24 Sep
|
Nangia u0026
|
New Delhi
24 Sep
Nangia u0026
New Delhi
> Qualification B. Tech / BCA / M. Tech / MCA in Computer Science or equivalent Experience 2-4 years of experience in GRC, cybersecurity, data privacy, risk advisory, information security, or audit/consulting
Key responsibilities:
- Execute GRC, cybersecurity, information security, data privacy, risk, and regulatory compliance assessments.
- Support clients in assessing and implementing requirements under Indias DPDP Act & Rules, GDPR, and other applicable data protection regulations.
- Conduct ISO/IEC 27001:2022, ITGC, information security, risk, control, and third-party/vendor assessments.
- Assess privacy and security controls across applications, infrastructure, business processes, cloud environments, and third-party service providers.
- Conduct stakeholder interviews, process walkthroughs, evidence reviews, control testing, and gap assessments.
- Develop and/or review Data Inventories, Records of Processing Activities (RoPA), Data Flow Diagrams (DFDs), Data Protection Impact Assessments (DPIAs), privacy notices, policies, SOPs, and privacy/security governance frameworks.
- Assess requirements relating to consent management, data principal/data subject rights, data retention and deletion, personal data breach management, cross-border data transfers, and Privacy by Design.
- Review vendor contracts, Data Processing Agreements (DPAs), outsourcing arrangements, and third-party privacy/security controls.
- Support privacy and security risk assessments, including identification, evaluation, and prioritisation of risks.
- Prepare audit observations,
risk registers, remediation plans, compliance trackers, assessment reports, and management presentations.
- Support clients with implementation, remediation, closure of identified gaps, and ongoing compliance activities.
- Coordinate with business, IT, cybersecurity, legal, compliance, procurement, and other stakeholders to drive closure of identified requirements.
Preferred Profile:
- Practical experience in Data Privacy / DPDP / GDPR assessments or implementation projects will be preferred.
- Valuable understanding of DPDP Act & Rules, GDPR, ISO/IEC 27001:2022, information security controls, risk management, and third-party risk management.
- Exposure to regulatory frameworks such as RBI, SEBI, IRDAI, CERT-In, or other sector-specific requirements will be an advantage.
- Relevant certifications such as CISA, ISO 27001 Lead Auditor/Implementer, CIPM, CIPP, CDPSE, or equivalent will be an advantage.
- Strong analytical, documentation, report-writing, communication, and stakeholder-management skills.
- Ability to independently manage multiple client deliverables and work effectively with business, IT, cybersecurity, legal, compliance, and senior management teams.
- Willingness to travel to client locations, as required.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 GRC & Data Privacy Consultant (New Delhi)
🏢 Nangia u0026
📍 New Delhi