Senior Privacy & GRC Lead
🏢 VB Spine, LLC · all VB Spine, LLC jobs
📍 India
📅 Posted 2026-08-15 · via Himalayas
🏷 Privacy-and-GRC-Lead,Privacy-Compliance,Governance-Risk-And-Compliance,Data-Privacy-Officer,Regulatory-Compliance,Governance-Risk-And-Compliance-Sr.-Privacy-Engineer,Senior-Privacy-Compliance-Consultant,Senior-Governance-Risk-And-Compliance-Specialist,Privacy-Compliance-Director,Senior-Security-GRC-Analyst,Privacy-and-Compliance-Program-Manager
Apply on original site ↗Sr. Privacy & GRC Lead
Location: India (Remote)
Company: VB Spine
Looking for a career where your work truly matters? At VB Spine, you’ll be part of a mission-focused team supporting innovation and better patient outcomes in spine care. As the Sr. Privacy & GRC Lead, you will lead the global Privacy and Governance, Risk & Compliance program, helping ensure the organization operates in alignment with applicable privacy laws, regulatory requirements, internal controls, and industry best practices.
What You’ll Do:
- Lead the development, implementation, and continuous improvement of the global Privacy and GRC programs
- Develop and maintain privacy policies, standards, procedures, and governance frameworks aligned with GDPR and other applicable global privacy regulations
- Lead Privacy Impact Assessments, Data Protection Impact Assessments, Transfer Impact Assessments, and other privacy risk assessments
- Maintain Records of Processing Activities and oversee global data mapping activities
- Monitor changes in global privacy laws and recommend updates to policies and business practices
- Serve as a key advisor to Legal, Security, IT, HR, Procurement, and business leaders on privacy and compliance matters
- Lead governance, risk assessment, compliance monitoring, internal control, and enterprise GRC activities
- Coordinate internal audits, compliance assessments, regulatory reviews, remediation activities, and audit readiness
- Develop and monitor compliance metrics, KPIs, and key risk indicators
- Oversee Data Subject Rights requests including access, deletion, correction, and portability
- Lead privacy incident investigations, breach response activities, corrective actions, and applicable regulatory notification processes
- Lead third-party privacy and compliance reviews, including vendor risk assessments and Data Processing Agreements
- Partner with Legal, Procurement, IT, and Security to support third-party risk management and remediation
- Promote Privacy by Design and Privacy by Default principles across new technologies, applications, and business processes
- Provide guidance related to secure data handling, retention, disposal, and international data transfers
- Present privacy and GRC program updates, risks, and remediation activities to senior leadership
- Lead privacy awareness and employee training initiatives
- Coach and develop Privacy and GRC team members
- Drive continuous improvement across privacy, compliance, governance, and risk processes
What You Bring:
- Bachelor’s degree in Information Security, Cybersecurity, Information Technology, Business, Law, Data Privacy, or a related field preferred; equivalent professional experience may be considered
- 5+ years of experience in privacy, governance, risk management, compliance, cybersecurity, audit, or a related field
- Experience implementing GDPR and other international privacy regulations
- Hands-on experience with PIAs, DPIAs, TIAs, ROPAs, and privacy risk assessments
- Experience supporting compliance audits, regulatory assessments, controls, and remediation activities
- Experience with third-party risk management, vendor privacy assessments, and DPAs
- Strong understanding of governance, enterprise risk management, internal controls, and compliance frameworks
- Ability to lead cross-functional initiatives and influence stakeholders across multiple business functions
- Strong analytical, organizational, communication, and problem-solving skills
- Ability to work independently, exercise sound judgment, and manage multiple priorities
- Experience within medical device, healthcare, life sciences, or another regulated industry is preferred
- Experience with GRC platforms and enterprise risk management frameworks is preferred
- Certifications such as CIPP/E, CIPM, CISSP, CISM, CRISC, or CISA are preferred
- Knowledge of ISO 27701 and global privacy frameworks is a plus
- Fluency in English required
Physical & Mental Requirem