- Posted 17 hours ago
- Be among the first 10 applicants
Job Description
Dhruva Space is seeking a dedicated Senior Associate — Information Security & Privacy to operate and maintain our certified, combined Information Security Management System (ISO/IEC 27001:2022) and Privacy Information Management System (ISO/IEC 27701:2019) in alignment with the Digital Personal Data Protection Act 2023 (DPDPA). The primary purpose of this role is to serve as the operational backbone of the ISMS/PIMS, keeping the management system mature, compliant, and continually audit-ready. This position requires a proactive governance, risk, and compliance (GRC) or privacy professional who can manage operational controls, execute privacy programs, and drive continuous improvement within a fast-paced space-technology environment.
Key responsibilities include, but are not limited to:
- Maintain comprehensive ISMS documentation, including policies, standard operating procedures (SOPs), the Statement of Applicability, and risk registers under document control.
- Operate the risk assessment and treatment process by actively maintaining the risk register and tracking treatment actions with respective owners.
- Coordinate and evidence daily operational controls, such as access reviews, incident registers, logging, backup/restore records, and monitoring metrics.
- Manage the Corrective and Preventive Action (CAPA) tracker to drive findings, observations, and opportunities for improvement to closure ahead of audits.
- Support internal and external audits by preparing evidence, coordinating with auditees, and tracking post-audit findings.
- Operate the full privacy consent lifecycle, including capture, inventory, and withdrawal handling.
- Maintain the Records of Processing Activities (RoPA) and Records of PII Disclosures, while supporting Privacy Impact Assessments (PIAs) for new tools and vendors.
- Handle all Data Principal requests (access, correction, erasure, grievance, nomination) in accordance with defined procedures and statutory timelines.
- Manage vendor Data Processing Agreements (DPAs) and the vendor-compliance register to track processor obligations.
- Execute the organizational security and privacy awareness program, including training campaigns, phishing simulations, and remedial follow-ups.
- Collaborate cross-functionally with HR, Legal, Procurement, and IT to ensure security and privacy requirements are deeply embedded in operational processes.
- Monitor developments under the DPDPA 2023 and assist the Data Protection Officer (DPO) with incident handling, breach reporting, and management KPI reporting.
Candidate Requirements
- Bachelor's degree in Information Technology, Computer Science, Law, or a closely related field.
- 3–6 years of hands-on experience in information security, data privacy, or governance, risk, and compliance (GRC).
- Demonstrated working knowledge of ISO/IEC 27001 (and ideally ISO/IEC 27701), with a solid understanding of how a certified management system operates in practice.
- Strong familiarity with the Digital Personal Data Protection Act 2023 (DPDPA) and core data-protection concepts such as consent, RoPA, and data-principal rights.
- Excellent documentation, record-keeping, and evidence-management skills, with a precise and detail-oriented approach.
- Outstanding communication skills with the ability to coordinate across functions and communicate effectively with both technical and non-technical stakeholders.
- Proficiency with common business tooling (e.g., Google Workspace, Zoho) and familiarity with security tooling (e.g., endpoint protection, awareness platforms).
- Possession of at least one relevant active certification, such as ISO 27001 Lead Implementer / Lead Auditor, a privacy certification (e.g., DCPP/DCPLA, CIPP), or CISA / CISM.
- Prior exposure to a certified ISMS/PIMS environment or a regulated/high-assurance industry is highly preferred; understanding of sector-specific obligations (e.g., CERT-In directions) is a plus.
More Info
Key Skills
ISO IEC 27701
ISO IEC 27001
