Senior Privacy & GRC Lead

VB Spine, LLC

India

On-site

INR 4,000,000 - 7,000,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Competitive benefits
Paid time off
Professional development
Global teams exposure
Career growth

Job summary

VB Spine, LLC is seeking a Sr. Privacy & GRC Lead to drive the global Privacy and Governance, Risk & Compliance program. You will ensure adherence to privacy laws, regulatory requirements, and internal controls across the organization.

You will lead PIA/DPIA/TAI processes, data mapping, and audit readiness while partnering with Legal, IT, Security, HR, and Procurement to manage third-party risk and drive Privacy by Design across new technologies.

Qualifications

  • Bachelor’s degree or equivalent professional experience in information security, privacy, or a related field.
  • 5+ years of privacy, governance, risk management, compliance, or related experience.
  • Experience implementing GDPR and other international privacy regulations.
  • Strong ability to lead cross-functional initiatives and influence stakeholders.

Responsibilities

  • Lead the development, implementation, and continuous improvement of global Privacy and GRC programs.
  • Develop privacy policies, standards, and governance frameworks aligned with GDPR and global regulations.
  • Lead privacy risk assessments (PIAs, DPIAs, TIAs) and data mapping activities.

Skills

Privacy & GRC
Regulatory compliance
Stakeholder leadership
Analytical skills
Communication skills
Independent work
Project management
Cross-functional collaboration

Education

Bachelor’s degree in information security / related field

Tools

GRC platforms

Job description

Looking for a career where your work truly matters? At VB Spine, you’ll be part of a mission-focused team supporting innovation and better patient outcomes in spine care. As the Sr. Privacy & GRC Lead, you will lead the global Privacy and Governance, Risk & Compliance program, helping ensure the organization operates in alignment with applicable privacy laws, regulatory requirements, internal controls, and industry best practices.

What You’ll Do:
  • Lead the development, implementation, and continuous improvement of the global Privacy and GRC programs
  • Develop and maintain privacy policies, standards, procedures, and governance frameworks aligned with GDPR and other applicable global privacy regulations
  • Lead Privacy Impact Assessments, Data Protection Impact Assessments, Transfer Impact Assessments, and other privacy risk assessments
  • Maintain Records of Processing Activities and oversee global data mapping activities
  • Monitor changes in global privacy laws and recommend updates to policies and business practices
  • Serve as a key advisor to Legal, Security, IT, HR, Procurement, and business leaders on privacy and compliance matters
  • Lead governance, risk assessment, compliance monitoring, internal control, and enterprise GRC activities
  • Coordinate internal audits, compliance assessments, regulatory reviews, remediation activities, and audit readiness
  • Develop and monitor compliance metrics, KPIs, and key risk indicators
  • Oversee Data Subject Rights requests including access, deletion, correction, and portability
  • Lead privacy incident investigations, breach response activities, corrective actions, and applicable regulatory notification processes
  • Lead third-party privacy and compliance reviews, including vendor risk assessments and Data Processing Agreements
  • Partner with Legal, Procurement, IT, and Security to support third-party risk management and remediation
  • Promote Privacy by Design and Privacy by Default principles across new technologies, applications, and business processes
  • Provide guidance related to secure data handling, retention, disposal, and international data transfers
  • Present privacy and GRC program updates, risks, and remediation activities to senior leadership
  • Lead privacy awareness and employee training initiatives
  • Coach and develop Privacy and GRC team members
  • Drive continuous improvement across privacy, compliance, governance, and risk processes
What You Bring:
  • Bachelor’s degree in Information Security, Cybersecurity, Information Technology, Business, Law, Data Privacy, or a related field preferred; equivalent professional experience may be considered
  • 5+ years of experience in privacy, governance, risk management, compliance, cybersecurity, audit, or a related field
  • Experience implementing GDPR and other international privacy regulations
  • Hands-on experience with PIAs, DPIAs, TIAs, ROPAs, and privacy risk assessments
  • Experience supporting compliance audits, regulatory assessments, controls, and remediation activities
  • Experience with third-party risk management, vendor privacy assessments, and DPAs
  • Strong understanding of governance, enterprise risk management, internal controls, and compliance frameworks
  • Ability to lead cross-functional initiatives and influence stakeholders across multiple business functions
  • Strong analytical, organizational, communication, and problem-solving skills
  • Ability to work independently, exercise sound judgment, and manage multiple priorities
  • Experience within medical device, healthcare, life sciences, or another regulated industry is preferred
  • Experience with GRC platforms and enterprise risk management frameworks is preferred
  • Certifications such as CIPP/E, CIPM, CISSP, CISM, CRISC, or CISA are preferred
  • Knowledge of ISO 27701 and global privacy frameworks is a plus
  • Fluency in English required
Physical & Mental Requirements:
  • Ability to manage multiple priorities in a fast-paced environment
  • Strong analytical, critical-thinking, and decision-making skills
  • Ability to maintain confidentiality and handle sensitive information with discretion
  • Ability to work independently and collaboratively with global teams
  • Excellent written and verbal communication skills
  • Occasional travel to company offices and vendor locations may be required, approximately 15%
Why VB Spine?

We believe in building strong teams and giving people the opportunity to make a meaningful impact. At VB Spine, you’ll help shape a global privacy and compliance program while partnering with teams across the organization to strengthen governance, manage risk, and support responsible business growth.

Compensation:

Compensation for this role is competitive and based on experience, qualifications, skills, and local market conditions. Final compensation will be determined on a case-by-case basis.

Benefits include:

Competitive benefits based on local country requirements

Paid time off and holidays

Ongoing training and professional development opportunities

Opportunity to work with global teams and senior leadership

Opportunity to grow within a fast-paced and evolving organization

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Privacy & GRC Lead
Senior Privacy & GRC Lead

VB Spine • India

On-site
INR 3,500,000 - 6,500,000
Competitive benefits
Paid time off
Professional development
+2
Global Privacy Specialist
Global Privacy Specialist

Progress Software Corporation • India

On-site
INR 1,500,000 - 2,500,000
Stock purchase plan
Leave benefits
Medical insurance
+2
Technical Lead
Technical Lead

Sopra Steria • Chennai District

On-site
INR 1,800,000 - 3,000,000
Senior GRC Expert
Senior GRC Expert

Velsera • Pune District

Hybrid
INR 3,000,000 - 5,200,000
Hybrid work model
Unlimited paid time off
Health insurance
+1
Data Privacy Counsel
Data Privacy Counsel

Varex Imaging India • Pune District

On-site
INR 1,200,000 - 1,800,000
IN_Associate 2_Data Privacy_ RC C&DR AITH_Advisory_Noida
IN_Associate 2_Data Privacy_ RC C&DR AITH_Advisory_Noida

PwC • Dadri

On-site
INR 1,200,000 - 2,400,000
Mentorship
Training programs
Flexible benefits
+1
Governance Risk and Complains Manager
Governance Risk and Complains Manager

Getix Health, LLC 1099 • Karnataka

On-site
INR 2,400,000 - 3,600,000
Senior GRC Analyst
Senior GRC Analyst

Litmos • India

On-site
INR 2,400,000 - 3,200,000
IN_Associate 2_Data Privacy_ RC C&DR AITH _Advisory_Noida
IN_Associate 2_Data Privacy_ RC C&DR AITH _Advisory_Noida

PwC South Africa • Dadri

On-site
Confidential
Senior InfoSec GRC Specialist
Senior InfoSec GRC Specialist

Velsera • Maharashtra

On-site
INR 4,200,000 - 6,200,000
Flexible Work & Time Off
Health & Well-being
Growth & Learning
+2