Governance Risk and Compliance Expert (Full remote - Europe)

 Posted 2 hours ago
     
5-10 years experience
Apply Now

Please mention DailyRemote when applying

AI Summary

The role involves turning legal and governance requirements into concrete documentation and processes across ICT systems. Key tasks include preparing RoPAs and DPIAs, validating technical data protection arrangements, and providing privacy-by-design input for projects.

Governance Risk and Compliance Expert (GRCE)

About the mission

Frontex's Digital Services Unit (DIG) is reinforcing its capacity to handle personal data protection and privacy compliance across its ICT environment. As GRCE, you'll support Frontex in applying Regulation in practice — turning legal and governance requirements into concrete documentation, processes and follow-up actions across multiple ICT systems, projects and procurements.

What you'll be doing

  • Preparing, updating and improving Records of Processing Activities (RoPAs) and Data Protection Impact Assessments (DPIAs) across ICT systems

  • Drafting and maintaining privacy notices and related data protection documentation

  • Validating personal data protection documentation against technical reality, working closely with system and technical owners

  • Analysing and documenting technical arrangements relevant to data protection: access rights, logs/SIEM exports, retention, hosting, data flows, transfers and processor chains

  • Supporting technical fact-finding for personal data breach incidents (without taking over breach qualification or notification decisions)

  • Working with incomplete or inconsistent information — distinguishing confirmed facts from assumptions and structuring clear next steps for management follow-up

  • Tracking actions, gaps and remediation items, and coordinating with system owners, project teams and the Frontex DPO

  • Providing privacy-by-design input into ICT projects, system changes and procurement files

What we're looking for

  • 5+ years of IT-relevant professional experience, including 4+ years in a similar role

  • At least 5 years of personal data protection compliance experience in an ICT, EU institutional, public-sector or similarly technology-heavy environment

  • At least 3 years of hands-on experience preparing, updating or reviewing RoPAs, DPIAs, DPAs or TIAs for real systems, including data mapping and validating input from system/technical owners

  • At least 2 years of experience analysing technical arrangements relevant to data protection (access rights, logs, retention, hosting, transfers, processors)

  • Excellent understanding of EU data protection legislation, standards and compliance frameworks

  • Strong stakeholder management and communication skills across technical and non-technical audiences

Education & certifications

  • Minimum education: Master's degree or equivalent

  • At least 3 certifications among: CISA, CISM, GSNA, GCCC, ISO 27001 Lead Implementer/Auditor, ISO 27005 Risk Manager, CAP, CRISC, CISSP-ISSMP, GIAC ISO-27000 Specialist (or internationally recognized equivalents)

Languages

  • Fluent English (C1)

Work Model

  • Full remote

Location

  • Europe

Similar Jobs

See all Remote Legal jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Legal

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified