Data Protection and Cybersecurity Manager
- Cognita Schools
- Hyderābād, India
- INR 2,000,000 – INR 3,500,000
CHIREC INTERNATIONAL SCHOOL
CHIREC International is a leading K-12 school located in Hyderabad, India offering International Baccalaureate Diploma Programme (IBDP), Cambridge International Examinations (CIE) and Central Board of Secondary Education (CBSE). CHIREC was founded in 1989 by Founder-Director, Ratna Reddy as a summer camp that offered programmes in fine arts, performing arts, computers, indoor and outdoor sports. Today, CHIREC is one of the premier educational institutions in the country for excellence in academics and co-curricular activities. CHIREC’s mission is to nurture the innate potential of its students to enable them to excel in whatever they choose. The school helps students to grow and evolve into open-minded, ethical and caring individuals who are focused and encouraged to set goals, attain them and exceed expectations. As a valued member of the Cognita global group, and recognized by respected educational bodies like the Council of International Schools (CIS) and the IB Organization, CHIREC International School is known for its exceptional quality of education.
About Cognita
At Cognita, we know every student is unique. We nurture their distinct
personalities and strengths. We support them academically, socially, and
emotionally, wherever they are in the world, wherever they’re starting from.
And each and every one of our schools is unique too.
We protect what’s special about them, while offering them rich knowledge,
opportunities, and best practices. And they get to be part of something bigger.
We open their classrooms to the collective wisdom of over 100 schools in 16
countries, ensuring every child gets an education that’s, quite literally,
world class.
It’s an individual approach that empowers every school, teacher and student to
focus on what they do best. And thrive.
Position
Overview
The Data Protection and
Cybersecurity Manager will initially focus on coordinating and driving the
organization's data protection & privacy implementation, including
implementation of the DPDPA and related requirements. The role will work
closely with business and IT teams to establish and embed appropriate data
protection practices, governance, documentation, and controls.
As part of the role, the
position will also work closely with the IT team on cybersecurity, technology
risk, security controls, and day-to-day IT operational matters, with the scope
expected to evolve as the organization's data protection and cybersecurity
capabilities mature.
The position coordinates organization-wide
implementation of the DPDPA, applicable privacy requirements, and relevant
cybersecurity standards and practices. Working with stakeholders across
departments, the role ensures that data protection, privacy and security
requirements are embedded into business processes, technology initiatives,
vendor relationships, and day-to-day operations.
Scope
The role identifies gaps,
coordinates corrective actions, monitors implementation, and provides practical
guidance to business and technology teams. Final legal interpretations,
executive-level policy ownership, and acceptance of significant risks remain
with the appropriate senior management, Legal/Compliance, or designated privacy
leadership. The scope of IT involvement will evolve based on organizational
priorities and requirements.
Job
Responsibilities
Data
Protection & Privacy
Act as the central point of coordination for
organization-wide data protection & privacy implementation.
Coordinate compliance with the DPDPA and other
applicable data protection and privacy requirements.
Maintain and support implementation of data protection
& privacy policies, procedures, standards, and guidelines.
Work with business and functional teams to embed data
protection requirements into processes, technology initiatives, and
third-party engagements.
Coordinate data mapping, data inventories, and
privacy/data protection impact assessments, where applicable.
Review data handling practices, identify compliance
gaps, and coordinate remediation.
Support management of data protection risks, privacy
incidents, and personal data breaches in coordination with relevant
stakeholders.
Maintain required data protection & privacy records
and documentation and provide periodic compliance updates to management.
Support data protection & privacy awareness and
training initiatives and provide day-to-day guidance to stakeholders.
Cybersecurity
Governance
Maintain and support the implementation of cybersecurity
policies.
Support the implementation of cybersecurity standards
and procedures.
Monitor compliance with established security controls.
Conduct periodic security governance reviews and track
corrective actions.
Prepare and report the organization's cybersecurity
posture and key risks to management.
Coordinate with IT and relevant stakeholders on
cybersecurity risk remediation.
Security
Operations
Monitor cybersecurity incidents, alerts, and security
monitoring reports.
Coordinate incident response and remediation activities
with IT and relevant stakeholders.
Monitor key endpoint, network, and cloud security
controls.
Coordinate vulnerability identification and timely
remediation.
Support periodic security assessments and testing.
Cybersecurity Risk Management
Support cybersecurity and data protection & privacy
risk assessments.
Maintain the cybersecurity and data risk register.
Monitor emerging cybersecurity threats and risks.
Track risk mitigation and remediation activities.
Report significant cybersecurity risks and outstanding
actions to management.
Identity & Access Management
Review privileged and critical user accounts.
Monitor user access governance and periodic access
reviews.
Coordinate access certification exercises.
Support least-privilege and segregation-of-duties
requirements.
Review critical access requests in accordance with
established policies.
Third-Party
Security
Support assessment of vendor cybersecurity and data
protection & privacy controls.
Review security and data protection & privacy requirements
in vendor arrangements.
Coordinate third-party cybersecurity and data protection
& privacy risk assessments.
Monitor remediation of identified vendor security risks.
Coordinate with Procurement, Legal, IT, and relevant
business teams on third-party security matters.
IT Operations
& Technology Coordination
Work closely with the IT team on day-to-day IT
operations, technology risks, and improvement initiatives.
Coordinate with IT on security, privacy, access,
infrastructure, and other technology controls.
Participate in IT projects, system changes, incident
management, and remediation activities.
Support continuous improvement of IT processes,
controls, documentation, and operational practices.
Required
Qualifications & Experience
Bachelor's degree in Computer Science, Information
Technology, Cybersecurity, Information Security, or a related discipline.
5–8 years of relevant experience in cybersecurity,
information security, data protection & privacy, IT risk, compliance,
or a related field.
Practical experience in data protection & privacy,
cybersecurity, IT operations, security governance, risk management,
compliance, or related areas, with the ability to work across both
governance and operational environments.
Working knowledge of data privacy principles and
applicable regulations, including the DPDPA.
Experience with security controls, vulnerability
management, access management, incident response, and third-party risk.
Good understanding of IT infrastructure, network,
endpoint, cloud, identity, application security, and general IT
operations.
Relevant certifications such as ISO 27001 or equivalent
cybersecurity/privacy certifications are preferred.
Benefits at CHIREC
· Competitive salary depending upon qualifications and experience
· Lunch on all school-working days
· School transport as per the available bus routes
· Comprehensive Medical Insurance
· Personal accident policy
· Term Life policy
· Professional Development
How to Apply
Complete the application form available on www.chirec.ac.in before the closing
date. The Closing Date for Applications is: 30-Sep. -2026
Cognita Schools are committed to safeguarding and promoting the welfare of
children and young people and expect all staff, volunteers and other third
parties to share this commitment. Safer recruitment practice and pre-employment
background checks will be undertaken before any appointment is
confirmed.
We believe having a diverse workforce makes us better, smarter and happier and
so welcome applicants from all backgrounds, genders, and races. We have an
unwavering commitment to being fair and equitable in our recruitment
process.
EARLY APPLICATIONS ARE ENCOURAGED; WE RESERVE THE RIGHT TO INTERVIEW AND
APPOINT PRIOR TO CLOSING DATE FOR THE RIGHT APPLICANT.
Applicants who have not heard from us by the closing date must assume that, on
this occasion, their application has been unsuccessful.
Skills
- Data Protection
- Cybersecurity
- Risk Management
- Compliance
- Incident Response
- Security Auditing
- Policy Development








