AVP - Data Protection (Technical)

Date:  Sep 23, 2026
Location: 

India

Office Location:  New Delhi, India

Headquartered in Tokyo, Sumitomo Mitsui Banking Corporation (SMBC) is a leading global financial institution and a core member of Sumitomo Mitsui Financial Group (SMBC Group). Built upon our rich Japanese heritage since 1876, we put our customers first and provide seamless access to, from and within the Asia Pacific region.   SMBC is one of the largest Japanese banks by assets and maintain strong credit ratings across our global integrated network.  We work closely as one SMBC Group to offer personal, corporate and investment banking services to meet the needs of our customers.

 

With sustainability embedded within our strategy and operations, we are committed to creating a society in which today’s generation can enjoy economic prosperity and well-being, and pass it on to future generations.

Primary Responsibilities

(These are the key work activities to achieve the position objective. Limit this section to essential responsibilities.)

Percentage (%) of

Time Spent

 

Secondary Responsibilities

(List of duties that are marginal or infrequent.)

  1. Support monitoring and implementation of privacy, data security and information security controls relevant to personal data processing, storage, transfer, access, retention and disposal.

20%

Maintain control inventories, evidence records and exception trackers.

  1. Support DPDP and other applicable data protection compliance activities, including operational checklists, control mapping, documentation and remediation follow-up.

20%

Prepare compliance status inputs and maintain supporting documentation for DPO review.

  1. Conduct or support security-related privacy risk assessments and DPIAs for systems, applications, processes, vendors and technology changes involving personal data.

15%

Record risks, control gaps, mitigating actions, owners and target dates.

  1. Support data classification, access control, encryption, masking, anonymization, retention, deletion and other technical or procedural data protection controls in coordination with control owners.

15%

Monitor implementation evidence and escalate overdue or unresolved matters.

  1. Assist in privacy and information security incident response, including initial fact collection, impact assessment support, case documentation, remediation tracking and preparation of DPO updates.

15%

Maintain incident files, chronology, decisions and closure evidence.

  1. Support third-party privacy and security assessments, due diligence reviews and monitoring of data protection requirements for vendors and service providers.

10%

Maintain assessment results, exceptions and remediation records.

  1. Prepare privacy / security metrics, dashboards, control testing results and awareness materials for DPO and governance forums.

5%

Coordinate periodic reporting inputs and training records.

Total

100%

 

  • Knowledge Requirements: Working knowledge of DPDP, GDPR, data privacy principles, data security and information security controls, privacy risk assessment, DPIA / PIA, data classification, retention, access management, encryption, masking, anonymisation, incident management, third-party risk and security governance frameworks.
  • Specialist / technical skills: Privacy and security control assessment; GRC and evidence management; data classification and retention; incident documentation; risk and control mapping; technical documentation; dashboard preparation and remediation tracking. Familiarity with ISO 27001, NIST or similar frameworks and privacy / security tools is desirable.
  • Behavioural / management skills: Analytical thinking, attention to detail, written and verbal communication, documentation discipline, stakeholder coordination, confidentiality, ownership and ability to work under the guidance of the DPO.

Education & Qualifications: Relevant Graduate or post-graduate qualification. Relevant certifications such as Certified Information Privacy Professional (CIPP), Certified Information Privacy Manager (CIPM), Certified Information Privacy Technologist (CIPT), Certified Information Systems Security Professional (CISSP), ISO 27001, Security+, or equivalent may be preferred depending on grade.