Line of Service
Internal Firm Services
Industry/Sector
Not Applicable
Specialism
Operations
Management Level
Director
& Summary
At PwC, our people in business application consulting specialise in consulting services for a variety of business applications, helping clients optimise operational efficiency. These individuals analyse client needs, implement software solutions, and provide training and support for seamless integration and utilisation of business applications, enabling clients to achieve their strategic objectives.
As a business application consulting generalist at PwC, you will provide consulting services for a wide range of business applications. You will leverage a broad understanding of various software solutions to assist clients in optimising operational efficiency through analysis, implementation, training, and support.
& Summary
The CISO & DPO is a senior leadership role (Senior Director level) accountable for leading the organization’s cyber security strategy, information security governance, and data protection operations. The role is split equally (50/50) between cyber security leadership and privacy governance. The incumbent will own the CISO office agenda, strengthen enterprise security posture, drive NIS and information security control implementation, and ensure alignment with the DPDP Act. This position requires a strategic leader capable of influencing executive stakeholders and managing cross-functional teams across technology, business, legal, and risk departments.
Responsibilities
Define and lead cyber security strategy, operating models, and governance routines. Drive continuous improvement across security and privacy processes, playbooks, and SOPs.
Oversee incident response, vulnerability management, DLP, security exceptions, and remediation tracking.
Lead DPDP Act 2023 compliance, privacy risk assessments (DPIA/DPRA), data principal rights governance, and privacy incident coordination.
Mentor and develop multi-disciplinary teams. Manage cross-functional working groups involving IT, Legal, Risk, and business units.
Sponsor and oversee compliance programs (ISO 27001, ISO 22301, SOC 2) and ensure security/privacy-by-design in new projects and technology rollouts.
Provide executive-level reporting on cyber risk, incident trends, regulatory readiness, and remediation status.
Mandatory skill sets
Ability to set enterprise cyber security strategy and operating models, and measure outcomes.
Expertise in coordinating assessments, evidence packs, and remediation plans for security and privacy controls.
Capability to oversee incident triage, escalation, and root-cause tracking.
Deep understanding of DPDP compliance, data rights, and privacy-by-design integration.
Proven leadership ability to influence executive stakeholders and build cross-functional alignment.
Ability to advise project/product teams on NIS controls and go-live readiness.
Preferred skill sets
Hands-on experience with ISO 27001, ISO 22301, SOC 2, and CIS controls frameworks.
Experience in business continuity planning (BCP), crisis management, and third-party/product security.
Strong executive communication skills and experience engaging with external assurance/regulatory interfaces.
Years of experience required
20–25 years of overall experience in information security, cyber risk, technology risk, security governance, IT risk management, privacy governance, or regulatory compliance.
Education qualification
Bachelor's degree in Engineering, Computer Science, Information Systems, Cyber Security, Risk Management, or related discipline (essential).
Postgraduate qualification (desirable).
Preferred certifications include CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer/Lead Auditor, ISO 22301, CCSP, or CIPM.
Executive leadership, crisis management, and program governance training are desirable.
Top of Form
Bottom of Form
Education (if blank, degree and/or field of study not specified)
Degrees/Field of Study required:Degrees/Field of Study preferred:
Certifications (if blank, certifications not specified)
Required Skills
Optional Skills
Accepting Feedback, Accepting Feedback, Active Listening, Agile Methodology, Analytical Thinking, Azure Data Factory, Coaching and Feedback, Communication, Creativity, Cybersecurity, Cybersecurity Framework, Cybersecurity Policy, Cybersecurity Requirements, Cybersecurity Strategy, Embracing Change, Emotional Regulation, Empathy, Encryption Technologies, Inclusion, Influence, Innovation, Intellectual Curiosity, Learning Agility, Managed Services, Optimism {+ 20 more}
Desired Languages (If blank, desired languages not specified)
Travel Requirements
Not Specified
Available for Work Visa Sponsorship?
No
Government Clearance Required?
No
Job Posting End Date
July 17, 2026

At PwC, we help clients drive their companies to the leading edge. We’re a tech-forward, people-empowered network with more than 370,000 people in 149 countries. Across audit and assurance, tax and legal, deals and consulting we help build, accelerate and sustain momentum. Find out more at www.pwc.com.
PwC: Audit and assurance, consulting and tax services
PwC refers to the PwC network and/or one or more of its member firms, each of which is a separate legal entity. Content on this page has been prepared for general information only and is not intended to be relied upon as accounting, tax or professional advice. Please reach out to your advisors for specific advice.