ABOUT THE PRACTICE
Olive Intelligence (OI) is building an independent, advisory-first cybersecurity, privacy, and responsible AI practice serving CISOs and senior executives across Indian enterprises — anchored to live regulatory mandates including the DPDP Act & Rules, SEBI CSCRF, RBI IT Governance and outsourcing directions, and CERT-In norms. We are product-independent by design: we assess, design, and advise — with recommendations anchored to risk and regulation.
ROLE OVERVIEW
You will architect and deliver the technical data protection layer beneath our privacy advisory — data discovery and classification, DLP, and cloud data security — turning policy into enforced controls and defensible evidence for DPDP, SEBI CSCRF, and RBI mandates.
KEY RESPONSIBILITIES
▪ Data security architecture — Assess client data landscapes and design classification schemes, protection policies, and control architectures across endpoint, network, email, and cloud channels.
▪ DLP delivery — Implement and tune DLP programmes end-to-end — policy design, rule authoring, incident triage workflows, false-positive reduction, and executive reporting.
▪ Cloud data protection — Deploy CASB and SSE controls for sanctioned/unsanctioned SaaS, shadow IT discovery, and data-in-motion protection across cloud services.
▪ Regulatory alignment — Map data protection controls to DPDP reasonable security safeguards, SEBI CSCRF data security requirements, and RBI IT/outsourcing directions; produce evidence trails that stand up to regulatory scrutiny.
▪ Client advisory — Advise CISOs on data security roadmaps, control rationalisation, and tooling strategy — product-independent, with recommendations anchored to risk and regulation.
MUST-HAVE: TOOLS & PLATFORMS
▪ Microsoft Purview — Information Protection (sensitivity labels), DLP policies, data lifecycle management, and eDiscovery; ideally including Purview DSPM and audit.
▪ Forcepoint DLP (or equivalent enterprise DLP such as Symantec/Broadcom or Trellix) — policy design, fingerprinting/EDM, endpoint and network channels.
▪ CASB / SSE platforms (e.g., Netskope, Microsoft Defender for Cloud Apps, Zscaler) — API and inline modes, SaaS security posture, and cloud DLP integration.
MUST-HAVE: EXPERIENCE & KNOWLEDGE
▪ 5+ years in data security engineering or consulting, with at least two full DLP or data classification programme deliveries.
▪ Working knowledge of DPDP security safeguard expectations, CERT-In directions, and BFSI regulatory context (SEBI CSCRF, RBI).
▪ Strong documentation discipline — HLD/LLD, runbooks, and control evidence packs.
GOOD TO HAVE
▪ Microsoft certifications (SC-400, SC-401, SC-100) or Forcepoint/Netskope certifications.
▪ Exposure to data discovery/DSPM tooling (BigID, Securiti.ai, Varonis) and how it feeds privacy programmes.
▪ Scripting for automation (PowerShell, Python) and KQL for Purview audit analytics.
Experience:
- Data Protection: 4 years (Preferred)
Work Location: Hybrid remote in Hyderabad, Telangana (Hyderabad District)