Head of P&R, Security & Data Privacy
IN
Position Title: Head of P&R, Security & Data Privacy- Allianz Services India
130 years of trust, time to shape what's next. Allianz Group is one of the world's leading insurers and asset managers - built on over a century of stability, expertise, and financial strength. Allianz Services is where that legacy meets the future. 8,200+ people. Eight countries. Three continents. We deliver specialized services to clients within Allianz Group, powered by AI, advanced analytics, and a mindset that refuses to stand still. From core insurance operations to engineering and consulting services, we reimagine how insurance works. What truly sets us apart are our people and the trusted partnerships we build, anchored in our values of expertise, integrity, and empowerment. We don't support the business. We shape it
Role Summary
The Head of P&R, Security & Data Privacy is responsible for leading the strategic and operational delivery of protection and resilience, information security, data privacy, AI Governance and Digital Resilience across, as part of the management & executive leadership of Allianz Services India. This role ensures that the entity is safeguarded against potential threats and complies with regulatory requirements, while fostering a culture of security and resilience. This position is also responsible for developing and implementing strategies for Quality Management.
Key Responsibilities
Executive Leadership & Corporate Governance
- Translate global Allianz Group risk, security, and quality strategies into actionable, localized operational roadmaps, advising C-suite and board stakeholders on risk posture, regulatory readiness, and vulnerabilities.
- Foster a culture of strict compliance, operational resilience, and continuous process optimization, managing budgets and resource allocation across all pillars for cost efficiency.
- Champion continuous improvement by identifying opportunities to enhance processes, systems, and controls across protection, security, and quality domains.
- Set clear objectives, conduct performance reviews, and drive talent development, succession planning, and change management to empower and inspire teams.
- Build, mentor, and retain a high-performing cross-functional team, synthesizing fragmented metrics into unified governance dashboards for transparent reporting.
- Enforce compliance with IRCS/NFRM controls as a robust First Line of Defence, championing participation in audits and governance communities of practice.
- Harmonize regulatory adherence with agile service delivery, driving training and awareness programs across protection, security, and quality domains for all personnel.
Protection & Resilience
- Define and execute the comprehensive India protection and resilience strategy aligned with DORA and the Allianz Standard for Protection & Resilience
- Lead the Crisis Management, orchestrating physical security, emergency response, and localized incident containment
- Ensure comprehensive IT Service Continuity Management (ITSCM) and Business Continuity Planning (BCP) across all critical shared service operations
- Design and execute crisis simulations, corporate readiness assessments, and extensive Business Impact Analyses (BIA)
- Liaise with local law enforcement, government emergency services, and cross-border regulatory bodies during critical events
- Embed threat intelligence mechanisms to counter geopolitical, environmental, and infrastructure risks to service continuity
Information Security
- Govern the Information Security strategy in alignment with AFRIS, AFRIT, AFIRM, and GISF frameworks
- Own enterprise GRC platform operations, driving risk identification, mitigation mapping, and automated reporting
- Oversee security incident response workflows, ensuring coordination with Global SOC/CIRT teams and deep post-mortem root cause analysis
- Manage the corporate Information Security risk register, enforcing accountability and timely mitigation by assigned risk owners
- Enforce supplier security assurance protocols, regulating vendor onboarding assessments and recurring threat-vector reviews
- Deploy enterprise-wide security awareness programs targeting sophisticated vectors including social engineering, deepfakes, and AI-driven fraud
- Operationalize compliance requirements for the EU AI Act regarding algorithmic transparency, data lineage, and risk mitigation in AI deployment
Data Privacy & AI Governance
- Ensure full compliance with the Allianz Privacy Standard (APS), Responsible AI Standards, GDPR (as Data Processor for EEA data), and India's Digital Personal Data Protection (DPDP) Act 2023
- Oversee Privacy Impact Assessments (PIAs), Data Protection Impact Assessments (DPIAs), and Privacy & Ethics Impact Assessments (PEIAs) for all processing activities and AI use cases
