Summary
Overview
Work History
Education
Skills
Certification
Additional Information
Timeline
Generic

Harsimran (Simran) Kaur

Castro Valley

Summary

Dynamic information security and privacy leader, driving strategic privacy initiatives, with a significant reduction in compliance risks. Expertise in GDPR and HIPAA regulations, combined with strong leadership and cross-functional collaboration skills, ensures alignment of privacy strategies with corporate objectives and enhances organizational resilience.

Overview

10
10
years of professional experience
1
1
Certification

Work History

Certification Manager

Roche Diagnostics
11.2024 - Current
  • Directed global data privacy and compliance programs, ensuring adherence to HIPAA, GDPR, and U.S State privacy laws
  • Reduced compliance risks by 20% through risk assessments, internal audits, and training programs
  • Primary liaison for regulatory audits, engaging with supervisory authorities on data processing
  • Led privacy risk assessments, DPIAs, and AI governance reviews to ensure compliance with Generative AI regulations
  • Partnered with Legal, IT, and business units to align privacy strategies with corporate objectives

Principal Lead Compliance Analyst

Roche Diagnostics
09.2022 - 10.2024
  • Managed a team of 5+ compliance analysts, delivering privacy training, monitoring, and risk management
  • Conducted privacy and AI risk assessments, ensuring integration of privacy-enhancing technologies (PETs)
  • Developed compliance product roadmaps, ensuring alignment with global data protection regulations
  • Implemented GRC tools (ServiceNow, Archer) and compliance-as-a-service models on AWS Cloud Internal Platform

Senior Compliance Analyst

Roche Diagnostics
09.2019 - 01.2022
  • Led ISO 27001, HITRUST, SOC2, and NIST certification processes, ensuring security and regulatory compliance
  • Conducted internal audits, DPIAs, and risk analysis, working closely with legal and compliance teams
  • Built partnerships with Legal, Sales, Marketing, and IT to integrate privacy compliance into business operations

IT Analyst

Tata Consultancy Services
08.2017 - 01.2019
  • Conducted vendor risk assessments and compliance evaluations (ISO, SOC2)
  • Developed privacy policies and trained internal teams on compliance best practices

System Engineer

Tata Consultancy Services
08.2015 - 01.2017
  • Managed cybersecurity and compliance documentation for cloud and mobile security initiatives
  • Assisted with penetration testing, disaster recovery planning, and security control reviews

Education

MBA - Quality Management

Birla Institute of Science and Technology
Pilani
01.2016

B.Tech - Computer Science

Punjab Technical University
Jalandhar
01.2012

Skills

  • Privacy and Compliance: GDPR, HIPAA, CCPA, AI Governance and global regulations, PETs
  • Data Privacy: Data Protection Impact Assessments (DPIA), AI Ethics
  • Stakeholder management and strategic planning for compliance initiatives: process optimization
  • Security Certifications: ISO 27001, HITRUST, SOC 2, NIST, FedRAMP
  • Customer engagement: Data controller inquiries, security, and privacy questionnaires
  • Leadership and Collaboration: Cross-functional Partnerships, Executive Communication
  • Cloud Security: AWS

Certification

  • IAPP-CIPM
  • HITRUST Certified Practitioner
  • AWS Cloud Practitioner
  • ITIL V3 Foundation
  • Harvard Online: Data Privacy
  • Technical Risk & Compliance (OneTrust)

Additional Information

Regular speaker on privacy compliance, AI governance, and data security best practices.

Timeline

Certification Manager

Roche Diagnostics
11.2024 - Current

Principal Lead Compliance Analyst

Roche Diagnostics
09.2022 - 10.2024

Senior Compliance Analyst

Roche Diagnostics
09.2019 - 01.2022

IT Analyst

Tata Consultancy Services
08.2017 - 01.2019

System Engineer

Tata Consultancy Services
08.2015 - 01.2017

MBA - Quality Management

Birla Institute of Science and Technology

B.Tech - Computer Science

Punjab Technical University
Harsimran (Simran) Kaur