Your work profile
- Lead and support data risk assessments across business applications, databases, and critical information assets.
- Implement and maintain data classification frameworks to identify and protect sensitive, confidential, and regulated data.
- Collaborate with data owners, stewards, and business stakeholders to strengthen data governance practices and accountability.
- Assess and document data lineage, data flows, and data handling processes to identify potential risk exposures.
- Evaluate and recommend data protection controls, including encryption, access management, and Data Loss Prevention (DLP) solutions.
- Monitor compliance with organizational data security policies, standards, and regulatory requirements.
- Utilize GRC platforms (ServiceNow GRC, RSA Archer, or equivalent) to document findings, manage risk registers, and track remediation activities.
- Support regulatory and compliance assessments related to GDPR, GLBA, SEC, FINRA, and other applicable data protection requirements. Perform technology risk assessments and evaluate IT General Controls (ITGCs) across applications, infrastructure, and business processes. Identify gaps in data management, access controls, and security processes and provide practical remediation recommendations.
- Partner with Cyber Security, Privacy, Risk, Audit,
and Technology teams to improve the organization's risk posture. Prepare risk reports, dashboards, and executive summaries for stakeholders and senior management. Assist in policy development, control testing, issue management, and risk monitoring activities. Support internal and external audits by providing evidence, documentation, and remediation status updates.
Key skills required:
1. 3 to 5 years of experience in Data Risk, Information Risk Management, Technology Risk, or IT Audit.
2. Robust understanding of Data Governance frameworks, including Data Ownership, Data Stewardship, Metadata Management, and Data Lineage.
3. Experience implementing and managing Data Classification programs for sensitive and regulated information.
4. Knowledge of Data Protection technologies, including Encryption, Access Management, Privileged Access Controls, and DLP solutions. Hands-on experience with GRC platforms such as ServiceNow GRC, RSA Archer, OpenPages, or equivalent.
5. Working knowledge of regulatory requirements including GDPR, GLBA, SEC, FINRA, CCPA, and other privacy/security regulations.
6. Experience performing Technology Risk Assessments and IT General Controls (ITGC) reviews.
Interested candidates can DM me your updated CV with:
[email protected]
📌 Data Consultant Risk Mandate (Bengaluru)
🏢 WSNE Consulting
📍 Bengaluru