ABOUT THE PRACTICE
Olive Intelligence (OI) is building an independent, advisory-first cybersecurity, privacy, and responsible AI practice serving CISOs and senior executives across Indian enterprises — anchored to live regulatory mandates including the DPDP Act & Rules, SEBI CSCRF, RBI IT Governance and outsourcing directions, and CERT-In norms. We are product-independent by design: we assess, design, and advise — with recommendations anchored to risk and regulation.
ROLE OVERVIEW
You will lead DPDP Act & Rules implementation engagements from gap assessment through operationalisation — building privacy governance, consent architecture, and defensible evidence trails that withstand Data Protection Board scrutiny. This is a hands-on delivery role at the centre of our privacy advisory portfolio, working directly with client DPOs, CISOs, and legal teams.
KEY RESPONSIBILITIES
▪ DPDP implementation — Lead end-to-end DPDP gap assessments and remediation programmes: RoPA, DPIA, consent lifecycle design, Consent Manager integration, DSAR workflows, breach notification readiness, and Significant Data Fiduciary (SDF) obligations.
▪ Privacy tooling — Design, configure, and operationalise privacy management platforms — module selection, data discovery and mapping, assessment automation, cookie/consent deployment, and integration with client systems.
▪ Governance & policy — Draft DPDP-aligned privacy policies, notices, TOMs, and cross-border transfer positions; stand up privacy governance operating models and DPO support (including virtual DPO retainers).
▪ Client advisory — Run workshops with CISOs, DPOs, and boards; translate the Act & Rules into defensible, evidence-based compliance roadmaps with named regulatory obligations.
▪ Practice building — Contribute to accelerators, assessment toolkits, and points of view that differentiate OI's privacy offerings.
MUST-HAVE: TOOLS & PLATFORMS
▪ Hands-on implementation experience in at least one leading privacy management platform — OneTrust, Securiti.ai, or BigID (or an equivalent enterprise privacy tool such as TrustArc or Privado) — covering data mapping, assessments, consent, and DSAR modules.
▪ Demonstrable delivery of at least one full-cycle privacy programme (DPDP, GDPR, or equivalent) from assessment to operationalization.
MUST-HAVE: EXPERIENCE & KNOWLEDGE
▪ Deep working knowledge of the DPDP Act 2023 and DPDP Rules — consent, notice, SDF criteria, children's data, breach reporting, and penalty framework.
▪ Practical exposure to GDPR and the ability to map GDPR artefacts (RoPA, DPIA, TOMs) to DPDP equivalents for Indian and export-oriented clients.
▪ Strong client-facing communication — comfortable presenting to CISO and board-level audiences.
GOOD TO HAVE
▪ Exposure to responsible AI governance — NIST AI RMF, ISO/IEC 42001, AI-related provisions in SEBI/RBI guidance — and privacy implications of AI systems (a strong plus, as this role supports OI's converged privacy + AI advisory).
▪ Sector experience in BFSI or healthcare; familiarity with RBI, SEBI CSCRF, or IRDAI expectations.
▪ Certifications: CIPP/E, CIPM, CIPT, DCPP, or platform certifications (OneTrust Certified Professional, Securiti certification, BigID certification).
Pay: ₹1,000,000.00 - ₹2,000,000.00 per year
Experience:
- Privacy : 4 years (Preferred)
Work Location: Hybrid remote in Hyderabad, Telangana (Hyderabad District)