GRC Expert (Data Protection & Privacy)
do 1900 PLN/ mies.B2B
SeniorFull-time·B2B
#434331·Dodano wczoraj·1
Źródło: CycladTech Stack / Keywords
data privacydata protectioncomplianceprivacy governanceRoPADPIADPATIAaccess managementprivileged access
Firma i stanowisko
Cyclad supports international organizations in strategic projects within IT, cybersecurity, and organizational transformation. The role is part of a project executed in an advanced ICT environment focused on the development of Data Protection & Privacy Governance.
Wymagania
- Minimum 5 years of professional experience in data protection, privacy, or compliance in ICT, public sector, international organizations, or similarly complex technological environments.
- Minimum 3 years of practical experience preparing, updating, or reviewing data protection documentation (RoPA, DPIA, DPA, TIA) for real systems, services, or data processing processes.
- Minimum 2 years of experience in analyzing and documenting technical aspects of data protection such as access management, privileged access, log management/SIEM, data retention, hosting and data transfers, vendors, processors, and subprocessors.
- Very good knowledge of European regulations on data protection, privacy and compliance standards, methodologies, and frameworks, legal and regulatory requirements, IT Operations, and IT Service Delivery environments.
- At least 3 certifications required from the following: CISA, CISM, CRISC, CISSP-ISSMP, GSNA, GCCC, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, ISO 27005 Risk Manager, CAP ((ISC)²), GIAC Certified ISO-27000 Specialist, or equivalent internationally recognized certifications.
Obowiązki
- Ensuring ICT environment compliance with data privacy and data protection requirements.
- Supporting design, implementation, and audit activities in the area of data protection.
- Identifying compliance risks and gaps and recommending remedial actions.
- Advising on compliance of personal data processing and privacy governance.
- Preparing and reviewing documentation related to data protection, including RoPA, DPIA, DPA, TIA, privacy notices, and privacy statements.
- Analyzing technical aspects of data protection, including data flows, access rights and privileged access, logs, SIEM, retention mechanisms, hosting, data transfers, and cooperation models with vendors and subprocessors.
- Collaborating with system owners, architects, security teams, SOC, infrastructure, and external providers.
- Developing and maintaining policies, standards, and procedures related to data protection and privacy governance.
- Supporting organizational awareness and culture around compliance and data protection.
- Participating in audits, regulatory activities, and strategic governance initiatives.
Benefity
- 100% remote work.
- Participation in a strategic project within an international ICT environment.
- Collaboration with experts in cybersecurity, governance, and compliance.
- Opportunity to influence the development of privacy governance and data protection.
- Long-term cooperation in a stable, demanding, and expert environment.
Cyclad
321 aktywnych ofert