Governance Risk and Compliance Expert

Job not on LinkedIn

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Qualco Technology

Qualco Technology

201 - 500 employees

💳 Fintech

🏦 Banking

☁️ SaaS

Fintech • Banking • SaaS

Qualco Technology is the technology arm of Qualco Group that delivers AI-driven, end-to-end software for credit, lending and collections management. With 25+ years of experience and clients in 30+ countries, it provides SaaS platforms for loan origination and management, collections & recoveries, supply chain finance, analytics, and business automation. Qualco focuses on helping banks, creditors and financial institutions automate workflows, ensure compliance and optimise the full credit lifecycle to drive growth.

📋 Description

• Ensure compliance of IT operations with data privacy and data protection standards, laws and regulations; • Assist in designing, implementing, auditing and compliance testing activities in order to Ensure data and privacy compliance; • Identify, document and propose countermeasures to compliance gaps (if any); • Advise on data protection matters, in particular in the context of personal data processing; • Conduct privacy impact assessments; • Write and/or review records of processing activity on personal data for data controllers and privacy statements; • Develop, maintain, communicate and train upon the data privacy policies and procedures; • Provide legal advice and guidance on data privacy and data protection standards, laws and regulations; • Enforce and advocate organisation’s data privacy and protection program; • Ensure that data owners, holders, controllers, processors, subjects, internal or external partners and entities are informed about their data protection rights, obligations and responsibilities; • Act as a contact point to handle queries and complaints regarding data processing; • Monitor audits and data protection related training activities; • Cooperate and share information with authorities and professional groups; • Contribute to the development of the organisation’s strategy, policy and procedures; • Develop and propose staff awareness training to achieve compliance and foster a culture of data protection within the organization; • Manage legal aspects of information security responsibilities and third-party relations; • Ensuring that all activities and duties are carried out in full compliance with regulatory requirements and supporting the continued implementation of the Group Anti-Bribery and Corruption Policy.

🎯 Requirements

• Master's degree; • Minimum 5 years of IT professional experience; • Minimum 4 years of experience in similar position; • At least 5 years of personal data protection compliance experience in an ICT, EU institutional, public-sector or similarly technology-heavy environment, including hands-on work with real systems, services or processing activities; • At least 3 years of hands-on experience preparing, updating or reviewing RoPAs, DPIAs, DPA, TIA or related personal data protection documentation for real systems or processing activities, including data mapping and obtaining or validating input from system owners, technical owners, architects, operations, cybersecurity/SOC teams or vendors; • At least 2 years of experience analysing and documenting technical arrangements relevant to personal data protection, including access rights, privileged access, logs or SIEM/log exports, retention, hosting, data flows, support access, transfers, processors or subprocessors; • At least 2 years of experience analysing and documenting technical arrangements relevant to personal data protection, including data flows, access rights, privileged access, logs or SIEM/log exports, retention, hosting, support access, transfers, processors or subprocessors; • Ability to work with incomplete or inconsistent ICT-related information, distinguish confirmed facts, assumptions, open questions and missing evidence, identify gaps or contradictions between declared system behaviour and likely technical reality, and structure clear next steps or status for review or management follow-up; • Comprehensive understanding of the IT business strategy and services and ability to factor into legal, regulatory and standards’ requirements; • Carry out working-life practices of the data protection and privacy issues involved in the implementation of the organizational and IT processes; • Lead the development of appropriate standards and privacy policies and procedures that complement the business needs and legal requirements; further ensure its acceptance, comprehension and implementation and communicate it between the involved parties; • Explain and communicate data protection and privacy topics to different types of audience; • Understand legal framework modifications implications to the organization’s data protection strategy, policies, practice and adhere to ethical requirements and standards; • **Excellent knowledge of: ** • EU data protection legislation and regulations; • Data protection standards, policies, methodologies and frameworks; • Legal, regulatory and legislative compliance requirements, recommendations and best practices; • IT Operations and IT Services delivery; • **Practical experience with:** • Privacy impact assessment standards, methodologies and frameworks; • Writing and reviewing records of processing activity on personal data for data controllers and privacy statements; • **At least 3 certifications among:** • CISA (Certified Information Systems Auditor); • CISM (Certified Information Security Manager); • GSNA (GIAC Certified Systems and Network Auditor); • GCCC (GIAC Certified Critical Controls); • ISO 27001 Lead implementer; • ISO 27001 Lead Auditor; • ISO 27005 Risk Manager; • CAP ((ISC)2 Certified Authorization Professional); • CRISC (ISACA Certified in Risk and Information Systems Control); • CISSP-ISSMP ((ISC)2 Certified Information Systems Security Management Professional); • GIAC Certified ISO-27000 Specialist; • or equivalent certification recognized internationally (subject to acceptance as a valid credential by the Contracting EU-I); • Very good knowledge of the English language (C2).

🏖️ Benefits

• **This role is an remote opportunity.** • **CV submitted in English.** • Your race, gender identity and expression, age ethnicity or disability make no difference in Quento we want to attract, develop, promote, and retain the best people based only on their ability and behavior. • Disclaimer: Quento collects and processes personal data in accordance with the EU General Data Protection Regulation (GDPR). We are bound to use the information provided within your job application for recruitment purposes only and not to share these with any third parties. For more details on the processing of your personal data during the Recruitment procedure, please be informed in the Recruitment Notice, before the submission of your application.

Apply Now

Similar Jobs

🕒 Yesterday

TheWhiteam

201 - 500

🤝 B2B

🏢 Enterprise

Expert in Governance Risk and Compliance for EU public institutions ensuring data protection compliance. Responsibilities include audits, documentation, and advising on data processing matters.

🗣️🇪🇸 Spanish Required

🕒 Yesterday

Uni Systems

1001 - 5000

Data Protection Compliance Expert ensuring compliance with data privacy standards at UniSystems. Conducting assessments, advising on protections, and training staff on privacy policies.

🕒 5 days ago

Revvity

10,000+ employees

🧬 Biotechnology

💊 Pharmaceuticals

⚕️ Healthcare Insurance

International Trade Compliance Specialist at Revvity ensuring compliance with global trade regulations. Managing import/export classifications and sanctions with a focus on accuracy and detail.

🕒 June 5

Worldwide Clinical Trials

1001 - 5000

🧬 Biotechnology

💊 Pharmaceuticals

⚕️ Healthcare Insurance

Specialist in Regulatory Affairs navigating regulatory landscape for clinical trials at Worldwide Clinical Trials. Ensuring compliance and submission success across multiple regions.

🗣️🇵🇱 Polish Required

🕒 June 5

Jabil

10,000+ employees

🤝 B2B

Sr. Global Compliance Specialist facilitating Jabil's compliance strategy across global operations. Collaborating on fraud detection and third-party integrity processes in a remote role.

🗣️🇵🇱 Polish Required