Senior Governance Risk and Compliance Expert

Posted 4 Days Ago
Be an Early Applicant
2 Locations
In-Office or Remote
Senior level
Artificial Intelligence • Big Data • Software • Automation
The Role
Ensure IT operations comply with EU data protection laws by conducting DPIAs and maintaining RoPAs; identify compliance gaps and propose countermeasures; advise stakeholders on personal data processing; develop privacy policies; deliver staff training; act as contact for data processing queries and cooperate with authorities; manage legal aspects of information security and third-party relationships.
Summary Generated by Built In

Why are you looking for a job?

If your answer ticks all the boxes, this could be the start of a great collaboration.

  • You have a curious mind - You won't understand what we're talking about if you don't 🤔
  • You want to learn more around technology - You won't survive if you don't 😱
  • You want to make the world a bit better 😇

We happen to be just like that as well. We like hacking things here and there (you included) and create scalable solutions that bring value to the world.

SquareDev? 🐿️

We use state-of-the-art technology to build solutions for our customers and our partners' customers. We make sure we stay best-in-class by participating in research projects across Europe, collaborating with top universities and enterprises on AI, Data, and Cloud.
About QnR Group

SquareDev is a member of the QnR Group, a leading technology organization specializing in end-to-end custom software solutions, Artificial Intelligence, Cybersecurity, SAP S/4HANA, SAP Business One, ServiceNow, and FinTech solutions.

As part of QnR Group's ongoing expansion — both in Greece and internationally — we are continuously hiring across a wide range of tech roles. Successful candidates may be hired by QnR Group, or another company within the Group, depending on the role and project.

Role overview

We are looking for a Senior Governance Risk and Compliance Expert to join one of our public sector clients based in Warsaw, working remotely. You will ensuring that IT operations align with EU data protection legislation, conducting privacy impact assessments, maintaining records of processing activities and advising stakeholders across the organisation on their obligations.


Requirements

The ideal candidate will be responsible for:

  • Ensuring IT operations comply with data privacy laws, regulations and standards.
  • Conducting privacy impact assessments (DPIAs) and maintaining records of processing activities (RoPAs).
  • Identifying compliance gaps and proposing practical countermeasures.
  • Advising on data protection matters, particularly around personal data processing.
  • Developing, maintaining and communicating data privacy policies and procedures.
  • Delivering staff awareness training to foster a culture of data protection.
  • Acting as the contact point for queries and complaints related to data processing.
  • Cooperating with authorities and professional groups on data protection matters.
  • Managing legal aspects of information security and third-party relations.

To excel in this role, you'll need:

  • At least 5+ years of IT experience and 4+ years in a GRC role.
  • Master’s degree in Computer Science, Engineering or a related technical field.
  • Hands-on data protection compliance experience in an ICT, EU institutional, or public-sector environment.
  • Experience in preparing or reviewing RoPAs, DPIAs, Data Processing Agreements, and Transfer Impact Assessments, including data mapping and input validation from technical owners.
  • Experience in documenting technical arrangements relevant to data protection: access rights, privileged access, logs/SIEM exports, retention, data flows, processors and subprocessors.
  • Deep knowledge of EU data protection legislation, regulatory frameworks, and privacy standards.
  • Ability to work with incomplete or inconsistent ICT information, distinguishing facts from assumptions, identifying gaps and structuring clear follow-up.
  • Strong communication skills, able to explain data protection topics to both technical and non-technical audiences.
  • English C1 level certification.

Certifications you'll need:

At least 3 certifications from the following:

  • CISA — Certified Information Systems Auditor
  • CISM — Certified Information Security Manager
  • GSNA — GIAC Systems and Network Auditor
  • GCCC — GIAC Critical Controls
  • ISO 27001 Lead Implementer
  • ISO 27001 Lead Auditor
  • ISO 27005 Risk Manager
  • CAP — (ISC)² Certified Authorization Professional
  • CRISC — ISACA Certified in Risk and Information Systems Control
  • CISSP-ISSMP — (ISC)² Information Systems Security Management Professional
  • GIAC Certified ISO-27000 Specialist
  • or internationally recognised equivalent (subject to EU-I acceptance)

Nice to have

  • Prior experience in an EU institutional environment.
  • Familiarity with the practical implications of evolving EU legal frameworks on organisational data protection strategy.
  • Experience collaborating across multidisciplinary teams including cybersecurity, SOC, and architecture functions.

Skills Required

  • At least 5+ years of IT experience and 4+ years in a GRC role
  • Master's degree in Computer Science, Engineering or related technical field
  • Hands-on data protection compliance experience in an ICT, EU institutional, or public-sector environment
  • Experience preparing or reviewing Records of Processing Activities (RoPAs), DPIAs, Data Processing Agreements, and Transfer Impact Assessments
  • Experience with data mapping and input validation from technical owners
  • Experience documenting technical arrangements: access rights, privileged access, logs/SIEM exports, retention, data flows, processors and subprocessors
  • Deep knowledge of EU data protection legislation, regulatory frameworks, and privacy standards
  • Ability to work with incomplete or inconsistent ICT information and structure clear follow-up
  • Strong communication skills; able to explain data protection topics to technical and non-technical audiences
  • English C1 level certification
  • At least 3 certifications from the listed set (e.g., CISA, CISM, GSNA, ISO 27001 Lead Implementer/Auditor, CRISC, CISSP-ISSMP, GIAC equivalents)
  • Prior experience in EU institutional environment
  • Experience collaborating with cybersecurity, SOC, and architecture teams
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
19 Employees
Year Founded: 2018

What We Do

SquareDev is an AI and data solutions company that develops secure, autonomous AI agents and provides developer tooling for building LLM-powered applications. They specialize in automating repetitive tasks, enhancing team productivity, and creating intelligent solutions for various industries.

Similar Jobs

Zapier Logo Zapier

Staff Engineer

Artificial Intelligence • Productivity • Software • Automation
Remote
32 Locations
800 Employees
211K-316K Annually

SEON Logo SEON

Senior Site Reliability Engineer

Artificial Intelligence • Cybersecurity
In-Office or Remote
28 Locations
415 Employees

Zapier Logo Zapier

Systems Engineer

Artificial Intelligence • Productivity • Software • Automation
Remote
27 Locations
800 Employees

Deepgram Logo Deepgram

Research Staff, LLMs

Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
In-Office or Remote
49 Locations
150 Employees
150K-250K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account