Stand out for this role — generate a tailored resume and cover letter in about a minute.
Ubique Systems in Mumbai seeks a Privacy, Compliance and Governance Operations Specialist to monitor compliance with privacy policies and data protection laws. You will conduct PIAs/DPIAs, map data flows and lead policy development.
You'll translate complex regulatory needs into technical specs, work with engineering on privacy controls, and support audits. Strong SDLC knowledge and encryption experience are required.
Compliance Monitoring: Monitor and ensure organizational compliance with internal privacy policies, procedures, and external data protection laws.
Monitor and coordinate to ensure compliance with company policies and regulations -DPDP 2023, ISO 27001 , HIPPA ,Internal Audit , CFR 21 ,ITGC - Support GMP audit
Risk Assessments: Conduct Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) to identify and mitigate privacy risks in new products, services, or vendor relationships.
Policy Development: Develop, update, and implement comprehensive privacy policies, data retention schedules, and data handling procedures.
Data Subject Rights: Manage and respond to data subject access requests (DSARs), including deletion, access, and portability requests within regulatory timelines.
Training & Awareness: Develop and conduct company-wide privacy training sessions to educate employees on data protection obligations.
Incident Response: Support the security team in investigating, managing, and reporting potential data breaches or privacy incidents.
Data Mapping: Maintain a detailed record of processing activities (ROPA), data inventory, and data flow mapping.
Privacy by Design: Embed privacy controls into the development life cycle of software applications and products.
Technical Implementation: Build and maintain privacy-enhancing technologies (PETs) such as pseudonymization, anonymization, and encryption services.
Data Governance: Implement and manage data mapping, data inventory, and data lifecycle management tools.
Cross-Functional Collaboration: Act as a technical liaison between legal/compliance teams and software engineers.
Incident Response: Assist in evaluating and responding to data protection incidents and potential breaches.
Tracking , Reporting , Follow-up and presenting Management Dash boards.
Responsibilities not limited to above and aligned with organisations and department's deliverables.
Education: Bachelor's in Computer Science, Information Systems, Privacy Engineering, Governance and Audit or a related technical field.
Experience: 3-5+ years of experience in Relevant domains and Technical Skills:
Strong understanding of software development lifecycle (SDLC).
Proficiency in languages like Python, Java, or SQL ,API integration. Familiarity with cloud platforms.
Hands-on experience with encryption tools, data mapping, and access control systems.
Knowledge of Regulations: In-depth knowledge of DPDP,GDPR, CCPA/CPRA, and other privacy frameworks.
Communication: Excellent ability to translate complex legal concepts into technical specifications.
Certified Information Privacy Technologist (CIPT) preferred.
GRC , ISO 27001 IA / LA optional
Experience in data governance frameworks and tool eg Data Discovery, Data Ageing and retention, Data Segregation, Consent management System, Cookie Consent
GRC tools and software, Risk assessment and management, Regulatory compliance, Internal audit, Policy development, Analytical skills, Communication skills, Problem-solving, Project management