Senior Privacy & GRC Lead
TypeFull-time job
LocationIndia
Posted3 hours ago
Sr. Privacy & GRC Lead
Location: India (Remote)
Company: VB Spine
Looking for a career where your work truly matters? At VB Spine, you’ll be part of a mission-focused team supporting innovation and better patient outcomes in spine care. As the Sr. Privacy & GRC Lead, you will lead the global Privacy and Governance, Risk & Compliance program, helping ensure the organization operates in alignment with applicable privacy laws, regulatory requirements, internal controls, and industry best practices.
What You’ll Do:
Lead the development, implementation, and continuous improvement of the global Privacy and GRC programs
Develop and maintain privacy policies, standards, procedures, and governance frameworks aligned with GDPR and other applicable global privacy regulations
Lead Privacy Impact Assessments, Data Protection Impact Assessments, Transfer Impact Assessments, and other privacy risk assessments
Maintain Records of Processing Activities and oversee global data mapping activities
Monitor changes in global privacy laws and recommend updates to policies and business practices
Serve as a key advisor to Legal, Security, IT, HR, Procurement, and business leaders on privacy and compliance matters
Lead governance, risk assessment, compliance monitoring, internal control, and enterprise GRC activities
Coordinate internal audits, compliance assessments, regulatory reviews, remediation activities, and audit readiness
Develop and monitor compliance metrics, KPIs, and key risk indicators
Oversee Data Subject Rights requests including access, deletion, correction, and portability
Lead privacy incident investigations, breach response activities, corrective actions, and applicable regulatory notification processes
Lead third-party privacy and compliance reviews, including vendor risk assessments and Data Processing Agreements
Partner with Legal, Procurement, IT, and Security to support third-party risk management and remediation
Promote Privacy by Design and Privacy by Default principles across new technologies, applications, and business processes
Provide guidance related to secure data handling, retention, disposal, and international data transfers
Present privacy and GRC program updates, risks, and remediation activities to senior leadership
Lead privacy awareness and employee training initiatives
Coach and develop Privacy and GRC team members
Drive continuous improvement across privacy, compliance, governance, and risk processes
What You Bring:
Bachelor’s degree in Information Security, Cybersecurity, Information Technology, Business, Law, Data Privacy, or a related field preferred; equivalent professional experience may be considered
5+ years of experience in privacy, governance, risk management, compliance, cybersecurity, audit, or a related field
Experience implementing GDPR and other international privacy regulations
Hands-on experience with PIAs, DPIAs, TIAs, ROPAs, and privacy risk assessments
Experience supporting compliance audits, regulatory assessments, controls, and remediation activities
Experience with third-party risk management, vendor privacy assessments, and DPAs
Strong understanding of governance, enterprise risk management, internal controls, and compliance frameworks
Ability to lead cross-functional initiatives and influence stakeholders across multiple business functions
Strong analytical, organizational, communication, and problem-solving skills
Ability to work independently, exercise sound judgment, and manage multiple priorities
Experience within medical device, healthcare, life sciences, or another regulated industry is preferred
Experience with GRC platforms and enterprise risk management frameworks is preferred
Certifications such as CIPP/E, CIPM, CISSP, CISM, CRISC, or CISA are preferred
Knowledge of ISO 27701 and global privacy frameworks is a plus
Fluency in English required
Physical & Mental Requirements:
Ability to manage multiple priorities in a fast-paced environment
Strong analytical, critical-thinking, and decision-making skills
Ability to maintain confidentiality and handle sensitive information with discretion
Ability to work independently and collaboratively with global teams
Excellent written and verbal communication skills
Occasional travel to company offices and vendor locations may be required, approximately 15%
Why VB Spine?
We believe in building strong teams and giving people the opportunity to make a meaningful impact. At VB Spine, you’ll help shape a global privacy and compliance program while partnering with teams across the organization to strengthen governance, manage risk, and support responsible business growth.
Compensation:
Compensation for this role is competitive and based on experience, qualifications, skills, and local market conditions. Final compensation will be determined on a case-by-case basis.
