Job Title:  Consultant | Governance and Policy Development | Mumbai | Cyber Strategy & Transformation

Consultant | Governance and Policy Development | Mumbai | Cyber Strategy & Transformation
Job requisition ID : 111169 
Location: Mumbai
Entity: Deloitte Touche Tohmatsu India LLP 

The Team  

 

         Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity  

 

 

Your Work Profile

 

We are looking for a motivated and detail-oriented Consultant with 2–4 years of experience Third-Party Risk Management (TPRM). The candidate will support the delivery of privacy and vendor risk consulting engagements, assist clients in implementing privacy and risk management frameworks, and contribute to compliance with applicable regulatory and industry standards.

The ideal candidate should possess a good understanding of data privacy principles, third-party risk management processes, and governance, risk, and compliance (GRC) concepts, along with strong analytical and communication skills.

 

Key Required Skills:

 

  • Support DPDPA, GDPR, and other data privacy compliance and implementation engagements.
  • Conduct Applicability Assessments, Gap Assessments, and Privacy Maturity Assessments.
  • Assist in conducting Data Protection Impact Assessments (DPIAs), Business Impact Assessments (BIAs), Data Flow Mapping, and Records of Processing Activities (RoPA).
  • Review business processes to identify personal data processing activities and privacy risks.
  • Assist in developing privacy policies, standards, procedures, notices, and governance documentation.
  • Support implementation of consent management, data retention, data classification, and data subject rights processes.
  • Track remediation activities and assist in preparing privacy compliance reports.Third-Party Risk Management (TPRM)
  • Support the implementation and enhancement of Third-Party Risk Management (TPRM) frameworks.
  • Conduct vendor due diligence and third-party security/privacy assessments.
  • Review vendor questionnaires and supporting evidence.
  • Assist in evaluating vendor risks and recommending mitigation measures.
  • Support contract reviews from an information security and privacy perspective.
  • Track third-party risk remediation activities and maintain assessment records.Governance, Risk & Compliance (GRC)
  • Assist in compliance assessments against DPDPA, ISO/IEC 27001, ISO/IEC 27701, and other applicable regulatory requirements.
  • Support the development and review of governance documents, policies, and standards.
  • Perform control assessments and identify compliance gaps.
  • Prepare assessment reports, presentations, and client deliverables.
  • Participate in client workshops, interviews, and stakeholder discussions.
  • Gather and analyze business and technical information.
  • Prepare project documentation, meeting minutes, trackers, and status reports.
  • Support project planning and timely delivery of assigned workstreams.
  • Collaborate with cross-functional teams to ensure high-quality project execution.
  • Bachelor’s degree in Computer Science, Information Security, Engineering, or related field.