Senior Data Protection Consultant
Responsibilities:
- Design and implement data protection and privacy programs that cater to our clients' specific business needs, ensuring their sensitive information is well safeguarded.
- Evaluate and assess our clients' data protection and privacy practices, offering valuable insights and actionable recommendations for continual improvement.
- Demonstrate expertise in various standards, such as ISO 27001/2, ISO 22301, ISO 27018, NIST standards on Cyber Security, HITRUST, ISO 27701, etc., to assist clients in compliance and governance.
- Provide guidance and support to clients in adhering to a complex web of national and international laws and regulations, including the EU General Data Protection Regulation (GDPR) and other privacy laws.
- Assist in preparing policies, reports, and schedules for clients and relevant stakeholders, ensuring clear communication and alignment with industry best practices.
- Conduct thorough audits of Privacy controls to monitor program effectiveness and compliance, ensuring data protection is at its optimal level.
- Utilize online tools to facilitate Incident Management and Data Subject Rights processes, ensuring efficient and timely responses to potential data incidents.
- Foster and maintain productive working relationships with client personnel, promoting effective collaboration and understanding of their specific needs.
- Demonstrate a strong commitment to adhering to workplace policies and procedures, maintaining the highest standards of professionalism and confidentiality.
- Contribute to cybersecurity engagements, developing cybersecurity strategies, governance, risk, and compliance activities, and cybersecurity policies in line with ISO 27001 and ISO 27701.
- Perform Gap Assessments, Risk Assessments, ISMS Documentation, Internal Audits, and support during Certification Audits to strengthen overall security frameworks.
Requirements
- Possess a sound knowledge of fundamentals of information security systems.
- Have 4+ years of relevant experience in the field.
- Demonstrate proficiency in standards such as ISO 27001/2, ISO 22301, ISO 27018, NIST standards on Cyber Security, HITRUST, ISO 27701, etc.
- Exhibit a good understanding of GDPR, CCPA, or other privacy laws.
- Display competence in governance and reporting, as well as a strong grasp of cyber and privacy risks.
- Hold relevant qualifications such as CIPM, CIPT, CIPP/E.
- Showcase excellent communication skills, both written and verbal.
Benefits
- Competitive salary and performance-based bonuses.
- Professional development opportunities, including training and certifications.
- Flexible working hours.
- Collaborative and inclusive work environment.
- Opportunity to work with a passionate team dedicated to making a difference in data privacy and security.