Associate Director – Privacy & GRC
HybridMumbai, Maharashtra, India
Job Summary
Lead and oversee client-specific privacy, GRC, and data protection programs by assessing controls, identifying gaps, and transforming roadmaps. Manage advanced assessments including DPIAs, PIAs, RoPA, and risk evaluations while providing advisory on GDPR, CCPA, DPDP Act, and other global regulations. Develop governance frameworks, support incident response planning, and conduct third-party risk assessments to ensure audit readiness. Collaborate with senior stakeholders such as CISOs and DPOs to deliver scalable solutions aligned with ISO 27001, NIST, and SOC 2 standards. Join a high-growth consulting firm focused on enterprise-level transformation and regulatory expertise.
Required Qualifications
- 7+ years of hands-on experience in privacy, data protection, cybersecurity, or GRC consulting
- Strong understanding of international privacy laws including GDPR, CCPA/CPRA, DPDP Act, PDPL, and global frameworks
- Solid grasp of ISO 27001, ISO 27701, NIST CSF, SOC 2, and other governance/control frameworks
- Experience managing enterprise-level privacy programs, GRC initiatives, ISMS/PIMS implementations, and audits
- Familiarity with privacy and GRC tools (e.g., Securiti.ai, OneTrust, BigID)
- Excellent communication skills
- Leadership capability
- Strong stakeholder management
- A mindset that is strategic, solution-oriented, collaborative, and impact-driven
Desired Qualifications
- Certifications such as CIPP/E, CIPM, CIPT, ISO 27001 LA/LI (preferred)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.