Senior Privacy & GRC Lead

🏢 VB Spine, LLC · all VB Spine, LLC jobs
📍 India
📅 Posted 2026-08-15 · via Himalayas
🏷 Privacy-and-GRC-Lead,Privacy-Compliance,Governance-Risk-And-Compliance,Data-Privacy-Officer,Regulatory-Compliance,Governance-Risk-And-Compliance-Sr.-Privacy-Engineer,Senior-Privacy-Compliance-Consultant,Senior-Governance-Risk-And-Compliance-Specialist,Privacy-Compliance-Director,Senior-Security-GRC-Analyst,Privacy-and-Compliance-Program-Manager
Apply on original site ↗
Sr. Privacy & GRC Lead Location: India (Remote) Company: VB Spine Looking for a career where your work truly matters? At VB Spine, you’ll be part of a mission-focused team supporting innovation and better patient outcomes in spine care. As the Sr. Privacy & GRC Lead, you will lead the global Privacy and Governance, Risk & Compliance program, helping ensure the organization operates in alignment with applicable privacy laws, regulatory requirements, internal controls, and industry best practices. What You’ll Do: - Lead the development, implementation, and continuous improvement of the global Privacy and GRC programs - Develop and maintain privacy policies, standards, procedures, and governance frameworks aligned with GDPR and other applicable global privacy regulations - Lead Privacy Impact Assessments, Data Protection Impact Assessments, Transfer Impact Assessments, and other privacy risk assessments - Maintain Records of Processing Activities and oversee global data mapping activities - Monitor changes in global privacy laws and recommend updates to policies and business practices - Serve as a key advisor to Legal, Security, IT, HR, Procurement, and business leaders on privacy and compliance matters - Lead governance, risk assessment, compliance monitoring, internal control, and enterprise GRC activities - Coordinate internal audits, compliance assessments, regulatory reviews, remediation activities, and audit readiness - Develop and monitor compliance metrics, KPIs, and key risk indicators - Oversee Data Subject Rights requests including access, deletion, correction, and portability - Lead privacy incident investigations, breach response activities, corrective actions, and applicable regulatory notification processes - Lead third-party privacy and compliance reviews, including vendor risk assessments and Data Processing Agreements - Partner with Legal, Procurement, IT, and Security to support third-party risk management and remediation - Promote Privacy by Design and Privacy by Default principles across new technologies, applications, and business processes - Provide guidance related to secure data handling, retention, disposal, and international data transfers - Present privacy and GRC program updates, risks, and remediation activities to senior leadership - Lead privacy awareness and employee training initiatives - Coach and develop Privacy and GRC team members - Drive continuous improvement across privacy, compliance, governance, and risk processes What You Bring: - Bachelor’s degree in Information Security, Cybersecurity, Information Technology, Business, Law, Data Privacy, or a related field preferred; equivalent professional experience may be considered - 5+ years of experience in privacy, governance, risk management, compliance, cybersecurity, audit, or a related field - Experience implementing GDPR and other international privacy regulations - Hands-on experience with PIAs, DPIAs, TIAs, ROPAs, and privacy risk assessments - Experience supporting compliance audits, regulatory assessments, controls, and remediation activities - Experience with third-party risk management, vendor privacy assessments, and DPAs - Strong understanding of governance, enterprise risk management, internal controls, and compliance frameworks - Ability to lead cross-functional initiatives and influence stakeholders across multiple business functions - Strong analytical, organizational, communication, and problem-solving skills - Ability to work independently, exercise sound judgment, and manage multiple priorities - Experience within medical device, healthcare, life sciences, or another regulated industry is preferred - Experience with GRC platforms and enterprise risk management frameworks is preferred - Certifications such as CIPP/E, CIPM, CISSP, CISM, CRISC, or CISA are preferred - Knowledge of ISO 27701 and global privacy frameworks is a plus - Fluency in English required Physical & Mental Requirem

← All remote jobs