Governance Risk and Compliance Expert
⚲ Remote
35 000 - 40 000 PLN (B2B)
Wymagania
- CISA
- CISM
- GIAC
- ISO
Opis stanowiska
Wymagania:
- Candidates must hold at least three (3) active certifications from the following list (or direct industry equivalents):
Audit & Security: CISA, CISM, GSNA, GCCC, CISSP-ISSMP, GIAC Certified ISO-27000 Specialist
Standards & Risk: ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, ISO 27005 Risk Manager, CRISC
Authorization & Privacy: CAP ((ISC)²), CRISC
- 5+ Years in Data Protection: Solid experience navigating privacy compliance in high-tech environments (ICT, EU institutions, public sector, or tech-heavy enterprises). - 3+ Years in Privacy Documentation: Proven track record in preparing, mapping, and validating RoPAs, DPIAs, and DPAs by obtaining inputs directly from system owners, SOC teams, and network architects.- 2+ Years in Technical Auditing: Hands-on experience analyzing technical arrangements, including privileged access rights, data transfers, hosting architectures, and subcontractor data flows.- Analytical Problem-Solver: Exceptional ability to work with incomplete or conflicting IT information, separate assumptions from facts, and identify technical compliance gaps with minimal supervision.
Codzienne zadania:
- Align complex IT and cloud operations with European data privacy standards, laws, and regulations.
- Conduct and review comprehensive DPIAs (Data Protection Impact Assessments) and maintain precise Records of Processing Activities (RoPAs).
- Analyze data flows, verify access control logs, review SIEM exports, and audit data retention schemes to ensure "likely technical reality" matches declared policies.
- Provide expert counsel on data protection agreements (DPAs), Transfer Impact Assessments (TIAs), and third-party vendor management.
- Act as the primary point of contact for data privacy inquiries, complaints, and external audit cooperations.
- Design, implement, and deliver engaging privacy awareness training programs for staff to foster a proactive security culture.
- Candidates must hold at least three (3) active certifications from the following list (or direct industry equivalents):
Audit & Security: CISA, CISM, GSNA, GCCC, CISSP-ISSMP, GIAC Certified ISO-27000 Specialist
Standards & Risk: ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, ISO 27005 Risk Manager, CRISC
Authorization & Privacy: CAP ((ISC)²), CRISC
- 5+ Years in Data Protection: Solid experience navigating privacy compliance in high-tech environments (ICT, EU institutions, public sector, or tech-heavy enterprises). - 3+ Years in Privacy Documentation: Proven track record in preparing, mapping, and validating RoPAs, DPIAs, and DPAs by obtaining inputs directly from system owners, SOC teams, and network architects.- 2+ Years in Technical Auditing: Hands-on experience analyzing technical arrangements, including privileged access rights, data transfers, hosting architectures, and subcontractor data flows.- Analytical Problem-Solver: Exceptional ability to work with incomplete or conflicting IT information, separate assumptions from facts, and identify technical compliance gaps with minimal supervision.
Codzienne zadania:
- Align complex IT and cloud operations with European data privacy standards, laws, and regulations.
- Conduct and review comprehensive DPIAs (Data Protection Impact Assessments) and maintain precise Records of Processing Activities (RoPAs).
- Analyze data flows, verify access control logs, review SIEM exports, and audit data retention schemes to ensure "likely technical reality" matches declared policies.
- Provide expert counsel on data protection agreements (DPAs), Transfer Impact Assessments (TIAs), and third-party vendor management.
- Act as the primary point of contact for data privacy inquiries, complaints, and external audit cooperations.
- Design, implement, and deliver engaging privacy awareness training programs for staff to foster a proactive security culture.
🔍 Dekoder Ogłoszenia
✓ Ogłoszenie wygląda transparentnie — brak typowych czerwonych flag.