HirePortal

Data Privacy & Security Specialist

  • BT Group
  • Gurugram, India
  • INR 3,000,000 – INR 4,500,000

Job Req ID: 62151

Posting Date: 1-Sep-26

Function: Risk, Compliance and Assurance

Location: Gurugram

Salary: Competitive

About the role

Specific business area: • Acts as a senior privacy specialist for designated Corporate Units Digital portfolios. The role performs a substantial proportion of the operational and advisory activities undertaken by the Data Privacy and Security Architect, independently owning complex privacy matters, setting the expected quality of reviews and representing the privacy function in agreed business and governance discussions. The Architect retains ownership of privacy strategy, the overall CU Digital privacy posture, final accountability for the operating model, precedent-setting decisions and material legal or regulatory escalations.
Impact of the role: • Provides authoritative, risk-based privacy advice that business and technology leaders can rely on when making decisions. The role leads complex assessments and investigations, determines required privacy outcomes within delegated authority, challenges unacceptable processing, and drives remediation to closure. It protects colleagues, strengthens audit and regulatory readiness, and enables responsible use of data, including AI and digital solutions.
Link to strategy: • Directly strengthens BT’s trusted and responsible use of data by embedding privacy-by-design, influencing standards and controls, and ensuring material privacy risks are visible to the right decision-makers. The role converts themes from PIAs, investigations and assurance into improvements across Corporate Units Digital and supports innovation at pace without compromising legal, regulatory or policy requirements.

What you’ll be doing

• Lead and determine the outcome of complex Privacy Impact Assessments and DPIAs, including high-risk data uses, colleague monitoring, profiling, AI, analytics and cross-border processing.
• Decide whether identified privacy risks can be accepted within delegated authority, require further mitigation, or must be escalated to the Data Privacy and Security Architect, Legal, Global Privacy Leads, Data Council or another accountable governance body.
• Lead complex privacy investigations involving incidents, complaints, suspected misuse, inappropriate access, retention failures or control weaknesses; establish facts, assess impact, determine root cause and issue defensible findings.
• Provide robust challenge to Directors, Product Owners, Delivery Leads, Architects and other senior stakeholders where proposed processing does not meet legal, policy or privacy-by-design expectations.
• Represent the Data Privacy function in governance forums, design reviews, risk discussions, audit activity and programme boards, ensuring privacy considerations influence decisions at the appropriate stage.
• Provide quality assurance and peer review for work completed by Data Privacy and Security Professionals, set expectations for evidence and documentation, and coach colleagues on complex or sensitive cases.
• Own the privacy position for complex supplier and contractual arrangements, identifying required data protection terms and controls and engaging Legal and Procurement within their respective remits.
• Direct the assessment of data landscapes, access controls, minimisation, retention, deletion, classification, labelling and international transfers, requiring corrective action where arrangements are insufficient.
• Own material privacy risks and remediation actions for assigned portfolios, agree proportionate treatment plans with accountable business owners, challenge slippage and escalate where exposure remains outside tolerance.
• Produce authoritative, concise and audit-ready privacy opinions, investigation reports, risk statements and senior management information, clearly recording decisions, rationale, dependencies and residual risk.
• Lead privacy input into audits, assurance reviews and regulatory enquiries, coordinating evidence and responses and ensuring identified weaknesses are addressed sustainably.
• Identify systemic and emerging risks across PIAs, investigations, incidents and assurance outcomes; translate themes into changes to standards, controls, guidance, training and operating processes.
• Support delivery of the privacy strategy, governance framework and team operating model defined by the Data Privacy and Security Architect, and deputise in specifically agreed forums or portfolio discussions when required; the role does not own overall strategy or function accountability.
• Build effective senior relationships across Legal, Security, HR, Procurement, Architecture, Audit and global privacy teams, ensuring accountability remains clear and specialist decisions are taken by the correct function.
• Manage a complex portfolio independently, prioritising according to risk and business impact while maintaining confidentiality, procedural fairness and a complete decision trail.
• Retain clear escalation boundaries: the Data Privacy and Security Architect remains accountable for CU Digital privacy strategy, final precedent-setting decisions, material legal or regulatory positions, senior Legal leadership engagement and the overall privacy function roadmap and posture.

Essential Skills / Experience

• Strong working knowledge of data protection principles and how they apply in a large, complex business environment, including GDPR and relevant Indian data protection requirements.
• Significant practical experience leading and determining complex PIAs/DPIAs and providing authoritative, risk-based privacy advice.
• Experience investigating privacy, compliance, data handling or control issues and producing clear, evidence-based findings and actions.
• Ability to analyse complex processing, data flows, contracts and control information, identify the material issues and reach balanced conclusions.
• Proven ability to operate with substantial independence, exercise delegated authority and constructively challenge senior stakeholders and accountable business owners.
• Ability to distinguish privacy responsibilities from those owned by Legal, Security, Procurement, HR or the business, and to engage or escalate appropriately.
• Strong written communication, including concise, audit-ready review notes, risk statements, investigation reports and senior summaries.
• Strong influencing and stakeholder leadership across business, technology, legal, security, HR, suppliers and global teams, including representation in governance forums.
• Ability to manage multiple priorities, maintain clear records and drive agreed actions through to closure.
• High standards of integrity, discretion and confidentiality when handling sensitive colleague and business information.

Desirable Skills / Experience

• CIPP/E preferred, or an equivalent recognised privacy qualification. Legal knowledge or a relevant legal, compliance, audit or investigations qualification is also desirable.
• Experience reviewing data protection clauses, controller and processor responsibilities, international transfers and supplier processing arrangements.
• Experience of colleague or employee data privacy, including working with HR data and cross-border processing.
• Knowledge of data retention, deletion, access controls, information classification and data governance.
• Awareness of privacy risks arising from AI, analytics and emerging technologies.
• Experience supporting audits, assurance reviews, remediation programmes or regulatory enquiries.
• Experience coaching privacy professionals, setting quality expectations and providing authoritative peer review without formal line-management responsibility.

BT Group is the UK’s leading communications group and the holding company behind some of the country’s most recognised brands – including BT, EE, Openreach and Plusnet. Our purpose is as simple as it is ambitious: we connect for good. Our customers include consumers, small, medium and large businesses, public sector organisations and other communications providers.

BT Group’s role is about setting direction, unlocking value and creating the conditions for our brands and businesses to thrive.

Having come through the most capital-intensive phase of our fibre investment, our focus now is on what comes next – simplifying how we operate, using technology and AI to work smarter, and organising ourselves to serve customers better and grow sustainably. Group teams shape strategy, policy, brand, capital allocation and transformation, helping the whole organisation perform at its best.

We have a singular culture that unites all our people: we are customer-first challengers, who are committed, clear and connected. These behaviours unite us as one team to deliver for our colleagues, our customers, our stakeholders and the country. Joining BT Group means working at the heart of a business that matters to the UK, with the opportunity to shape decisions, influence outcomes and help set the future course of one of the country’s most important companies.

Skills

  • Data Privacy
  • Privacy Impact Assessment
  • GDPR
  • Risk assessment
  • Regulatory Compliance
  • Privacy by Design
  • Data Governance

Related jobs

BT GroupApply for this job