The opportunity
Are you ready for your next career step? We are looking for an experienced Data Protection & Governance Manager to join the Data Protection & Governance team within the CISO Office.
What you'll do
Govern & Scale: Operationalise data ownership, stewardship, classification, and lifecycle/deletion controls across the business.
Manage Privacy Risk: Maintain the 2LoD risk framework, risk register, and effectiveness testing for EU privacy laws (GDPR), DORA, MaRisk, and emerging regulations like the EU AI Act.
Support the DPO & CISO: Triage the DPO mailbox, handle complex internal/external queries, and run DPO involvement and administrative processes.
Monitor & Report: Design high-impact privacy metrics, global "health checks," and executive reporting for governance forums.
Drive Execution & Compliance: Partner cross-functionally to close audit findings, manage third-party/vendor risks (DPAs, PIAs/TIAs), and run dynamic privacy awareness initiatives.
+ years of hands-on experience combining data protection/privacy risk: management with data governance (metadata, data quality, stewardship) preferably in banking, fintech, or financial services.
What they're looking for
- Proven track record building operational/NFR frameworks, risk matrices, and: registers covering personal data, privacy, and AI risks.
- Solid grasp of core InfoSec intersection points: encryption, access controls, logging, and incident response.
- Familiarity with GRC tooling (e.g., ServiceNow) and modern AI-driven risk reporting.
- Certifications (Preferred): IAPP (CIPP/E, CIPM) or Security/Risk credentials (CISA, CISM, CRISC).