- Ensure all AI Systems and AI Use Cases are governed; monitor prohibited AI practices and high-risk AI system obligations under the EU AI Act
- Manage personal data incident response, ensuring breach notification compliance within statutory timelines
- Oversee Subject Access Requests (SARs), data subject rights, and the right to contest automated AI-driven decisions
- Maintain comprehensive Records of Processing Activities (RoPA) using the OneTrust Privacy Management Tool
- Ensure compliance with cross-border data transfer requirements, Allianz Binding Corporate Rules (BCRs), and Standard Contractual Clauses
- Drive vendor and third-party privacy due diligence, including AI tool assessments against Allianz Generative AI Guidelines
- Lead AI Literacy and data privacy training programs as mandated by the RAI Standard and APS
Standards & Quality Management
- Drive end-to-end process standardization across the organisation
- Lead the corporate Quality Management System (QMS) alongside Lean, Six Sigma, and PDCA continuous improvement methodologies
- Own and continuously optimize the Integrated Management System (IMS), harmonizing ISO 9001, ISO 27001, ISO 14001, and ISO 22301 standards. Maintain and systematically advance the organization's CMMI for Services (CMMI-SVC) maturity level through targeted appraisals
- Proactively identify, evaluate, and recommend emerging industry standards and frameworks aligned with organizational strategy and drive implementation
- Direct all certifications, surveillance, regulatory and other audits & checks, targeting zero major non-conformities across operations
- Define and monitor key performance and quality indicators (KPIs/KQIs) to maximize process efficiency and service delivery excellence
Qualifications
Education: Bachelor's degree or higher in Information Security, Engineering, Business Administration, or related fields. Master's degree/MBA preferred.
Experience (15+ years):
- Minimum 7 years in senior leadership managing multiple governance functions
- Demonstrated success in crisis management, business continuity, and protection programs
- Strong experience in Information Security governance, GRC, and incident management
- Proven experience implementing data privacy frameworks (GDPR, DPDP Act) and AI governance programs
- Experience in shared services / GBS / IT services / insurance or financial services
- Proven track record leading ISO certifications (9001, 27001, 14001, 22301) and CMMI appraisals
- CXO committee exposure and global stakeholder management in a matrix organization
Key Skills:
- DORA-compliant risk management, crisis response, and business continuity
- Data privacy regulations (GDPR, DPDP Act 2023, IT Act 2000) and privacy management tools
- AI governance, EU AI Act compliance, responsible AI frameworks, and AI risk assessment
- IS Governance & Risk frameworks (ISO 27001, NIST, COBIT)
- ISO management system standards and CMMI framework
- Process management methodologies (Lean, Six Sigma, BPM, ITIL)
- GRC platforms, quality tools (FMEA, RCA, SPC), and internal auditing
- Network, application, mobile, and cloud security
- Knowledge of Indian regulatory landscape (IT Act 2000, CERT-In, DPDP Act 2023, IRDAI, BIS)
- Strong leadership, communication, and strategic stakeholder management
Preferred Certifications:
- CISSP / CISM / CISA / CRISC
- CIPP/E / CIPP/A / CIPM / CIPT
- CPP / CBCP
- ISO 9001 & ISO 27001 Lead Auditor/Implementer
- CMMI Associate / Certified CMMI Professional
- Six Sigma Black Belt
- ITIL Foundation or higher
[please translate into your local language]
103519 | Operations | Management | Allianz Executive | Allianz Services | Full-Time | Permanent
Allianz Group is one of the most trusted insurance and asset management companies in the world. Caring for our employees, their ambitions, dreams and challenges, is what makes us a unique employer. Together we can build an environment where everyone feels empowered and has the confidence to explore, to grow and to shape a better future for our customers and the world around us.
At Allianz, we stand for unity: we believe that a united world is a more prosperous world, and we are dedicated to consistently advocating for equal opportunities for all. And the foundation for this is our inclusive workplace, where people and performance both matter, and nurtures a culture grounded in integrity, fairness, inclusion and trust.
We therefore welcome applications regardless of ethnicity or cultural background, age, gender, nationality, religion, social class, disability or sexual orientation, or any other characteristics protected under applicable local laws and regulations.
Join us. Let's care for tomorrow.