11 Aug
|
Meta Infotech
|
Mumbai
11 Aug
Meta Infotech
Mumbai
Experience
812 years in Information Security, Data Protection, Cyber Security Governance, Risk & Compliance, or related domains.
Role Summary
The Senior Consultant will support the design, enhancement, and continuous improvement of the organization's Data Protection Governance capability. The role is responsible for developing governance frameworks, operating models, control libraries, maturity assessment methodologies, and executive reporting aligned with enterprise security standards and regulatory requirements. The individual will also lead maturity assessments across business units and technology platforms and provide strategic recommendations to improve the organization's Data Protection posture.
Data Protection Governance
- Review and assess existing Data Protection governance frameworks to identify gaps and improvement opportunities.
- Develop and maintain enterprise Data Protection Governance Frameworks aligned with business objectives, regulatory requirements, and industry best practices.
- Design governance structures, operating models, stakeholder engagement models, and decision-making forums.
- Define and maintain roles, responsibilities, ownership models, and RACI matrices.
- Develop governance documentation, standards mapping, procedures, and supporting artefacts.
Control Library & Compliance Framework
- Develop and maintain a comprehensive Data Protection Control Library aligned with enterprise Data Security Standards, Cryptography Standards, regulatory requirements, and industry frameworks.
- Define control objectives, implementation guidance, success criteria, testing methodologies,
evidence requirements, and assessment questionnaires.
- Establish maturity scoring models and control effectiveness criteria.
- Map controls to regulatory obligations and internal security standards.
- Periodically review and update the control library.
Maturity Assessments
- Develop risk-based methodologies for Data Protection maturity assessments.
- Prepare annual and quarterly assessment plans.
- Conduct maturity assessments across applications and business divisions.
- Review evidence and validate implementation of security controls.
- Identify gaps and provide remediation recommendations.
Dashboard & Executive Reporting
- Define KPIs, KRIs, compliance metrics, and governance scorecards.
- Design executive dashboards and maturity reporting.
- Prepare management reports for senior leadership.
- Present findings and recommendations to governance forums.
Stakeholder Management
- Conduct workshops with business, technology, risk, compliance, and security teams.
- Collaborate with control owners and provide strategic advisory.
Required Skills
- Robust experience in Data Protection Governance.
- Experience developing security control frameworks and control libraries.
- Knowledge of data protection regulations and compliance requirements.
- Experience conducting governance reviews and maturity assessments.
- Excellent documentation, stakeholder management, and executive communication skills.
Preferred Technical Knowledge
- Microsoft Purview Information Protection
- Microsoft Purview DLP
- Information Classification & Labeling
- Encryption & Key Management
- Information Rights Management (IRM)
- Cloud Security (Azure/AWS)
- Power BI or equivalent dashboarding tools
Knowledge of Standards & Frameworks
- ISO/IEC 27001 & ISO 27002
- NIST Cybersecurity Framework
- CIS Controls
- Cryptography Standards
- GDPR, DORA, DPDP Act (India) or equivalent
Preferred Certifications
- CISSP
- CISM
- CRISC
- ISO 27001 Lead Implementer/Auditor
- Microsoft SC-400, SC-100, SC-900
- TOGAF or SABSA (preferred)
Key Competencies
- Strategic thinking
- Governance and policy development
- Analytical problem-solving
- Executive communication
- Stakeholder management
- Workshop facilitation
- Documentation and report writing
- Consulting and advisory mindset
Ideal Candidate Profile
The ideal candidate should have prior experience delivering enterprise-scale Data Protection Governance or Cyber Security Governance consulting engagements, preferably within a global financial services or regulated environment. They should have hands-on experience developing governance frameworks, control libraries, maturity assessment methodologies, executive dashboards, and leading stakeholder workshops.
📌 Senior Consultant - Data Protection (Mumbai)
🏢 Meta Infotech
📍 Mumbai