30 Jul
|
Sharp Group
|
India
Job Title
GRC and Data Privacy Consultant
Designation
Sr. Security Analyst
Job Type
Full - Time
Department
GRC
Location
Gurgaon - Hybrid
Domain
GRC
Purpose of the role:
We are seeking a skilled and experienced GRC (Governance, Risk, and Compliance) and Data Privacy Consultant to join our dynamic team. As a consultant, you will be responsible for providing expert guidance and support to our clients in implementing and maintaining robust information security and data privacy frameworks. You will work closely with cross-functional teams to ensure that our clients adhere to industry standards such as ISO 27001, SOC 2, HIPAA, HITRUST, GDPR, and other compliance and data privacy regulations. Your expertise will help clients achieve compliance, manage risks, and protect sensitive data effectively.
Job Description:
- Compliance Management –
1. Lead and support clients in achieving and maintaining compliance with ISO 27001, SOC 2, HIPAA, HITRUST, and other regulatory and compliance requirements.
2. Conduct risk assessments, gap analysis, and internal audits to identify areas of improvement and non-compliance.
3. Assist in the development and implementation of policies, procedures, and controls to ensure data protection and compliance.
4. Conduct training sessions and workshops to educate clients on compliance requirements and best practices.
- Data Privacy –
1. Provide expert advice on data privacy regulations, including GDPR, DPDPA, and other relevant laws.
2. Develop and implement data privacy frameworks, policies, and practices that align with industry standards.
3. Conduct data protection impact assessments (DPIAs) and manage data breach incidents.
- Risk Management –
1. Assess and manage risks related to information security and data privacy.
2.
Develop risk mitigation strategies and monitor the effectiveness of implemented controls.
3. Collaborate with clients to develop risk management plans and ensure compliance with applicable regulations.
- Audit and Reporting –
- Prepare and present audit reports, compliance assessments, and recommendations to clients.
- Collaborate with internal and external auditors during compliance audits.
- Monitor changes in regulatory requirements and update clients accordingly.
Qualification & Experience:
- Work Experience: 2-4 years.
- Bachelor’s degree in computer science, Information Security, or a related field; advanced certifications (e.g., CISA, CISM, ISO 27001 LA/LI, CISSP) preferred not mandatory.
- 2-4 years of relevant experience in GRC, data privacy, or information security roles.
- Hands-on experience with the implementation or auditing of at least two regulatory standards or frameworks, such as ISO 27001, SOC 2, HIPAA, HITRUST, GDPR, or other compliance frameworks.
- Familiarity with cybersecurity tools and technologies as OneTrust, Archer, ServiceNow GRC etc.
- Proven ability to manage and prioritize multiple projects and deadlines.
- Excellent written and verbal communication skills, with the ability to effectively convey technical information to both technical and non-technical stakeholders.
- Experience in developing and delivering technical presentations and reports.
- Strong analytical and problem-solving skills, with meticulous attention to detail.
- Ability to work independently and as part of a team in a quick-paced, dynamic environment.
Preferred Qualifications:
- Any ISACA certification (CISA, CISM, CRISC, etc), Privacy certification (CIPP, CIPM, etc), ISO 27001 LI/LA is/are good to have.
Consulting Experience: At least 2 years of hands-on experience in a client-facing role focused on Governance, Risk, and Compliance (GRC) or Data Privacy.
📌 -GRC-Sr. Security Analyst- SSL-GGN (India)
🏢 Sharp Group
📍 India