Education (CBSE). CHIREC was founded in 1989 by Founder-Director, Ratna Reddy as a summer camp that offered programmes in fine arts, performing arts, computers, indoor and outdoor sports. Today, CHIREC is one of the premier educational institutions in the country for excellence in academics and co-curricular activities. CHIREC’s mission is to nurture the innate potential of its students to enable them to excel in whatever they choose. The school helps students to grow and evolve into open-minded, ethical and caring individuals who are focused and encouraged to set goals, attain them and exceed expectations. As a valued member of the Cognita global group, and recognized by respected educational bodies like the Council of International Schools (CIS) and the IB Organization, CHIREC International School is known for its exceptional quality of education. About Cognita At Cognita, we know every student is unique. We nurture their distinct personalities and strengths. We support them academically, socially, and emotionally, wherever they are in the world, wherever they’re starting from. And each and every one of our schools is unique too. We protect what’s special about them, while offering them rich knowledge, opportunities, and best practices. And they get to be part of something bigger. We open their classrooms to the collective wisdom of over 100 schools in 16 countries, ensuring every child gets an education that’s, quite literally, world class. It’s an individual approach that empowers every school, teacher and student to focus on what they do best. And thrive. Position Overview The Data Protection and Cybersecurity Manager will initially focus on coordinating and driving the organization's data protection & privacy implementation, including implementation of the DPDPA and related requirements. The role will work closely with business and IT teams to establish and embed appropriate data protection practices, governance, documentation, and controls. As part of the role, the position will also work closely with the IT team on cybersecurity, technology risk, security controls, and day-to-day IT operational matters, with the scope expected to evolve as the organization's data protection and cybersecurity capabilities mature. The position coordinates organization-wide implementation of the DPDPA, applicable privacy requirements, and relevant cybersecurity standards and practices. Working with stakeholders across departments, the role ensures that data protection, privacy and security requirements are embedded into business processes, technology initiatives, vendor relationships, and day-to-day operations. Scope The role identifies gaps, coordinates corrective actions, monitors implementation, and provides practical guidance to business and technology teams. Final legal interpretations, executive-level policy ownership, and acceptance of significant risks remain with the appropriate senior management, Legal/Compliance, or designated privacy leadership. The scope of IT involvement will evolve based on organizational priorities and requirements. Job Responsibilities Data Protection & Privacy Act as the central point of coordination for organization-wide data protection & privacy implementation. Coordinate compliance with the DPDPA and other applicable data protection and privacy requirements. Maintain and support implementation of data protection & privacy policies, procedures, standards, and guidelines. Work with business and functional teams to embed data protection requirements into processes, technology initiatives, and third-party engagements. Coordinate data mapping, data inventories, and privacy/data protection impact assessments, where applicable. Review data handling practices, identify compliance gaps, and coordinate remediation. Support management of data protection risks, privacy incidents, and personal data breaches in coordination with relevant stakeholders. Maintain required data protection & privacy records and documentation and provide periodic compliance updates to management. Support data protection & privacy awareness and training initiatives and provide day-to-day guidance to stakeholders. Cybersecurity Governance Maintain and support the implementation of cybersecurity policies. Support the implementation of cybersecurity standards and procedures. Monitor compliance with established security controls. Conduct periodic security governance reviews and track corrective actions. Prepare and report the organization's cybersecurity posture and key risks to management. Coordinate with IT and relevant stakeholders on cybersecurity risk remediation. Security Operations Monitor cybersecurity incidents, alerts, and security monitoring reports. Coordinate incident response and remediation activities with IT and relevant stakeholders. Monitor key endpoint, network, and cloud security controls. Coordinate vulnerability identification and timely remediation. Support periodic security assessments and testing. Cybersecurity Risk Management Support cybersecurity and data protection & privacy risk assessments. Maintain the cybersecurity and data risk register. Monitor emerging cybersecurity threats and risks. Track risk mitigation and remediation activities. Report significant cybersecurity risks and outstanding actions to management. Identity & Access Management Review privileged and critical user accounts. Monitor user access governance and periodic access reviews. Coordinate access certification exercises. Support least-privilege and segregation-of-duties requirements. Review critical access requests in accordance with established policies. Third-Party Security Support assessment of vendor cybersecurity and data protection & privacy controls. Review security and data protection & privacy requirements in vendor arrangements. Coordinate third-party cybersecurity and data protection & privacy risk assessments. Monitor remediation of identified vendor security risks. Coordinate with Procurement, Legal, IT, and relevant business teams on third-party security matters. IT Operations & Technology Coordination Work closely with the IT team on day-to-day IT operations, technology risks, and improvement initiatives. Coordinate with IT on security, privacy, access, infrastructure, and other technology controls. Participate in IT projects, system changes, incident management, and remediation activities. Support continuous improvement of IT processes, controls, documentation, and operational practices. Required Qualifications & Experience Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Security, or a related discipline. 5–8 years of relevant experience in cybersecurity, information security, data protection & privacy, IT risk, compliance, or a related field. Practical experience in data protection & privacy, cybersecurity, IT operations, security governance, risk management, compliance, or related areas, with the ability to work across both governance and operational environments. Working knowledge of data privacy principles and applicable regulations, including the DPDPA. Experience with security controls, vulnerability management, access management, incident response, and third-party risk. Good understanding of IT infrastructure, network, endpoint, cloud, identity, application security, and general IT operations. Relevant certifications such as ISO 27001 or equivalent cybersecurity/privacy certifications are preferred. Benefits at CHIREC · Competitive salary depending upon qualifications and experience · Lunch on all school-working days · School transport as per the available bus routes · Comprehensive Medical Insurance · Personal accident policy · Term Life policy · Professional Development How to Apply Complete the application form available on www.chirec.ac.in before the closing date. The Closing Date for Applications is: 31-August -2026 Cognita Schools are committed to safeguarding and promoting the welfare of children and young people and expect all staff, volunteers and other third parties to share this commitment. Safer recruitment practice and pre-employment background checks will be undertaken before any appointment is confirmed. We believe having a diverse workforce makes us better, smarter and happier and so welcome applicants from all backgrounds, genders, and races. We have an unwavering commitment to being fair and equitable in our recruitment process. EARLY APPLICATIONS ARE ENCOURAGED; WE RESERVE THE RIGHT TO INTERVIEW AND APPOINT PRIOR TO CLOSING DATE FOR THE RIGHT APPLICANT. Applicants who have not heard from us by the closing date must assume that, on this occasion, their application has been unsuccessful.

Get AI-Matched to This Job

Upload your resume and our AI will score how well you match this and thousands of similar roles.