Apply Edge Start your job search

Staff Data Privacy

Razorpay · Greater Bengaluru Area

Apply & track with Apply Edge
Key Responsibilities: A. Privacy Programme Management & Regulatory OperationsOwn the operationalisation of DPDP Act 2023 and GDPR requirements across Razorpay products, systems, and vendor stack — in coordination with the HeadManage and continuously improve the Record of Processing Activities (RoPA), consent framework, data subject rights workflows, and data classification registerLead execution of Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) — with increasing automation over timeOversee cross-border data transfer compliance: SCCs, adequacy decisions, and DPDP cross-border transfer rulesCoordinate with the Head for regulatory audits (RBI/SEBI), data privacy reviews, and incident reporting timelinesEnforce consent, purpose limitation, data minimisation, and retention policies in live production systemsB. Technical Privacy Posture & Assessment DeliveryLead and conduct infrastructure privacy reviews of cloud environments (AWS/GCP/Azure) — access controls, encryption, data residency, audit loggingDrive vendor and SaaS tool assessments beyond standard questionnaires — review actual data flows, API integrations, and technical configurationsOwn the technical quality of privacy assessments produced by the team — review, calibrate, and ensure regulatory alignmentMonitor control effectiveness across production systems; identify gaps and partner with engineering to define remediationBuild and maintain the team's assessment methodology, templates, and scoring frameworksC. AI Systems Privacy & Governance (LLM-Focused)Own Razorpay's AI tool onboarding and privacy review process — from intake to sign-offLead privacy assessments of LLM-powered tools, internal AI agents, and third-party AI integrations, with focus on data input, storage, retention, and cross-border sharingBuild and maintain the AI privacy onboarding framework: checklists, risk registers, approval workflows, and exception managementDefine and document AI-specific privacy risks: prompt data leakage, model memory, third-party AI provider data usage, and agentic system data accessEmbed Privacy-by-Design into AI product lifecycles — engaging product and engineering teams from ideation through to inferenceTrack third-party AI provider privacy policies (OpenAI, Anthropic, Google, etc.) and maintain a current compliance alignment registerD. Compliance Automation & AI-Powered Privacy OperationsDesign, build, and maintain AI-assisted compliance workflows — DPIA generation, evidence collection, control testing, and risk flaggingCreate and maintain compliance dashboards that give engineering, product, and leadership real-time visibility into privacy postureDevelop standardised playbooks, checklists, and templates that enable product teams to self-serve privacy reviews with confidenceEvaluate and validate the accuracy and regulatory alignment of AI-generated compliance outputs before they are accepted as formal evidenceContinuously improve the team's tooling stack — GRC platforms, privacy management tools, AI assistants — for maximum operational leverageE. Team Leadership & Stakeholder ManagementDirectly manage, mentor, and develop the Lead Compliance Engineer — Privacy; set clear goals, unblock work, and drive their professional growthAct as the primary point of contact for engineering, product, legal, and business teams on day-to-day privacy mattersTranslate privacy requirements and risk findings into actionable, prioritised guidance for technical and non-technical stakeholdersSupport the Head with board-level and leadership reporting — prepare data, evidence packages, and risk summariesMaintain the privacy incident register, manage incident response timelines, and ensure regulatory reporting deadlines are metDrive a culture of privacy-as-enabler within the organisation — position compliance as a feature, not a gateSkills Required : 6–8 total years in privacy, compliance, or security — with at least 2 years in a hands-on technical capacityHas operationalised both frameworks in production — not just mapped policies. Can identify gaps without being prompted.Can assess LLM data handling, prompt pipelines, model memory, RAG architectures, and third-party AI provider risks.Can assess cloud infra, APIs, and SaaS integrations for privacy risk — going beyond questionnaires to actual technical evidence.Has designed or significantly improved automated compliance workflows using AI tools, scripting, or GRC platforms.Has managed IC-level compliance or security professionals; can communicate privacy risk clearly to both engineers and executives.Working knowledge of FinTech-specific data obligations applicable to a payment aggregator contextUnderstands data flow design, pseudonymisation, tokenization, encryption-at-rest and in transit, and SDLC privacy gates.Can read AWS/GCP/Azure architecture diagrams to identify data egress risks, misconfigured IAM, and storage issues.Developing familiarity with AI fairness, explainability, consent, and auditability frameworks for regulated contexts