GRC & Data Privacy Analyst

Hugohub

Hyderabad

On-site

INR 1,200,000 - 1,800,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Hugohub in Hyderabad, India seeks a detail-oriented GRC & Data Privacy Analyst to join its security team and lead privacy and risk programs. You will ensure operations stay compliant with GDPR, PDPA, and related standards while identifying and mitigating risks across the organization.

You will drive governance, risk assessments, data mapping, DSAR coordination, audits, and training, translating regulatory changes into actionable technical requirements for IT and product teams.

Qualifications

  • 8 - 10 years in GRC, Information Security, or IT Audit, with at least 2–4 years specifically focused on Data Privacy.
  • Certifications (Preferred): CISA, CRISC, or CISM.
  • Technical Skills: Familiarity with GRC tools (Sprinto) and a solid understanding of cloud security (AWS).
  • Regulatory Knowledge: Deep understanding of GDPR, PDPA, and industry standards like ISO 27001, SOC 2 and Singapore MAS

Responsibilities

  • Governance & Risk Management: Framework Alignment, Risk Assessments, Policy Management, Third-Party Risk Management.
  • Data Privacy Implementation: PIAs/DPIAs, Data Mapping, DSAR, Compliance Monitoring.
  • Compliance & Auditing: Internal Audits, External Audit Liaison, Awareness Training.

Skills

GRC
Information Security
Data Privacy
IT Audit
Cloud Security AWS

Tools

Sprinto
AWS

Job description

Role Overview

We are seeking a detail-oriented GRC & Data Privacy Analyst to join our security team. In this role, you will be responsible for maintaining our integrated risk management framework while taking a lead role in implementing and auditing our data privacy program. You will ensure that our operations remain compliant with global regulations (GDPR, PDPA, etc.) while identifying and mitigating risks across the organization.

Key Responsibilities
Governance & Risk Management
  • Framework Alignment: Maintain and mature the organization’s security framework (e.g., ISO 27001, SOC 2 and Singapore MAS).

  • Risk Assessments: Conduct annual and project-based risk assessments; maintain the Corporate Risk Register and track remediation efforts.

  • Policy Management: Draft, review, and update internal security policies and standards to ensure they reflect current business processes.

  • Third-Party Risk Management (TPRM): Evaluate the security posture of vendors and partners through assessments and due diligence reviews.

Data Privacy Implementation
  • Privacy Impact Assessments (PIAs/DPIAs): Lead the evaluation of new products or processes to ensure "Privacy by Design" is integrated into the development lifecycle.

  • Data Mapping: Maintain a comprehensive record of processing activities (ROPA) and data flow diagrams.

  • Privacy Operations: Manage the Data Subject Access Request (DSAR) process and coordinate responses to privacy-related inquiries.

  • Compliance Monitoring: Monitor changes in global privacy laws and translate them into actionable technical or procedural requirements for the IT and Product teams.

Compliance & Auditing
  • Internal Audits: Perform regular control testing to ensure ongoing compliance with internal policies and external regulations.

  • External Audit Liaison: Serve as the primary point of contact for external auditors during certification cycles.

  • Awareness Training: Develop and deliver training content on security best practices and data handling requirements for all employees.

Required Qualifications
  • Experience: 8 - 10 years in GRC, Information Security, or IT Audit, with at least 2–4 years specifically focused on Data Privacy.

  • Certifications (Preferred): CISA, CRISC, or CISM.

  • Technical Skills: Familiarity with GRC tools (Sprinto) and a solid understanding of cloud security (AWS).

  • Regulatory Knowledge: Deep understanding of GDPR, PDPA, and industry standards like ISO 27001, SOC 2 and Singapore MAS

Soft Skills for Success
  • The "Translator" Ability: Can explain complex legal requirements to developers and technical risks to executives.

  • Analytical Rigor: A passion for documentation and a "trust but verify" mindset.

  • Adaptability: Comfortable navigating the gray areas of emerging privacy legislation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security and Data Privacy Manager
Information Security and Data Privacy Manager

Tiger Analytics • Chennai District

Hybrid
INR 2,500,000 - 6,000,000
Governance, Risk & Compliance (GRC) Manager
Governance, Risk & Compliance (GRC) Manager

TeamsWork.In • India

On-site
INR 1,500,000 - 2,100,000
GRC /SOC Analyst
GRC /SOC Analyst

fulcrumdigital • Pune District

Hybrid
INR 600,000 - 900,000
IT Compliance and Security Manager
IT Compliance and Security Manager

RGP • Pune District

On-site
INR 900,000 - 1,500,000
DTDC - Practice Head - Data Security & Privacy
DTDC - Practice Head - Data Security & Privacy

DTDC Express Limited • Bengaluru

On-site
INR 3,000,000 - 4,500,000
Lead Compliance Specialist
Lead Compliance Specialist

TAC Security • Chandigarh

On-site
INR 2,600,000 - 3,200,000
GRC /SOC Analyst
GRC /SOC Analyst

Fulcrum Digital • Pune District

On-site
INR 800,000 - 1,200,000
Data Protection Consultant/Assistant Manager
Data Protection Consultant/Assistant Manager

Privacypillar • Bengaluru, Mumbai

On-site
INR 900,000 - 1,200,000
Module Lead Information Security
Module Lead Information Security

IDfy • Mumbai

On-site
INR 4,000,000 - 7,000,000
100% Remote Compliance Manager
100% Remote Compliance Manager

TeamsWork.In • India

On-site
INR 2,000,000 - 3,500,000