03 Sep
|
Perydot
|
Mumbai
Position Title: GRC & Data Privacy Consultant
Location: Mumbai
Experience: 7+ years (BIG4 experience is an advantage)
Qualification: BE / BTech / MCA in IT or Computer Science
Certifications (Preferred): CISA, CISSP, CRISC, CISM, ISO 27001 LA/LI, Data Privacy certifications (GDPR/DPA).
About the Role
We are seeking an experienced Manager - GRC & Data Privacy Consultant to lead Governance, Risk, Compliance (GRC), Information Security, and Data Privacy engagements for our clients. The ideal candidate will possess strong expertise in cybersecurity, risk management, regulatory compliance, and privacy frameworks, with proven experience in implementing enterprise-wide governance and privacy programs.
This role requires a combination of advisory, implementation, project management, and client-facing consulting capabilities. The candidate will work closely with client leadership teams to establish robust governance structures, compliance frameworks, and privacy programs aligned with business and regulatory requirements.
Key Responsibilities
Governance, Risk & Compliance (GRC)
- Lead and coordinate end-to-end implementation of Governance, Risk, and Compliance (GRC) frameworks for mid-sized and large organizations.
- Conduct enterprise risk assessments, compliance assessments, gap analyses, and maturity assessments.
- Develop and implement information security governance frameworks, policies, standards, procedures, and control libraries.
- Support organizations in achieving compliance with standards and regulations including ISO 27001, ISO 27701, ISO 22301, NIST CSF, PCI DSS, SOC 2, RBI, SEBI, and other applicable regulatory requirements.
- Prepare and deliver client reports, risk dashboards, executive presentations, and remediation roadmaps.
- Act as the primary point of contact for client engagements and manage stakeholder communications throughout project lifecycles.
- Assist in proposal development, solution design, effort estimation, and RFP responses for GRC and privacy consulting opportunities.
- Mentor and guide junior consultants, ensuring high-quality project delivery and capability development.
Data Privacy & DPDPA Implementation
- Lead enterprise-wide implementation and operationalization of the Digital Personal Data Protection (DPDP) Act, 2023 and applicable DPDP Rules.
- Interpret regulatory requirements and translate them into practical business controls,
privacy governance frameworks, policies, procedures, and operating models.
- Conduct DPDPA readiness assessments, gap assessments, compliance reviews, and implementation engagements.
- Design, develop, and implement Data Privacy Policies, Privacy Notices, Consent Management frameworks, and Standard Operating Procedures (SOPs).
- Establish and operationalize processes for Data Principal Rights management, grievance redressal, data retention, and personal data lifecycle management.
- Design and implement consent collection, withdrawal, tracking, and consent lifecycle management mechanisms in accordance with regulatory requirements.
- Evaluate and support implementation of Consent Management Platforms (CMPs) and privacy technology solutions.
- Lead data discovery, data inventory, data classification, Records of Processing Activities (RoPA), and Data Flow Mapping initiatives.
- Conduct Privacy Impact Assessments (PIA), Data Protection Impact Assessments (DPIA), and Privacy-by-Design reviews for recent products, services, applications, and business processes.
- Support implementation and governance of cookie consent management solutions, cookie policies, and periodic website privacy compliance reviews.
- Review cross-border personal data transfers and assist in drafting privacy clauses, Data Processing Agreements (DPAs), and data-sharing agreements.
- Conduct privacy-focused Third-Party Risk Assessments (TPRA) and identify mitigation measures for vendor and outsourcing risks.
- Establish privacy incident and personal data breach management processes, including investigation, reporting, regulatory notification, and corrective actions.
- Conduct periodic privacy audits, compliance assessments, and privacy maturity assessments against DPDPA, GDPR, ISO 27701, and NIST Privacy Framework requirements.
- Collaborate with Legal, Information Security, Compliance, Technology, and Business stakeholders to ensure sustainable privacy compliance and governance.
Client Advisory & Consulting
- Advise client leadership teams on governance, risk, compliance, cybersecurity, and privacy strategy.
- Facilitate workshops, awareness sessions, and stakeholder discussions related to information security and privacy compliance.
- Support clients in establishing sustainable governance and operational models for long-term compliance management.
- Provide strategic recommendations and implementation guidance aligned with industry best practices and evolving regulatory requirements.
Required Skills & Competencies
- Strong understanding of Governance, Risk, Compliance (GRC), Information Security, and Data Privacy principles.
- Hands-on experience implementing frameworks such as ISO 27001, ISO 27701, NIST, PCI DSS, SOC 2, and related regulatory requirements.
- Strong knowledge of the Digital Personal Data Protection (DPDP) Act, 2023, DPDP Rules, GDPR, and global privacy regulations.
- Experience conducting DPDPA implementation projects, privacy assessments, DPIAs, privacy governance initiatives, and compliance reviews.
- Practical knowledge of Consent Management, RoPA management, Data Flow Mapping, Data Discovery, Data Classification, and Data Lifecycle Management.
- Experience with privacy management platforms, consent management solutions, and privacy automation tools.
- Strong understanding of third-party risk management, outsourcing risk assessments, and privacy-related contractual requirements.
- Experience in security audits, compliance audits, risk assessments, and control effectiveness reviews.
- Excellent communication, stakeholder management, presentation, and consulting skills.
- Strong analytical, documentation, project management, and report-writing capabilities.
- Ability to manage multiple client engagements simultaneously while maintaining quality and timelines.
Preferred Certifications
- CISA, CISM, CRISC
- ISO 27001 Lead Auditor / Lead Implementer
- ISO 27701 Lead Implementer / Lead Auditor
- Certified Data Privacy certifications (CIPP/E, CIPM, CDPO, DPDPA Practitioner, GDPR certifications, etc.)
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 GRC & Data Privacy Consultant (Mumbai)
🏢 Perydot
📍 Mumbai