Job Title:  Data risk Consultant | Assurance - Tech Advisory | Bengaluru | Controls

Data risk Consultant | Assurance - Tech Advisory | Bengaluru | Controls
Job requisition ID : 108034 
Location: Bengaluru
Entity: Deloitte South Asia LLP 

The team

The Data Risk team is seeking experienced Data Risk Consultants to support enterprise data governance, data protection, and regulatory compliance initiatives. The ideal candidate will possess strong knowledge of data classification, risk management, governance frameworks, and technology risk controls to help organizations identify, assess, and mitigate data-related risks.

Your work profile

  • Lead and support data risk assessments across business applications, databases, and critical information assets.
  • Implement and maintain data classification frameworks to identify and protect sensitive, confidential, and regulated data.
  • Collaborate with data owners, stewards, and business stakeholders to strengthen data governance practices and accountability.
  • Assess and document data lineage, data flows, and data handling processes to identify potential risk exposures.
  • Evaluate and recommend data protection controls, including encryption, access management, and Data Loss Prevention (DLP) solutions.
  • Monitor compliance with organizational data security policies, standards, and regulatory requirements.
  • Utilize GRC platforms (ServiceNow GRC, RSA Archer, or equivalent) to document findings, manage risk registers, and track remediation activities.
  • Support regulatory and compliance assessments related to GDPR, GLBA, SEC, FINRA, and other applicable data protection requirements.
  • Perform technology risk assessments and evaluate IT General Controls (ITGCs) across applications, infrastructure, and business processes.
  • Identify gaps in data management, access controls, and security processes and provide practical remediation recommendations.
  • Partner with Cyber Security, Privacy, Risk, Audit, and Technology teams to improve the organization's risk posture.
  • Prepare risk reports, dashboards, and executive summaries for stakeholders and senior management.
  • Assist in policy development, control testing, issue management, and risk monitoring activities.
  • Support internal and external audits by providing evidence, documentation, and remediation status updates.

Key skills required: 

  • 3 to 5 years of experience in Data Risk, Information Risk Management, Technology Risk, or IT Audit.
  • Strong understanding of Data Governance frameworks, including Data Ownership, Data Stewardship, Metadata Management, and Data Lineage.
  • Experience implementing and managing Data Classification programs for sensitive and regulated information.
  • Knowledge of Data Protection technologies, including Encryption, Access Management, Privileged Access Controls, and DLP solutions.
  • Hands-on experience with GRC platforms such as ServiceNow GRC, RSA Archer, OpenPages, or equivalent.
  • Working knowledge of regulatory requirements including GDPR, GLBA, SEC, FINRA, CCPA, and other privacy/security regulations.
  • Experience performing Technology Risk Assessments and IT General Controls (ITGC) reviews.