For Employers

Luzmo

Head of Security & Compliance

Posted an hour ago
€57000 - €69000 per year
5-10 years experience
Apply Now

Please mention DailyRemote when applying

?
Resume Match Score

See how much of this job your resume covers, and what’s missing.

Want a recruiter to go through it line by line?

Get professional review

Create a cover letter for this job

Upload your resume and we draft a letter for this exact role, tailored to what it asks for.

  • Tailored to this role
  • Based on your resume
  • Fully editable
AI Summary

The Head of Security & Compliance will establish and oversee security and data protection policies while acting as the company's CISO and DPO. They will report directly to the Board of Directors to ensure independent oversight of security controls, audits, and incident response processes.

The job

Luzmo is a fast-growing scale-up with a small team and limited means. Until now, security and privacy were handled by several people next to their main job. That no longer fits the clients we serve. So we are creating an independent role: a Head of Security & Compliance who sets our security and data protection policy, checks that we follow it, and tells us clearly when we don't.

You will be our CISO and our Data Protection Officer (DPO). To make sure you can do that independently, you report to our Board of Directors, not to the CTO or the founders. Our engineering team builds and runs the platform; you set the rules, test and challenge the controls, and advise. That separation is a deliberate choice.

This is a part-time role (60%), as an employee (preferred) or freelancer, from our Leuven office or remote within EU time zones.

If you want to build a security and privacy program you can stand behind, with real ownership and a direct line to the board, we'd like to talk to you.

Who we are

Luzmo is embedded AI analytics, everywhere your users work. We help data-centric companies, where data is the product, put governed, white-labeled AI analytics in front of their own customers: branded dashboards, self-service analytics, AI analytics chatbots, workflow analytics and white-labeled MCP. Build it once, and it works everywhere: in the product, in Slack or email, in ChatGPT and Claude, and in AI agents.

From our HQ in Leuven, Belgium and our office in New York, USA we serve customers across Europe and North America. We decide fast, own our work, and use AI across the company to punch above our weight.

Security and privacy are a key reason clients choose Luzmo. Clients increasingly connect their data to AI agents over MCP, in Slack, ChatGPT and Claude. As we move into larger clients and regulated sectors (telecom, banking, healthcare, public sector), security reviews, DPAs and SLAs are often part of closing a deal.

What you'll do

  • Set our security and data protection policies and standards, keep the risk register up to date and agree the priorities with management.

  • Check that the controls work in practice: review cloud and infrastructure configuration, run periodic access reviews, follow up on vulnerability and logging requirements, and manage pentests and the follow-up of findings.

  • Run our SOC2 Type II program and the yearly audit, together with the control owners in engineering.

  • Act as our Data Protection Officer: advise on and monitor GDPR compliance, DPIAs, records of processing, data subject requests and data transfers. Be the contact point for the Belgian Data Protection Authority.

  • Answer security questionnaires, advise on the security and data protection parts of client contracts, assess vendors and subprocessors, and join client calls about security.

  • Review designs of new features for security and privacy before they are built, and turn findings into clear requirements for the engineering team.

  • Own the incident response process, coordinate the response to security incidents and advise on breach notifications. Engineering does the technical fixing.

  • Organize security awareness training for everyone and secure coding training for engineers.

  • Report regularly to the Board of Directors on risks, compliance and the progress of the security program.

What you won't do (by design)

You will not run IT operations or manage the engineering team. You will not decide which personal data we process or why. You will not have commercial targets. You need to be able to look at our systems, so you get read-only access to cloud configuration and logs, and emergency access during incidents. This keeps you independent, as GDPR and the Belgian Data Protection Authority expect from a DPO.

What this job offers

  • Full ownership of security and data protection at Luzmo, with a direct line to the Board.

  • Real independence: your advice is documented, and as DPO you are legally protected against dismissal or penalties for doing your job.

  • Your own budget for tools, audits, pentests, external advice and training.

  • An exciting scale-up environment with growth opportunities.

  • Competitive salary (or day rate if you work as a freelancer).

  • Flexible holiday policy, remote working and international get-togethers.

  • The equipment, software and tech you need to do your job.


How we work

We empower success. We accomplish daily. We innovate fearlessly. Join a team of collaborative, driven and ambitious people at Luzmo.



Who we're looking for

  • 5+ years of experience in security, of which at least 2 owning security and/or compliance at a software company.

  • A technical background (e.g. as engineer, DevOps / SRE, security engineer or pentester). You can read code and cloud configuration, not only policies.

  • You have run a SOC2 Type II audit yourself.

  • Practical knowledge of GDPR: DPAs, subprocessors, international data transfers, DPIAs, breach notifications. You can take up the formal DPO role.

  • Experience with public cloud security (AWS, GCP or Azure).

  • Experience with security questionnaires, client contract reviews and security incidents.

  • You give independent advice, also when it is not what people want to hear, and you look for practical solutions.

  • You can explain security clearly to engineers, sales, clients and the board.

  • Fluent in English, written and spoken. Based in an EU time zone.

Nice to have

  • Experience with ISO 27001, NIS2, DORA or the EU AI Act.

  • Interest in AI security: LLM data flows, prompt injection, MCP / agent access control.

  • Experience at a scale-up of 50–200 people.

  • Certifications like CISSP, CISM, CCSP, OSCP or CIPP/E.

  • Dutch or French.

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Legal jobs →

 Compliance Assistant

Freelance Worldwide Legal

Regulatory Affairs Specialist I

Full Time United States Legal

Compliance Investigation Analyst

Full Time Poland 120K - 150K per year Legal

RN Consultant Sr - Professional Liability

Full Time United States $80000 - $85000 per year Legal

Assistant General Counsel

Full Time United States $200K - $240K per year Legal

Legal Counsel (f/m/d)

Full Time South Africa Legal
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Featuring 212,390+ Jobs in Legal

Answer easy questions

Answer easy questions

212,390+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified