GRC & Data Privacy Analyst

Posted 9 Days Ago
Be an Early Applicant
Hyderabad, Telangana, IND
In-Office
Expert/Leader
Fintech • Payments • Software • Financial Services
The Role
Maintains and matures security governance, risk, and compliance frameworks; conducts risk assessments, policy management, third-party risk reviews, control testing, and audit coordination. Leads data privacy operations including DPIAs, data mapping, ROPA maintenance, DSAR handling, regulatory monitoring, and privacy-by-design implementation. Develops security and data-handling awareness training and translates legal and technical requirements for business, product, IT, and executive stakeholders.
Summary Generated by Built In
Role Overview

We are seeking a detail-oriented GRC & Data Privacy Analyst to join our security team. In this role, you will be responsible for maintaining our integrated risk management framework while taking a lead role in implementing and auditing our data privacy program. You will ensure that our operations remain compliant with global regulations (GDPR, PDPA, etc.) while identifying and mitigating risks across the organization.

Key ResponsibilitiesGovernance & Risk Management
  • Framework Alignment: Maintain and mature the organization’s security framework (e.g., ISO 27001, SOC 2 and Singapore MAS).

  • Risk Assessments: Conduct annual and project-based risk assessments; maintain the Corporate Risk Register and track remediation efforts.

  • Policy Management: Draft, review, and update internal security policies and standards to ensure they reflect current business processes.

  • Third-Party Risk Management (TPRM): Evaluate the security posture of vendors and partners through assessments and due diligence reviews.

Data Privacy Implementation
  • Privacy Impact Assessments (PIAs/DPIAs): Lead the evaluation of new products or processes to ensure "Privacy by Design" is integrated into the development lifecycle.

  • Data Mapping: Maintain a comprehensive record of processing activities (ROPA) and data flow diagrams.

  • Privacy Operations: Manage the Data Subject Access Request (DSAR) process and coordinate responses to privacy-related inquiries.

  • Compliance Monitoring: Monitor changes in global privacy laws and translate them into actionable technical or procedural requirements for the IT and Product teams.

Compliance & Auditing
  • Internal Audits: Perform regular control testing to ensure ongoing compliance with internal policies and external regulations.

  • External Audit Liaison: Serve as the primary point of contact for external auditors during certification cycles.

  • Awareness Training: Develop and deliver training content on security best practices and data handling requirements for all employees.

Required Qualifications
  • Experience: 8 - 10 years in GRC, Information Security, or IT Audit, with at least 2–4 years specifically focused on Data Privacy.

  • Certifications (Preferred): CISA, CRISC, or CISM.

  • Technical Skills: Familiarity with GRC tools (Sprinto) and a solid understanding of cloud security (AWS).

  • Regulatory Knowledge: Deep understanding of GDPR, PDPA, and industry standards like ISO 27001, SOC 2 and Singapore MAS

Soft Skills for Success
  • The "Translator" Ability: Can explain complex legal requirements to developers and technical risks to executives.

  • Analytical Rigor: A passion for documentation and a "trust but verify" mindset.

  • Adaptability: Comfortable navigating the gray areas of emerging privacy legislation.

Skills Required

  • 8–10 years of experience in GRC, information security, or IT audit
  • 2–4 years of experience specifically focused on data privacy
  • Familiarity with GRC tools, specifically Sprinto
  • Solid understanding of cloud security, specifically AWS
  • Deep understanding of GDPR and PDPA
  • Understanding of ISO 27001, SOC 2, and Singapore MAS standards
  • CISA, CRISC, or CISM certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
60 Employees
Year Founded: 2019

What We Do

Atlas Consolidated Pte. Ltd., operating the HugoHub brand, develops technology for digital financial institutions. Its modular banking-as-a-service platform helps fintechs and other institutions embed payments, accounts, lending, and related financial services into their applications without holding a banking license. The company’s mission is to simplify complexity in finance, expand access, and support more intelligent, inclusive financial systems across global markets.

Similar Jobs

Hybrid
Hyderabad, Telangana, IND
289097 Employees
Hybrid
Hyderabad, Telangana, IND
289097 Employees
Hybrid
Hyderabad, Telangana, IND
289097 Employees

JPMorganChase Logo JPMorganChase

Client Data

Financial Services
Hybrid
2 Locations
289097 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account