09 Sep
|
Securisti Consulting
|
Mumbai
09 Sep
Securisti Consulting
Mumbai
Immediate joining Requirement - Securisti Consulting LLP
Securisti Consulting LLP is a rapidly growing consulting company that believes in democratizing cybersecurity through an unwavering commitment to “Bespoke Security” and vision of making “Cyber Security for All” a reality. Securisti provides a complete suite of cybersecurity services such as implementation and sustenance of ISO 27001 & 22301, Managed GRC, Cyber Risk monitoring, Third Party Risk Management, Cybersecurity framework design and implementation (IRDAI / RBI / PFRDA / SEBI), vCISO services, Table Top exercises and IR simulations, Managed Incident Response, Technical Vulnerability Management and Security testing.
For more details visit: https://securisti.com/
We currently are expanding our GRC operations and have multiple requirements for candidates interested in switching to or already having experience of GRC.
: Data Privacy / DPDPA Specialist
Experience : 2–3 years of relevant experience in Data Privacy, Data Protection, Compliance, or Information Governance.
Job Overview
We are looking for a Data Privacy / DPDPA Specialist with 2–3 years of experience to support the organization in implementing and maintaining data privacy and protection requirements. The ideal candidate should have sound knowledge of the Digital Personal Data Protection Act (DPDPA), applicable Rules, privacy principles, data mapping, Records of Processing Activities (RoPA), consent management, Privacy Impact Assessments (PIA), and data flows.
The candidate will work closely with business, legal, compliance, IT, security, and other stakeholders to identify privacy risks and ensure that personal data is processed in accordance with applicable regulatory and organizational requirements.
Key Responsibilities
- Develop a strong understanding of the Digital Personal Data Protection Act (DPDPA) and associated Rules and support organizational compliance initiatives.
- Understand and apply key data privacy and protection principles across business processes.
- Support the creation, review,
and maintenance of Records of Processing Activities (RoPA).
- Perform data discovery and data mapping to identify personal data, processing purposes, data subjects, systems, applications, recipients, and retention requirements.
- Develop and document process flows and data flows, including identification of data collection, processing, storage, sharing, transfer, and deletion points.
- Support the design and implementation of consent architecture, including consent collection, management, withdrawal, tracking, and auditability.
- Conduct and support Privacy Impact Assessments (PIA) / privacy risk assessments for new and existing processes, products, applications, and projects.
- Identify privacy risks and assist in developing appropriate mitigation and remediation plans.
- Collaborate with business and technology teams to embed Privacy by Design principles into processes, products, and applications.
- Support privacy compliance assessments, audits, questionnaires, and evidence collection.
- Assist in reviewing data processing activities against applicable privacy requirements and internal policies.
- Maintain privacy documentation, process inventories, data-flow diagrams, assessment records, and compliance trackers.
- Support the development and implementation of privacy policies, procedures, standards, and controls.
- Monitor regulatory developments relating to DPDPA and data privacy and communicate relevant changes to stakeholders.
- Work with cross-functional teams to support data subject rights/grievance handling, consent management, data retention, breach response, and other privacy-related activities as applicable.
Required Skills & Knowledge :
- Good working knowledge of the Digital Personal Data Protection Act (DPDPA) and DPDPA Rules.
- Strong understanding of data privacy principles and privacy governance.
- Hands-on understanding of RoPA / processing activity inventories.
- Ability to create and understand business process flows and personal data flows.
- Understanding of data mapping and data lineage concepts.
- Knowledge of consent lifecycle and consent architecture.Experience or understanding of conducting Privacy Impact Assessments (PIA) / Data Protection Impact Assessments (DPIA).
- Understanding of Privacy by Design principles.
- Valuable understanding of personal data lifecycle: collection → processing → storage → sharing → retention → deletion.
- Familiarity with privacy risk identification and control implementation.
- Good documentation, analytical, and stakeholder-management skills.
- Ability to work with both business and technical teams and translate privacy requirements into practical controls.
Preferred Qualifications :
- Bachelor's degree in Law, Technology, Information Security, Risk & Compliance, Business, or a related discipline.
- Certifications such as CIPP/E, CIPM, CIPT, CDPO, or other relevant privacy/data protection certifications will be an advantage.
- Exposure to global privacy regulations such as GDPR will be an added advantage.
- Experience working with GRC, privacy management, data discovery, consent management, or data-mapping tools will be preferred.
Experience Profile:
2–3 years of relevant experience in one or more of the following areas:
- Data Privacy / Data Protection
- DPDPA / GDPR Compliance
- Privacy Governance
- Data Protection ConsultingGRC / Risk & Compliance
- Information Governance
- Privacy Assessments and Data Mapping
Key Competencies
- Data Privacy & Protection
- DPDPA Compliance
- RoPA & Data Mapping
- Process & Data Flow Analysis
- Consent Management / Architecture
- PIA / DPIA
- Privacy by Design
- Privacy Risk Assessment
- Regulatory Compliance
- Stakeholder Management
- Documentation & Analytical Skills
📌 Governance Risk and Compliance Associate (Mumbai)
🏢 Securisti Consulting
📍 Mumbai