Benefits include:
Competitive benefits based on local country requirements
Paid time off and holidays
Ongoing training and professional development opportunities
Opportunity to work with global teams and senior leadership
Opportunity to grow within a fast-paced and evolving organization
Originally posted on Himalayas
Location: India (Remote)
Company: VB Spine
Looking for a career where your work truly matters? At VB Spine, you’ll be part of a mission-focused team supporting innovation and better patient outcomes in spine care. As the Sr. Privacy & GRC Lead, you will lead the global Privacy and Governance, Risk & Compliance program, helping ensure the organization operates in alignment with applicable privacy laws, regulatory requirements, internal controls, and industry best practices.
What You’ll Do:
Lead the development, implementation, and continuous improvement of the global Privacy and GRC programs
Develop and maintain privacy policies, standards, procedures, and governance frameworks aligned with GDPR and other applicable global privacy regulations
Lead Privacy Impact Assessments, Data Protection Impact Assessments, Transfer Impact Assessments, and other privacy risk assessments
Maintain Records of Processing Activities and oversee global data mapping activities
Monitor changes in global privacy laws and recommend updates to policies and business practices
Serve as a key advisor to Legal, Security, IT, HR, Procurement, and business leaders on privacy and compliance matters
Lead governance, risk assessment, compliance monitoring, internal control, and enterprise GRC activities
Coordinate internal audits, compliance assessments, regulatory reviews, remediation activities, and audit readiness
Develop and monitor compliance metrics, KPIs, and key risk indicators
Oversee Data Subject Rights requests including access, deletion, correction, and portability
Lead privacy incident investigations, breach response activities, corrective actions, and applicable regulatory notification processes
Lead third-party privacy and compliance reviews, including vendor risk assessments and Data Processing Agreements
Partner with Legal, Procurement, IT, and Security to support third-party risk management and remediation
Promote Privacy by Design and Privacy by Default principles across new technologies, applications, and business processes
Provide guidance related to secure data handling, retention, disposal, and international data transfers
Present privacy and GRC program updates, risks, and remediation activities to senior leadership
Lead privacy awareness and employee training initiatives
Coach and develop Privacy and GRC team members
Drive continuous improvement across privacy, compliance, governance, and risk processes
What You Bring:
Bachelor’s degree in Information Security, Cybersecurity, Information Technology, Business, Law, Data Privacy, or a related field preferred; equivalent professional experience may be considered
5+ years of experience in privacy, governance, risk management, compliance, cybersecurity, audit, or a related field
Experience implementing GDPR and other international privacy regulations
Hands-on experience with PIAs, DPIAs, TIAs, ROPAs, and privacy risk assessments
Experience supporting compliance audits, regulatory assessments, controls, and remediation activities
Experience with third-party risk management, vendor privacy assessments, and DPAs
Strong understanding of governance, enterprise risk management, internal controls, and compliance frameworks
Ability to lead cross-functional initiatives and influence stakeholders across multiple business functions
Strong analytical, organizational, communication, and problem-solving skills
Ability to work independently, exercise sound judgment, and manage multiple priorities
Experience within medical device, healthcare, life sciences, or another regulated industry is preferred
Experience with GRC platforms and enterprise risk management frameworks is preferred
Certifications such as CIPP/E, CIPM, CISSP, CISM, CRISC, or CISA are preferred
Knowledge of ISO 27701 and global privacy frameworks is a plus
Fluency in English required
Physical & Mental Requirements:
Ability to manage multiple priorities in a fast-paced environment
Strong analytical, critical-thinking, and decision-making skills
Ability to maintain confidentiality and handle sensitive information with discretion
Ability to work independently and collaboratively with global teams
Excellent written and verbal communication skills
Occasional travel to company offices and vendor locations may be required, approximately 15%
Why VB Spine?
We believe in building strong teams and giving people the opportunity to make a meaningful impact. At VB Spine, you’ll help shape a global privacy and compliance program while partnering with teams across the organization to strengthen governance, manage risk, and support responsible business growth.
Compensation:
Compensation for this role is competitive and based on experience, qualifications, skills, and local market conditions. Final compensation will be determined on a case-by-case basis.
Benefits include:
Competitive benefits based on local country requirements
Paid time off and holidays
Ongoing training and professional development opportunities
Opportunity to work with global teams and senior leadership
Opportunity to grow within a fast-paced and evolving organization
Originally posted on Himalayas
Apply on Himalayas →
Job sourced from Himalayas. Applications happen directly on the original platform — we never collect your data.