Skip to main content
National Payments Corporation of India (NPCI) logo

Senior - Information Security & Privacy

National Payments Corporation of India (NPCI)
2 hours ago
Full-time
On-site
Mumbai Suburban District, Maharashtra, India

About the Role

NPCI is seeking an accomplished leader to Lead the Market Information Security, Cyber Resilience and Privacy function for India's critical digital payments ecosystem. This is a high-impact strategic leadership opportunity for a seasoned professional who can influence not only enterprise security but also the cybersecurity, privacy, resilience, and trust posture of an entire financial ecosystem.

The role is responsible for defining and driving market-wide cybersecurity strategy, information security governance, cyber resilience, privacy governance, regulatory compliance, and risk management initiatives across banks, payment system participants, fintechs, third-party service providers, and other ecosystem stakeholders connected to NPCI platforms.

As a trusted advisor to regulators, industry bodies, financial institutions, and senior leadership, the incumbent will drive initiatives that strengthen ecosystem resilience against cyber threats, technology disruptions, privacy risks, systemic vulnerabilities, and evolving regulatory expectations. The role requires a forward-looking leader capable of anticipating emerging risks, shaping industry standards, and fostering a culture of security, resilience, privacy, and trust across the payments ecosystem.


​

Key Responsibilities

Market Security & Cyber Resilience Leadership

  • Define and execute the Market Information Security, Cyber Resilience, and Privacy strategy aligned with NPCI's vision and regulatory expectations.
  • Lead development and implementation of ecosystem-wide security standards, policies, frameworks, and control requirements.
  • Drive initiatives to enhance cyber maturity, resilience, and operational readiness across market participants.
  • Provide strategic leadership on emerging technology risks, cloud security, AI security, digital trust, and cyber-defense capabilities.

Cyber Risk & Governance

  • Lead market-level cyber risk management and systemic risk assessment programs.
  • Establish governance mechanisms for identifying, measuring, monitoring, and mitigating cybersecurity and technology risks.
  • Drive third-party risk management, supply-chain security, and critical dependency assessments across ecosystem participants.
  • Develop risk-based frameworks and assurance mechanisms to strengthen overall ecosystem security.

Privacy Governance & DPDP Readiness

  • Drive privacy governance initiatives across ecosystem participants aligned with applicable privacy and data protection laws.
  • Collaborate with stakeholders on privacy risk assessments, Privacy Impact Assessments (PIAs), Data Protection Impact Assessments (DPIAs), data classification, cross-border data sharing, consent management, and privacy-by-design principles.
  • Support implementation and monitoring of privacy controls, accountability frameworks, and data governance standards.
  • Assess emerging privacy regulations and translate regulatory expectations into practical security and privacy controls.
  • Partner with business, legal, compliance, and technology teams to strengthen privacy compliance and data protection maturity.

Regulatory Compliance & Assurance

  • Lead engagement with regulators, supervisory authorities, auditors, and industry bodies.
  • Drive ecosystem-wide compliance assessments, security reviews, regulatory examinations, audits, and remediation programs.
  • Ensure alignment with applicable cybersecurity, resilience, privacy, and regulatory requirements.
  • Influence industry standards and contribute to regulatory consultations, working groups, and sector-wide initiatives.

Incident Preparedness & Resilience

  • Lead cyber resilience programs including crisis management, cyber drills, tabletop exercises, threat simulations, and incident-response preparedness.
  • Strengthen ecosystem readiness against cyberattacks, large-scale disruptions, systemic failures, and privacy-related incidents.
  • Drive coordinated response mechanisms and information-sharing initiatives across market participants.

Stakeholder Management & Industry Collaboration

  • Build strong relationships with regulators, banks, fintechs, payment ecosystem participants, technology providers, auditors, and industry forums.
  • Act as NPCI's representative in cybersecurity, resilience, privacy, and governance engagements.
  • Foster collaboration and collective defense strategies to address evolving threats and privacy challenges.

Executive Reporting & Governance

  • Develop board-level dashboards, cybersecurity metrics, privacy metrics, risk indicators, and resilience maturity reports.
  • Present strategic insights and recommendations to executive management, Board Committees, and governance forums.
  • Provide thought leadership on cyber threats, data protection, regulatory developments, and emerging technology risks.
​






Requirements

  • Bachelor's or Master's degree in Engineering, Computer Science, Information Security, Cybersecurity, Privacy, Technology, or related disciplines.
  • Minimum 15+ years of experience in Information Security, Cybersecurity, Privacy, GRC, Technology Risk, Audit, Regulatory Compliance, or Cyber Resilience.
  • Proven leadership experience within BFSI, Payments, Financial Market Infrastructure, FinTech, or other highly regulated sectors.
  • Strong expertise in cybersecurity governance, information security, cyber resilience, privacy management, regulatory compliance, risk management, and audit.
  • Deep understanding of financial-sector regulations, cybersecurity frameworks, privacy laws, DPDP requirements, resilience frameworks, and industry standards.
  • Proven experience engaging with regulators, auditors, Boards, senior executives, and external stakeholders.
  • Demonstrated ability to influence policy, drive industry-wide initiatives, and lead complex transformation programs.
  • Excellent strategic thinking, analytical capability, stakeholder management, and leadership skills with the ability to operate effectively at CXO, Board, and regulatory levels.
  • Professional certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor/Lead Implementer, CIPT, CIPM, CIPP, CDPSE, or equivalent will be an added advantage.