Apply Edge Start your job search

Privacy Consultant

Sftwtrs.ai · Gurugram, Haryana, India

Apply & track with Apply Edge
About usSftwtrs.AI builds enterprise AI infrastructure. Knowledge graph systems, industrial computer vision, voice AI platforms handling call volumes at national scale, and browser automation. Our clients are manufacturers, infrastructure companies, and government departments, in India and abroad.Alongside the product work we run a cybersecurity and compliance practice. Security architecture and assessment, data discovery and classification, data loss prevention, database activity monitoring, identity and access assurance, incident response, and regulatory compliance across the DPDP Act, ISO 27001 and sector frameworks. Our leadership comes from a cybersecurity and digital forensics background, so this is where the company started rather than something bolted on later.About the roleThe Digital Personal Data Protection Act came into force with the Rules published in November 2025, and the bulk of obligations commence eighteen months from that date. Government departments running citizen databases at real scale, and enterprises with data spread across two decades of systems, are all working out the same thing at once: what do we actually hold, on what basis, and what has to change.That question is answered by assessment work, and this is the assessment role.You will run gap assessments end to end. Map the data, classify the processing, test the controls, rate the risk, and hand the client a roadmap they can actually execute. Then stay long enough to see whether they did.You will not do it alone. This role sits inside our cybersecurity and compliance team, reporting to our Data Protection Officer and working alongside security architects, incident responders, and the engineers who deploy our discovery, DLP and monitoring stack. When you need to know what personal data is sitting in a client's file shares, you will have a tool and a team rather than a questionnaire.What you will doMap the data. Identify and document personal data flows across a client's systems, from collection through storage, processing, sharing and disposal. Produce the data flow register that everything else is built on.Assess the legal basis. Evaluate each processing activity against Sections 4 to 7 of the Act, classify it as consent-based, legitimate use or non-compliant, and maintain the processing register.Test the controls. Assess technical safeguards against Rule 6: encryption at rest and in transit, access controls, logging, monitoring and backup. Work with our security team where the assessment needs to go deeper than documentation.Review the harder categories. Identify processing involving children's data and assess it against Section 9 and Rule 10. Map data processors and test whether their contracts carry the provisions Rule 6(1)(f) requires. Identify cross-border transfers and assess them against Section 16.Write the report. A gap analysis with each finding risk-rated and mapped to a specific provision, a prioritised remediation roadmap with timelines and owners, and an executive summary a department secretary will actually read.Support the ongoing programme. Help draft privacy policies, consent notices, retention schedules and data subject rights procedures. Support DPIAs and DSAR handling as the practice grows.Build the method. Turn each engagement into reusable templates, checklists and tooling. The second assessment should be faster than the first.What you needEssentialA current privacy certification: CIPP, CIPM, CDPSE, or an equivalent recognised privacy credentialThree or more years working in data privacy, information security or complianceExperience conducting privacy or security assessments, and writing the report that followsWorking understanding of the DPDP Act and Rules, or a demonstrated ability to get there quickly from adjacent regulatory experienceWillingness to be named in client and tender documentation as a member of the assessment teamClear written English. Much of the value of this work is in the reportValued, not requiredA law degree, or experience working alongside legal counsel on regulatory mattersExperience with Indian public sector or PSU clientsISO 27001 lead implementer or lead auditorFamiliarity with GDPR, and the judgement to know where it does and does not map onto the DPDP frameworkHands-on experience with data discovery, classification or DLP toolingComfort reading a database schema or a network diagramWorking knowledge of HindiIf you have strong assessment experience and no privacy certification yet, apply anyway and say so. We fund certification for the right person.What this role asks of youYou may be named in client and tender documentation, with your CV and certification submitted to and verified by client organisations and procurement authorities.Assessment work runs to deadlines that are contractual. A typical gap assessment is eight weeks from kick-off to final report, and the report lands when it is due.Travel within Haryana is part of the work. Clients are in Chandigarh, Panchkula, Gurugram and elsewhere across the state, with manufacturing sites beyond it. Data mapping is difficult to do properly from a desk.What we offerCompensation. Competitive and negotiable against experience.Growth. This is a practice being built. The person who does this well moves into leading engagements, and then into leading the practice.Range. Government departments, manufacturing, infrastructure and enterprise clients. Every environment is different and none of them are tidy.Support. Certification and continuing education funded. Conference and professional body membership covered.Autonomy. A small team, short decisions, and no layer between you and the client.How to applySend a CV and a short note to [email] with the subject line Privacy Consultant Application.The note matters more than the covering letter. Tell us about an assessment where what you found was not what the client expected, and what you did about it. We read these.Please include:Certification details, with certification number and validity, or your plan to certifyAssessment or compliance engagements you would rely on, with dates and scope. Client names may be withheld if you are under confidentiality obligationsNotice period and earliest availabilityConfirmation that you are not currently a serving government employee, and that you are not a relative of an official at any procurement authority we bid to. This is a declaration requirement in government tenders where key personnel are named, so we have to ask earlyWe respond to every application.Sftwtrs.AI is the brand under which Nilesh AI Systems Pvt Ltd operates. Employment is offered by Nilesh AI Systems Pvt Ltd, CIN U46512HR2023PTC116126, Gurugram.We are an equal opportunity employer. We assess candidates on capability and judgement.