T&T | Cyber CST | Consultant | Governance and Policy Development | Mumbai | (Mumbai, IN)
Deloitte
Deloitte
Join a leading cybersecurity team focused on safeguarding valuable assets and preventing cyberattacks. We help organizations build resilience and manage cyber risk effectively, enabling them to seize new opportunities while embedding security into their strategic development. Explore a career dedicated to managing information and technology risks with cutting-edge solutions.
This role involves supporting privacy and vendor risk consulting engagements, assisting clients in establishing robust privacy and risk management frameworks, and ensuring adherence to relevant regulatory and industry standards. A strong grasp of data privacy principles, third-party risk management, and GRC concepts, coupled with excellent analytical and communication skills, is essential for success.
Key responsibilities include supporting DPDPA, GDPR, and other data privacy compliance initiatives. Conduct applicability, gap, and privacy maturity assessments, and assist with DPIAs, BIAs, data flow mapping, and RoPA.
Review business processes to identify privacy risks and personal data processing activities. Develop privacy policies, standards, procedures, and governance documentation. Support consent management, data retention, classification, and data subject rights processes. Track remediation efforts and prepare privacy compliance reports.
Enhance Third-Party Risk Management (TPRM) frameworks through due diligence and security/privacy assessments of vendors. Evaluate vendor risks, review contracts from a security and privacy standpoint, and maintain assessment records. Assist in compliance assessments against DPDPA, ISO/IEC 27001, ISO/IEC 27701, and other regulations.
Support the development of governance documents and perform control assessments. Prepare assessment reports, presentations, and client deliverables. Engage in client workshops, gather business and technical information, and prepare project documentation. Collaborate with cross-functional teams for high-quality project execution.
We are seeking a motivated and detail-oriented Consultant with 2–4 years of experience in Third-Party Risk Management (TPRM). A solid understanding of data privacy principles, third-party risk management processes, and governance, risk, and compliance (GRC) concepts is required.
Essential skills include supporting DPDPA, GDPR, and data privacy compliance. The role involves conducting various assessments (Applicability, Gap, Privacy Maturity, DPIA, BIA), data mapping, and managing RoPA. Reviewing business processes for privacy risks and assisting in the development of privacy policies and procedures are critical.
Experience in TPRM frameworks, vendor due diligence, security/privacy assessments, and contract reviews is necessary. Knowledge of compliance assessments against DPDPA, ISO/IEC 27001, and ISO/IEC 27701 is also required. The position demands strong analytical and communication skills for client interactions and reporting.
Candidates should possess a Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field. This is an onsite position located in Mumbai, IN.
Deloitte
Information Technology & Services