Data Privacy Trainee

SISA Information Security Pvt LtdChennai, Tamil NaduOn-siteFull-timeNew grad, 0–1 yearsListed 2 hours ago

Apply now

About this role

Job Summary: The Associate Consultant / Trainee will support the delivery of Data Privacy, Data Protection, Cyber Law, Cybersecurity and GRC engagements. This role is suitable for freshers and candidates with 0 – 2 years of experience who have an academic or professional background in Law, Cyber Law, Cybersecurity or Information Security. The candidate will work with experienced consultants to support privacy assessments, regulatory research, risk assessments, documentation and compliance activities. Knowledge of Cyber Law and Cybersecurity will be an added advantage. Key Responsibilities:
- Support Data Privacy and Data Protection assessments, including Privacy Gap Assessments, against applicable laws and regulations.
- Assist with PIA, DPIA, RoPA and Data Flow Mapping activities.
- Support review of privacy policies, procedures, privacy notices, consent, data retention and data subject rights.
- Research applicable regulations including DPDP Act, GDPR, PDPA and other relevant requirements.
- Support the team in understanding Cyber Law, Cybersecurity and Information Security requirements and emerging cyber risks.
- Assist in mapping legal and regulatory requirements to applicable privacy and cybersecurity controls.
- Support review of basic cybersecurity controls relating to access management, data security, encryption, vulnerability and incident management.
- Support privacy and compliance assessments, including collection and review of client information, documents and audit evidence.
- Support consultants in client engagements, meetings and information-gathering sessions.
- Assist in preparing assessment reports, compliance checklists, trackers, presentations and other supporting documentation.
Qualifications:
- Integrated B.Tech + LLB, Bachelor’s degree in Law, Cyber Law, Cybersecurity, Information Security, Computer Science, IT or a related field.
- Candidates with a combination of Law and Cybersecurity / Information Security background will be an advantage.
- Relevant internships, academic projects or training in Data Privacy, Cyber Law, Cybersecurity, IT GRC or Compliance will be preferred.

Work Experience:
- Freshers and candidates with 0–2 years of experience in Data Privacy, Cybersecurity, Cyber Law, IT GRC, IT Audit, Risk or Compliance.
- Good understanding of data privacy principles and regulatory requirements.
- Ability to read and understand laws, regulations and regulatory guidelines.
- Basic understanding of Cyber Law, Cybersecurity and Information Security concepts.
- Understanding of the relationship between legal requirements, privacy obligations and cybersecurity controls.
- Good research, analytical and problem-solving abilities.
- Good written and verbal communication skills.
- Ability to prepare clear documentation and reports.
- Willingness to learn and develop expertise in Data Privacy, Cybersecurity and GRC.
- Cyber Law and Cybersecurity knowledge will be an added advantage.
- Exposure to DPDP Act, GDPR, PCI DSS, ISO 27001 or ISO 27701 will be preferred.
- Attention to detail and ability to work with documentation and assessment evidence.
- Ability to manage assigned tasks and complete deliverables within timelines.
- Industry Certification will be an be plus: DCPP, CIPP, AIGP, ISO 27001, Security+, CEH, CCNA or other relevant certifications will be an advantage.
- Tools Exposure: Exposure to Data Privacy or GRC tools such as OneTrust, BigID, TrustArc or similar platforms will be an advantage.