Senior Data Protection Specialist (Governance, Risk & Compliance) - Santander
hace 23 horas
Santander
ph3Responsibilities /h3ulliEnsure that IT operations comply with EU data protection and privacy standards, laws and regulations /liliSupport the design, implementation, auditing and testing of controls to ensure data protection compliance /liliIdentify, document and propose remediation actions for compliance gaps /liliProvide expert advice on data protection matters, particularly in the context of personal data processing activities /liliConduct Privacy Impact Assessments (DPIAs) and support risk analysis activities /liliDraft and review Records of Processing Activities (RoPAs), privacy notices and related documentation /liliDevelop, maintain and promote data privacy policies, procedures and awareness initiatives across the organisation /liliAct as a key point of contact for data protection queries, incidents and complaints /liliEnsure stakeholders (data owners, controllers, processors and partners) understand their data protection obligations /liliMonitor audit activities and contribute to data protection training programs /liliCollaborate with internal teams (IT, cybersecurity, operations, legal) and external stakeholders, including authorities /liliContribute to the continuous improvement of organisational data protection strategy, policies and processes /liliManage legal aspects of information security and third‑party data protection compliance /li /ulh3Requirements /h3ulliCandidates based anywhere in the European Union are welcome to apply /liliMinimum education level: Level7 (Master) /liliMinimum English level: C1 (CEFR) /liliAt least5years of relevant professional experience in IT/data protection, with a minimum of4years in a similar role /liliAt least5years of experience in personal data protection compliance in ICT, EU institutions, public sector or similar environments /liliHands‑on experience (minimum3years) preparing or reviewing RoPAs, DPIAs, DPA, TIA and related documentation /liliAt least2years of experience analysing technical environments (data flows, access management, logs, SIEM, hosting, transfers, subprocessors, etc.) /liliStrong ability to work with incomplete or inconsistent information, identify gaps and structure actionable next steps /liliAt least3 recognised certifications such as CISA, CISM, CRISC, CISSP‑ISSMP, CAP, ISO27001 Lead Implementer/Auditor, ISO27005 Risk Manager, GIAC certifications or equivalent /liliExcellent knowledge of EU data protection legislation and regulatory frameworks /liliStrong understanding of data protection standards, policies and best practices /liliSolid background in IT operations, service delivery and compliance frameworks /liliPractical experience with privacy impact assessment methodologies /liliAbility to align business strategy with legal and regulatory requirements /liliProven capability to design and implement data protection policies and procedures /liliExcellent communication skills with the ability to explain complex privacy topics to diverse audiences /liliStrong ethical mindset and ability to adapt to regulatory changes /liliTeam‑oriented approach with strong collaboration skills /li /ulh3What We Offer /h3ulliPrestigious projects within European institutions /liliInternational, innovative, and multicultural environments /liliContinuous support from a team of experts in EU projects /li /ulpIn accordance with Organic Law3/2007 of March22, the company is committed to promoting the defense and effective application of the principle of equality between men and women, preventing any type of labour discrimination based on sex, and guaranteeing equal entry opportunities. The company also promotes diversity and rejects any discrimination based on race, gender, functional diversity, religion, sexual orientation, gender identity, or any other personal or social condition, striving to build an inclusive and enriching environment. /p /p #J-18808-Ljbffr