Skip to main content
UniSystems

Data Protection Compliance Expert

RemotePoland only
Published
Role
Security
Experience
Senior
Employment
Full-time
Salary not disclosed
Check eligibility

Open to PL only. Set where you work from to check your eligibility.

No BS summary

Data Protection Compliance Expert with 5+ years of IT experience and 4 years in a similar role, specializing in personal data protection compliance within ICT/EU institutional/public-sector environments. Must have excellent knowledge of EU data protection legislation and hold at least 3 specific certifications. Based in Warsaw, Poland.

Core skills

Data ProtectionComplianceEU Data Protection Legislation

Required skills

CISA/CISM/GSNA/GCCC/ISO 27001 Lead Implementer/ISO 27001 Lead Auditor/ISO 27005 Risk Manager/CAP/CRISC/CISSP-ISSMP/GIAC Certified ISO-27000 Specialist

Required languages

English C1

What you'll do

  • Ensure compliance of IT operations with data privacy and data protection standards, laws and regulations.
  • Assist in designing, implementing, auditing and compliance testing activities in order to Ensure data and privacy compliance.
  • Advise on data protection matters, in particular in the context of personal data processing.
  • Conduct privacy impact assessments.
  • Write and/or review records of processing activity on personal data for data controllers and privacy statements.
  • Develop, maintain, communicate and train upon the data privacy policies and procedures.
  • Provide legal advice and guidance on data privacy and data protection standards, laws and regulations.
  • Enforce and advocate organization’s data privacy and protection program.
  • Ensure that data owners, holders, controllers, processors, subjects, internal or external partners and entities are informed about their data protection rights, obligations and responsibilities.
  • Monitor audits and data protection related training activities.
  • Develop and propose staff awareness training to achieve compliance and foster a culture of data protection within the organization.

What they require

  • A Master's degree in a relevant field.
  • At least 5 years of IT relevant professional experience.
  • 4 years in a similar position.
  • At least 5 years of personal data protection compliance experience in an ICT, EU institutional, public-sector or similarly technology-heavy environment, including hands-on work with real systems, services or processing activities.
  • At least 3 years of hands-on experience preparing, updating or reviewing RoPAs, DPIAs, DPA, TIA or related personal data protection documentation for real systems or processing activities, including data mapping and obtaining or validating input from system owners, technical owners, architects, operations, cybersecurity/SOC teams or vendors.
  • At least 2 years of experience analysing and documenting technical arrangements relevant to personal data protection, including access rights, privileged access, logs or SIEM/log exports, retention, hosting, data flows, support access, transfers, processors or subprocessors.
  • At least 2 years of experience coordinating multiple concurrent personal data protection work items and driving them to closure, including prioritization, ownership and deadline tracking, follow-up, escalation, closure evidence and version control.
  • Excellent knowledge and understanding of the EU data protection legislation and regulations.
  • Excellent knowledge of data protection standards, policies, methodologies and frameworks.
  • Excellent knowledge and understanding of legal, regulatory and legislative compliance requirements, recommendations and best practices.
  • Excellent knowledge and understanding of IT Operations and IT Services delivery.
  • Practical experience with privacy impact assessment standards, methodologies and frameworks.
  • Practical experience writing and reviewing records of processing activity on personal data for data controllers and privacy statements.
  • Required certificates, at least 3 of the among: CISA (Certified Information Systems Auditor), CISM (Certified Information Security Manager), GSNA (GIAC Certified Systems and Network Auditor), GCCC (GIAC Certified Critical Controls), ISO 27001 Lead implementer, ISO 27001 Lead Auditor, ISO 27005 Risk Manager, CAP ((ISC)2 Certified Authorization Professional), CRISC (ISACA Certified in Risk and Information Systems Control), CISSP-ISSMP ((ISC)2 Certified Information Systems Security Management Professional), GIAC Certified ISO-27000 Specialist or equivalent certification recognized internationally.
Salary not disclosed