09 Oct
|
SMBC Group
|
India
Responsibilities
(List of duties that are marginal or infrequent.)
- Support monitoring and implementation of privacy, data security and information security controls relevant to personal data processing, storage, transfer, access, retention and disposal.
20%
Maintain control inventories, evidence records and exception trackers.
- Support DPDP and other applicable data protection compliance activities, including operational checklists, control mapping, documentation and remediation follow-up.
20%
Prepare compliance status inputs and maintain supporting documentation for DPO review.
- Conduct or support security-related privacy risk assessments and DPIAs for systems, applications, processes, vendors and technology changes involving personal data.
15%
Record risks, control gaps, mitigating actions, owners and target dates.
- Support data classification, access control, encryption, masking, anonymization, retention, deletion and other technical or procedural data protection controls in coordination with control owners.
15%
Monitor implementation evidence and escalate overdue or unresolved matters.
- Assist in privacy and information security incident response, including initial fact collection, impact assessment support, case documentation, remediation tracking and preparation of DPO updates.
15%
Maintain incident files, chronology, decisions and closure evidence.
- Support third-party privacy and security assessments, due diligence reviews and monitoring of data protection requirements for vendors and service providers.
10%
Maintain assessment results,
exceptions and remediation records.
- Prepare privacy / security metrics, dashboards, control testing results and awareness materials for DPO and governance forums.
5%
Coordinate periodic reporting inputs and training records.
Total
100%
- Knowledge Requirements: Working knowledge of DPDP, GDPR, data privacy principles, data security and information security controls, privacy risk assessment, DPIA / PIA, data classification, retention, access management, encryption, masking, anonymisation, incident management, third-party risk and security governance frameworks.
- Specialist / technical skills: Privacy and security control assessment; GRC and evidence management; data classification and retention; incident documentation; risk and control mapping; technical documentation; dashboard preparation and remediation tracking. Familiarity with ISO 27001, NIST or similar frameworks and privacy / security tools is desirable.
- Behavioural / management skills: Analytical thinking, attention to detail, written and verbal communication, documentation discipline, stakeholder coordination, confidentiality, ownership and ability to work under the guidance of the DPO.
Education & Qualifications: Relevant Graduate or post-graduate qualification. Relevant certifications such as Certified Information Privacy Skilled (CIPP), Certified Information Privacy Manager (CIPM), Certified Information Privacy Technologist (CIPT), Certified Information Systems Security Professional (CISSP), ISO 27001, Security+, or equivalent may be preferred depending on grade.
📌 AVP - Data Protection (Technical) (India)
🏢 SMBC Group
📍 India