Senior Privacy & GRC Lead
VB Spine, LLC
IndiaremotePosted 22 days ago
V
Skill Required
Privacy-and-GRC-LeadPrivacy-ComplianceGovernance-Risk-And-ComplianceData-Privacy-OfficerRegulatory-ComplianceGovernance-Risk-And-Compliance-Sr.-Privacy-EngineerSenior-Privacy-Compliance-ConsultantSenior-Governance-Risk-And-Compliance-SpecialistPrivacy-Compliance-DirectorSenior-Security-GRC-AnalystPrivacy-and-Compliance-Program-Managerrelated fieldCybersecurityanalyticalObservabilitysecuritybuildingwrittendesignandFulltime
Key highlights
- Location: India (Remote)
- Compensation is competitive and individually negotiated
- Required experience: 5+ years in privacy, governance, risk management, compliance, cybersecurity, audit, or related field
- Key benefit: Opportunity to grow within a fast-paced and evolving organization
- Notable requirement: Occasional travel to company offices and vendor locations may be required, approximately 15%
Role overview
VB Spine is seeking a Sr. Privacy & GRC Lead to lead the global Privacy and Governance, Risk & Compliance program. The role involves developing and implementing privacy policies, conducting risk assessments, ensuring regulatory compliance with GDPR and other laws, leading incident investigations, managing third-party vendor assessments, and advising cross-functional leadership on privacy and compliance matters. The successful candidate will drive continuous improvement across privacy, compliance, governance, and risk processes while building and coaching a team within a mission-focused healthcare organization focused on spine care innovation and patient outcomes.
Responsibilities
- Lead the development, implementation, and continuous improvement of the global Privacy and GRC programs
- Develop and maintain privacy policies, standards, procedures, and governance frameworks aligned with GDPR and other applicable global privacy regulations
- Lead Privacy Impact Assessments, Data Protection Impact Assessments, Transfer Impact Assessments, and other privacy risk assessments
- Maintain Records of Processing Activities and oversee global data mapping activities
- Monitor changes in global privacy laws and recommend updates to policies and business practices
- Serve as a key advisor to Legal, Security, IT, HR, Procurement, and business leaders on privacy and compliance matters
- Lead governance, risk assessment, compliance monitoring, internal control, and enterprise GRC activities
- Coordinate internal audits, compliance assessments, regulatory reviews, remediation activities, and audit readiness
- Develop and monitor compliance metrics, KPIs, and key risk indicators
- Oversee Data Subject Rights requests including access, deletion, correction, and portability
- Lead privacy incident investigations, breach response activities, corrective actions, and applicable regulatory notification processes
- Lead third-party privacy and compliance reviews, including vendor risk assessments and Data Processing Agreements
- Partner with Legal, Procurement, IT, and Security to support third-party risk management and remediation
- Promote Privacy by Design and Privacy by Default principles across new technologies, applications, and business processes
- Provide guidance related to secure data handling, retention, disposal, and international data transfers
- Present privacy and GRC program updates, risks, and remediation activities to senior leadership
- Lead privacy awareness and employee training initiatives
- Coach and develop Privacy and GRC team members
- Drive continuous improvement across privacy, compliance, governance, and risk processes
Requirements
- Bachelor's degree in Information Security, Cybersecurity, Information Technology, Business, Law, Data Privacy, or a related field preferred; equivalent professional experience may be considered
- 5+ years of experience in privacy, governance, risk management, compliance, cybersecurity, audit, or a related field
- Experience implementing GDPR and other international privacy regulations
- Hands-on experience with PIAs, DPIAs, TIAs, ROPAs, and privacy risk assessments
- Experience supporting compliance audits, regulatory assessments, controls, and remediation activities
- Experience with third-party risk management, vendor privacy assessments, and DPAs
- Strong understanding of governance, enterprise risk management, internal controls, and compliance frameworks
- Ability to lead cross-functional initiatives and influence stakeholders across multiple business functions
- Strong analytical, organizational, communication, and problem-solving skills
- Ability to work independently, exercise sound judgment, and manage multiple priorities
- Experience within medical device, healthcare, life sciences, or another regulated industry is preferred
- Fluency in English required
- Ability to manage multiple priorities in a fast-paced environment
- Strong analytical, critical-thinking, and decision-making skills
- Ability to maintain confidentiality and handle sensitive information with discretion
- Ability to work independently and collaboratively with global teams
- Excellent written and verbal communication skills
- Occasional travel to company offices and vendor locations may be required, approximately 15%
Nice to have
- Experience with GRC platforms and enterprise risk management frameworks is preferred
- Certifications such as CIPP/E, CIPM, CISSP, CISM, CRISC, or CISA are preferred
- Knowledge of ISO 27701 and global privacy frameworks is a plus
Benefits
- Competitive benefits based on local country requirements
- Paid time off and holidays
- Ongoing training and professional development opportunities
- Opportunity to work with global teams and senior leadership
- Opportunity to grow within a fast-paced and evolving organization
Additional details
- Compensation for this role is competitive and based on experience, qualifications, skills, and local market conditions. Final compensation will be determined on a case-by-case basis.