Padmi

GRC & Privacy Lead

BangalorePosted 2 months ago
CybersecuritySeniorFull Time; Regular
Apply at Mitigata

Opens the source posting on shine.com

Source description

About the role

View original

We are looking for an experienced GRC and Privacy Lead to drive Governance, Risk, Compliance (GRC), and Data Privacy consulting engagements for a diverse portfolio of enterprise clients. In this highly visible, client-facing leadership role, you will serve as a trusted advisor to CISOs, DPOs, Legal teams, and executive stakeholders while leading a team of consultants delivering complex compliance and privacy programs. You will also play a key role in implementing and optimising Mitigata's proprietary GRC automation platform, helping clients streamline compliance processes, automate evidence collection, and strengthen enterprise risk management. This role combines deep regulatory expertise, consulting excellence, leadership, and technology enablement. The candidate will have responsibilities across the following functions: Client Delivery and Consulting Leadership: Lead multiple GRC and Data Privacy consulting engagements across enterprise clients.Manage end-to-end client delivery while ensuring quality, timelines, and stakeholder satisfaction.Build trusted relationships with executive stakeholders including CISOs, DPOs, Compliance Heads, Legal teams, and Information Security leaders.Develop strategic governance, compliance, and privacy roadmaps aligned to each client's business objectives and risk profile.Serve as the primary escalation point and Subject Matter Expert (SME) for complex regulatory and compliance matters. Team Leadership: Lead, mentor, and develop a team of GRC and Privacy consultants.Allocate work across multiple client engagements while maintaining delivery excellence.Review deliverables, provide technical guidance, and ensure adherence to consulting best practices.Build a high-performing consulting practice through coaching and knowledge sharing. Privacy and Data Protection: Design, implement, and mature enterprise privacy programs aligned with global regulations, including: GDPR, CCPA / CPRA.India's Digital Personal Data Protection Act (DPDPA).Lead key privacy operations including: Data Protection Impact Assessments (DPIAs), Records of Processing Activities (RoPA), Data Subject Access Requests (DSARs), Cross-border data transfer compliance.Monitor emerging global privacy regulations and translate legal requirements into practical operational controls. Governance, Risk and Compliance: Conduct enterprise risk assessments, maturity assessments, compliance reviews, and gap analyses.Lead client readiness programs for certifications and regulatory audits.Support implementation and compliance across industry frameworks including: ISO 27001 SOC 2 NIST Cybersecurity Framework (CSF), HIPAAManage Third-Party Risk Management (TPRM) programs.Coordinate with external auditors and certification bodies during assessments. GRC Automation and Platform Enablement: Lead implementation of Mitigata's GRC automation platform across client environments.Configure and optimise workflows for: Continuous compliance monitoring, Automated evidence collection, Risk register management, and control monitoring.Train internal teams and client stakeholders on platform capabilities and best practices.Collaborate with Product and Engineering teams by sharing customer feedback to enhance future platform capabilities. Requirements: 8+ years of experience in Governance, Risk & Compliance (GRC) and Data Privacy.Minimum 3 years of client-facing consulting or advisory experience.Proven experience managing multiple enterprise clients simultaneously.Demonstrated success leading consulting teams and mentoring professionals.Strong hands-on expertise in global privacy regulations and enterprise compliance programs.Bachelor's degree in Cybersecurity, Information Technology, Information Security, Law, Business, or a related discipline. Good to Have: Proven consulting experience managing enterprise GRC and privacy engagements.Strong leadership with the ability to manage teams and multiple client portfolios.Deep understanding of global privacy regulations and security frameworks.Ability to bridge legal, compliance, and technology requirements.Passion for delivering strategic value while driving operational excellence through automation. Required Certifications: Must hold at least one (preferably more) certification: CISA, CISM, CRISC, CISSP.ISO 27001 Lead Auditor/Implementer.CIPP/E, CIPP/US, CIPP/A (Certified Information Privacy Professional).CIPM (Certified Information Privacy Manager).CIPT (Certified Information Privacy Technologist).CDPSE (Certified Data Privacy Solutions Engineer).Highly preferred additional GRC certifications: CISA, CISM, CRISC, CISSP, or ISO 27001 Lead Auditor/Implementer. Skills and Competencies: Client Relationship Management: High emotional intelligence with the ability to build trust, manage client expectations, and navigate complex organisational dynamics.Tech-Savvy: Comfortable working with enterprise automation platforms and bridging the gap between legal/privacy

One address, no account. We’ll tell you when matching roles go live.