KEY RESPONSIBILITIES
Data Classification & Risk Assessment
Identify, classify, categorize & regular monitoring of sensitive and personal data within the organization
Support enterprise initiatives like Data anonymization, masking etc
Compliance Monitoring
Support in ensuring compliance with Data Privacy laws and regulations
Plan, prepare and coordinate Data Privacy reviews with stakeholders
Remediation and governance of action plan and closure of remediation within applicable timelines
Annually review Data Flow Diagram (DFD) and Record of Processing activities( RoPA). Responsible for creating RoPA and DFD for new process
Assist in conducting DPIA for new processing activities & update for existing activities
Responsible for annual compliance and Privacy COMS tasks
Data Subject Rights Management
Vendor & 3rd party management
Responsible in 3rd party risk assessment and ensure vendors are adhering to standards laid by AMLI
Review and assess third-party privacy practices to ensure data shared externally is protected
Training & Awareness
Drive privacy related training to employees and vendor at all levels to enhance awareness and understanding.
Spurious Call Management
- Program manage Spurious Call Agenda by working closely with all relevant stakeholders
- Drive awareness agenda with the customer basis the learnings emanating
- Perform assessment with respect to Segregation of Duties (SOD) and Access Control management
- Drive periodic engagement with the leadership on Spurious Call matters
SKILLS
1. Analytical and problem solving skills
2. Large project program management
3. Strong written and verbal communication skills
4. High work ethics and ability to partner with different stakeholders
5. Strong influencing, networking and advisory skills
6. Ability to balance business objectives with privacy requirements.
7. Proficient in collaborating across diverse teams, Businesses and functions.
8. Detail-oriented and capable of handling sensitive information with discretion
Measures of Success
1. Timely closure of all gaps emanating from assessments
2. Accuracy and complete visibility and traceability of data flow in organization
3. Privacy Risk culture awareness and adoption across the function
4. Reduction in spurious call
5. Timely consequent management and closure of cases investigated