Governance Risk and Compliance Expert
⚲ Warszawa, Białystok, Olsztyn, Gdańsk, Szczecin, Poznań, Łódź, Wrocław, Kraków, Lublin
35 000 - 40 000 PLN netto (B2B)
Wymagania
- Data
- SIEM
- Security
Opis stanowiska
Requirements:
• Candidates must hold at least three (3) active certifications from the following list (or direct industry equivalents):
Audit & Security: CISA, CISM, GSNA, GCCC, CISSP-ISSMP, GIAC Certified ISO-27000 Specialist
Standards & Risk: ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, ISO 27005 Risk Manager, CRISC
Authorization & Privacy: CAP ((ISC)²), CRISC
• 5+ Years in Data Protection: Solid experience navigating privacy compliance in high-tech environments (ICT, EU institutions, public sector, or tech-heavy enterprises).
• 3+ Years in Privacy Documentation: Proven track record in preparing, mapping, and validating RoPAs, DPIAs, and DPAs by obtaining inputs directly from system owners, SOC teams, and network architects.
• 2+ Years in Technical Auditing: Hands-on experience analyzing technical arrangements, including privileged access rights, data transfers, hosting architectures, and subcontractor data flows.
• Analytical Problem-Solver: Exceptional ability to work with incomplete or conflicting IT information, separate assumptions from facts, and identify technical compliance gaps with minimal supervision.
Responsibilities:
• Align complex IT and cloud operations with European data privacy standards, laws, and regulations.
• Conduct and review comprehensive DPIAs (Data Protection Impact Assessments) and maintain precise Records of Processing Activities (RoPAs).
• Analyze data flows, verify access control logs, review SIEM exports, and audit data retention schemes to ensure "likely technical reality" matches declared policies.
• Provide expert counsel on data protection agreements (DPAs), Transfer Impact Assessments (TIAs), and third-party vendor management.
• Act as the primary point of contact for data privacy inquiries, complaints, and external audit cooperations.
• Design, implement, and deliver engaging privacy awareness training programs for staff to foster a proactive security culture.
• Candidates must hold at least three (3) active certifications from the following list (or direct industry equivalents):
Audit & Security: CISA, CISM, GSNA, GCCC, CISSP-ISSMP, GIAC Certified ISO-27000 Specialist
Standards & Risk: ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, ISO 27005 Risk Manager, CRISC
Authorization & Privacy: CAP ((ISC)²), CRISC
• 5+ Years in Data Protection: Solid experience navigating privacy compliance in high-tech environments (ICT, EU institutions, public sector, or tech-heavy enterprises).
• 3+ Years in Privacy Documentation: Proven track record in preparing, mapping, and validating RoPAs, DPIAs, and DPAs by obtaining inputs directly from system owners, SOC teams, and network architects.
• 2+ Years in Technical Auditing: Hands-on experience analyzing technical arrangements, including privileged access rights, data transfers, hosting architectures, and subcontractor data flows.
• Analytical Problem-Solver: Exceptional ability to work with incomplete or conflicting IT information, separate assumptions from facts, and identify technical compliance gaps with minimal supervision.
Responsibilities:
• Align complex IT and cloud operations with European data privacy standards, laws, and regulations.
• Conduct and review comprehensive DPIAs (Data Protection Impact Assessments) and maintain precise Records of Processing Activities (RoPAs).
• Analyze data flows, verify access control logs, review SIEM exports, and audit data retention schemes to ensure "likely technical reality" matches declared policies.
• Provide expert counsel on data protection agreements (DPAs), Transfer Impact Assessments (TIAs), and third-party vendor management.
• Act as the primary point of contact for data privacy inquiries, complaints, and external audit cooperations.
• Design, implement, and deliver engaging privacy awareness training programs for staff to foster a proactive security culture.
🔍 Dekoder Ogłoszenia
✓ Ogłoszenie wygląda transparentnie — brak typowych czerwonych flag.