Job Title: Consultant | CyberArk Operations | Mumbai | Digital Privacy & Trust | Data Protection & Compliance
Job description
Job Title: Consultant – Data Privacy & Trust
Experience: 3+ Years
Location: As per business requirement
Role Overview
The Data Privacy & Trust professional will be responsible for driving the organization’s data protection, privacy governance, and trust frameworks. This role will work closely with IAM, DAM, cybersecurity, legal, and business teams to ensure secure handling of sensitive data, regulatory compliance, and strong privacy-by-design practices across systems and applications.
Key Responsibilities
- Lead the design, implementation, and governance of data privacy and trust frameworks across enterprise environments.
- Work closely with IAM, DAM, PAM, and data security teams to ensure secure identity-based and data-centric access controls.
- Define and enforce data classification, access governance, and data lifecycle management policies.
- Support implementation and operations of:
- Identity & Access Management (IAM)
- Database Activity Monitoring (DAM)
- Data Loss Prevention (DLP)
- Privileged Access Management (PAM)
- Perform Data Protection Impact Assessments (DPIA) and privacy risk assessments.
- Ensure compliance with relevant regulations such as:
- DPDP Act (India)
- GDPR, ISO 27701, ISO 27001
- Industry regulations (BFSI, Healthcare, Telecom as applicable)
- Define and monitor privacy KPIs, KRIs, and compliance metrics.
- Drive incident response for data breaches, including forensic coordination, regulatory reporting support, and remediation.
- Support audits (internal/external), regulatory inspections, and client assessments.
- Conduct privacy awareness and trust-building programs for employees and stakeholders.
- Work with application teams to ensure privacy-by-design and security-by-design across digital platforms.
Required Skills & Experience
- 3+ years of experience in Data Privacy, Data Protection, or Information Security.
- Strong hands-on knowledge of:
- IAM (RBAC, ABAC, SSO, MFA, IGA)
- DAM (Database monitoring, anomaly detection, audit trails)
- PAM, DLP, and Encryption technologies
- Strong understanding of:
- Data classification frameworks
- Access governance
- Secure data storage and transmission
- Experience with privacy risk assessments, audits, and regulatory reporting.
- Good understanding of cloud data security (AWS, Azure, GCP).
- Ability to work with legal, compliance, IT, and business stakeholders.
Desired qualifications
Bachelors or Masters in a technical discipline Computer Science
/ Computer Engineering / any equivalent bachelor’s or Masters in Information Security Domain.
Minimum of 3 years of relevant experience out of which at least 2 years in various technology tracks in ‘Similar Projects’ or OEM like IBM security verify, Okta Identity Cloud, Ping Identity, and SailPoint IdentityIQ.
Advanced Certification in proposed tools along with Security Certification like CEH.