T&T | Consultant | Governance and Policy Development | Mumbai | Cyber Strategy & Transformation
Deloitte
Deloitte
Join a leading cybersecurity team focused on protecting valuable organizational assets and enabling new opportunities through robust cyber risk management. We specialize in embedding cyber risk into strategic development for effective information and technology risk management. Explore the cutting edge of Cybersecurity with us.
This role is for a motivated Consultant with 2-4 years of experience in Third-Party Risk Management (TPRM), privacy, and vendor risk consulting. You will play a key part in delivering client engagements, assisting in the implementation of privacy and risk management frameworks, and ensuring compliance with industry standards. Strong analytical and communication abilities are essential, alongside a solid understanding of data privacy, TPRM processes, and GRC concepts.
Support DPDPA, GDPR, and other data privacy compliance initiatives. Conduct assessments including Applicability, Gap, and Privacy Maturity. Assist with Data Protection Impact Assessments (DPIAs), Business Impact Assessments (BIAs), Data Flow Mapping, and Records of Processing Activities (RoPA). Review processes to identify privacy risks associated with personal data. Develop and refine privacy policies, standards, and procedures. Manage consent, data retention, classification, and data subject rights processes. Track remediation activities and prepare compliance reports.
Enhance Third-Party Risk Management (TPRM) frameworks. Perform vendor due diligence and security/privacy assessments. Review vendor questionnaires and evidence. Evaluate vendor risks and propose mitigation strategies. Support contract reviews for security and privacy aspects. Track third-party risk remediation and maintain assessment records.
Assist with compliance assessments against DPDPA, ISO/IEC 27001, ISO/IEC 27701, and other regulations. Support the creation and review of governance documents and policies. Conduct control assessments and identify compliance gaps. Prepare assessment reports, presentations, and client deliverables. Engage in client workshops and stakeholder discussions. Gather and analyze business and technical information. Manage project documentation, meeting minutes, trackers, and status reports. Aid in project planning and ensuring timely delivery of workstreams. Collaborate with teams for high-quality project execution.
A Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field is required. Candidates should possess 2-4 years of relevant experience in Third-Party Risk Management (TPRM), privacy, and vendor risk consulting. Essential skills include a strong understanding of data privacy principles, TPRM processes, and Governance, Risk, and Compliance (GRC) concepts. Excellent analytical and communication skills are also critical for success in this role.
Deloitte
Cybersecurity