Advertisement
in-feed
Define and maintain enterprise data protection policies, standards, guidelines, and control frameworks.
- Lead efforts to uplift existing documentation for data classification, data loss prevention (DLP), encryption, access controls, and retention.
- Develop governance operating models, RACI matrices, and governance councils for data protection accountability.
- Establish end-to-end policy lifecycle processes—creation, review, approval, communication, and compliance monitoring.
- Ensure alignment of data protection policies with global regulations, including GDPR, CCPA, and SEBI.
- Work with business units and global offices to adapt policies to local data protection and privacy regulations.
- Act as a trusted advisor to business lines, IT, risk, and compliance teams on data protection best practices and policy adherence.
- Support business-aligned implementation of policies through training, awareness, and operational guidance.
- Recommend remediation actions, policy controls, and prioritization strategies to address governance gaps.
- Partner with data protection implementation teams, including MIP, BigID, DLP, and IRM, to ensure policies translate into enforceable controls.
- Promote synergy between governance and automation by aligning classification taxonomies, retention labels, and rights management policies.
Requirements
- 4–6 years of experience in data protection and security governance consulting in an enterprise or regulated industry.
- Demonstrated ability to design and lead data protection programs, including policy, process, and standards development.
- Strong understanding of data classification, access control models, retention, encryption, and information lifecycle.
- Familiarity with Microsoft Purview, BigID, Varonis, Symantec DLP, Forcepoint, or OneTrust for alignment purposes.
- Knowledge of GDPR, CCPA, DORA, SEBI, NIST, and ISO 27001.
- Prior experience in consulting, advisory, or risk management roles with cross-functional stakeholder engagement.