Live opening · Posted 12 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Dhruva Space is seeking a dedicated Senior Associate — Information Security & Privacy to operate and maintain our certified, combined Information Security Management System (ISO/IEC 27001:2022) and Privacy Information Management System (ISO/IEC 27701:2019) in alignment with the Digital Personal Data Protection Act 2023 (DPDPA). The primary purpose of this role is to serve as the operational backbone of the ISMS/PIMS, keeping the management system mature, compliant, and continually audit-ready. This position requires a proactive governance, risk, and compliance (GRC) or privacy professional who can manage operational controls, execute privacy programs, and drive continuous improvement within a fast-paced space-technology environment.
Key responsibilities include, but are not limited to:
Maintain comprehensive ISMS documentation, including policies, standard operating procedures (SOPs), the Statement of Applicability, and risk registers under document control.
Operate the risk assessment and treatment process by actively maintaining the risk register and tracking treatment actions with respective owners.
Coordinate and evidence daily operational controls, such as access reviews, incident registers, logging, backup/restore records, and monitoring metrics.
Manage the Corrective and Preventive Action (CAPA) tracker to drive findings, observations, and opportunities for improvement to closure ahead of audits.
Support internal and external audits by preparing evidence, coordinating with auditees, and tracking post-audit findings.
Operate the full privacy consent lifecycle, including capture, inventory, and withdrawal handling.
Maintain the Records of Processing Activities (RoPA) and Records of PII Disclosures, while supporting Privacy Impact Assessments (PIAs) for new tools and vendors.
Handle all Data Principal requests (access, correction, erasure, grievance, nomination) in accordance with defined procedures and statutory timelines.
Manage vendor Data Processing Agreements (DPAs) and the vendor-compliance register to track processor obligations.
Execute the organizational security and privacy awareness program, including training campaigns, phishing simulations, and remedial follow-ups.
Collaborate cross-functionally with HR, Legal, Procurement, and IT to ensure security and privacy requirements are deeply embedded in operational processes.
Monitor developments under the DPDPA 2023 and assist the Data Protection Officer (DPO) with incident handling, breach reporting, and management KPI reporting.
Candidate Requirements
Bachelor’s degree in Information Technology, Computer Science, Law, or a closely related field.
3–6 years of hands-on experience in information security, data privacy, or governance, risk, and compliance (GRC).
Demonstrated working knowledge of ISO/IEC 27001 (and ideally ISO/IEC 27701), with a solid understanding of how a certified management system operates in practice.
Strong familiarity with the Digital Personal Data Protection Act 2023 (DPDPA) and core data-protection concepts such as consent, RoPA, and data-principal rights.
Excellent documentation, record-keeping, and evidence-management skills, with a precise and detail-oriented approach.
Outstanding communication skills with the ability to coordinate across functions and communicate effectively with both technical and non-technical stakeholders.
Proficiency with common business tooling (e.g., Google Workspace, Zoho) and familiarity with security tooling (e.g., endpoint protection, awareness platforms).
Possession of at least one relevant active certification, such as ISO 27001 Lead Implementer / Lead Auditor, a privacy certification (e.g., DCPP/DCPLA, CIPP), or CISA / CISM.
Prior exposure to a certified ISMS/PIMS environment or a regulated/high-assurance industry is highly preferred; understanding of sector-specific obligations (e.g., CERT-In directions) is a plus.
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.