Search Jobs

Search by job, company or skills

Senior Associate Information Security & Privacy

Senior Associate Information Security & Privacy

Dhruva Space
Early Applicant
  • Posted 16 hours ago
  • Be among the first 10 applicants

Job Description

Dhruva Space is seeking a dedicated Senior Associate — Information Security & Privacy to operate and maintain our certified, combined Information Security Management System (ISO/IEC 27001:2022) and Privacy Information Management System (ISO/IEC 27701:2019) in alignment with the Digital Personal Data Protection Act 2023 (DPDPA). The primary purpose of this role is to serve as the operational backbone of the ISMS/PIMS, keeping the management system mature, compliant, and continually audit-ready. This position requires a proactive governance, risk, and compliance (GRC) or privacy professional who can manage operational controls, execute privacy programs, and drive continuous improvement within a fast-paced space-technology environment.

Key responsibilities include, but are not limited to:

  • Maintain comprehensive ISMS documentation, including policies, standard operating procedures (SOPs), the Statement of Applicability, and risk registers under document control.
  • Operate the risk assessment and treatment process by actively maintaining the risk register and tracking treatment actions with respective owners.
  • Coordinate and evidence daily operational controls, such as access reviews, incident registers, logging, backup/restore records, and monitoring metrics.
  • Manage the Corrective and Preventive Action (CAPA) tracker to drive findings, observations, and opportunities for improvement to closure ahead of audits.
  • Support internal and external audits by preparing evidence, coordinating with auditees, and tracking post-audit findings.
  • Operate the full privacy consent lifecycle, including capture, inventory, and withdrawal handling.
  • Maintain the Records of Processing Activities (RoPA) and Records of PII Disclosures, while supporting Privacy Impact Assessments (PIAs) for new tools and vendors.
  • Handle all Data Principal requests (access, correction, erasure, grievance, nomination) in accordance with defined procedures and statutory timelines.
  • Manage vendor Data Processing Agreements (DPAs) and the vendor-compliance register to track processor obligations.
  • Execute the organizational security and privacy awareness program, including training campaigns, phishing simulations, and remedial follow-ups.
  • Collaborate cross-functionally with HR, Legal, Procurement, and IT to ensure security and privacy requirements are deeply embedded in operational processes.
  • Monitor developments under the DPDPA 2023 and assist the Data Protection Officer (DPO) with incident handling, breach reporting, and management KPI reporting.

Candidate Requirements

  • Bachelor's degree in Information Technology, Computer Science, Law, or a closely related field.
  • 3–6 years of hands-on experience in information security, data privacy, or governance, risk, and compliance (GRC).
  • Demonstrated working knowledge of ISO/IEC 27001 (and ideally ISO/IEC 27701), with a solid understanding of how a certified management system operates in practice.
  • Strong familiarity with the Digital Personal Data Protection Act 2023 (DPDPA) and core data-protection concepts such as consent, RoPA, and data-principal rights.
  • Excellent documentation, record-keeping, and evidence-management skills, with a precise and detail-oriented approach.
  • Outstanding communication skills with the ability to coordinate across functions and communicate effectively with both technical and non-technical stakeholders.
  • Proficiency with common business tooling (e.g., Google Workspace, Zoho) and familiarity with security tooling (e.g., endpoint protection, awareness platforms).
  • Possession of at least one relevant active certification, such as ISO 27001 Lead Implementer / Lead Auditor, a privacy certification (e.g., DCPP/DCPLA, CIPP), or CISA / CISM.
  • Prior exposure to a certified ISMS/PIMS environment or a regulated/high-assurance industry is highly preferred; understanding of sector-specific obligations (e.g., CERT-In directions) is a plus.

More Info

Job Type:
Industry:
Employment Type:

Key Skills

ISO IEC 27701

ISO IEC 27001

About Company