Required Data Protection and GRC Manager
The position
Which department will you join?
You will join and head the Data Protection team, part of the Cyber Defense group, which centers on protecting our data in its corporate environments, services, and products against current cyber security threats.
You will oversee the organization's Privacy Management System, covering the privacy of customers' and employee data processed by or stored on our systems, services or products.
You will manage the team performing cyber security and privacy risk assessments, leading internal and external auditing activities, and ensuring our compliance and certification per cyber security policies, guidelines, and standards.
What will your job look like:
Monitor compliance with data protection laws and regulations, cybersecurity standards and best practices. Develop, assess and maintain clear and effective organizational Information Security and Privacy policies.
You will lead GRC activities and engage with key stakeholders in the organization to ensure cyber security and privacy risks are identified and mitigated.
You will maintain our Cyber and Privacy risk management program.
Operate and drive implementation of essential privacy operations, such as data subjects access requests, maintain records of security and personal data processing activities, and ensure notification and communication of Incidents.
Govern Privacy-by-design in our products and services.
Operate vendor and supply chain risk assessments and audits
Liaise with our legal counsel to maintain appropriate notices and records, as well as the setting of Privacy provisions with customers, partners and vendors.
You will maintain our successful compliance and certification to leading industry standards ISO 27K, TISAX, Soc2 etc.
Requirements: 5 years of Hands-On experience auditing security controls in diverse technological environments. Proven experience in leading teams in GRC activities.
In-depth knowledge of risk assessment methodologies, and the ability to translate technical security vulnerabilities into business impact assessments.
In-depth knowledge and proven certification processes with security and privacy standards and regulation frameworks (e.g., ISO27001, TISAX, GDPR, CPRA and PIPL).
In-depth knowledge of security architectural considerations, security controls design and evaluating effectiveness of implemented controls. Proven experience with Security/Privacy by design for products.
Ability to manage and prioritize simultaneous projects, related to different stakeholders, internal and external to the organization.
Excellent written and verbal communication skills, including experience producing reports and presentations (native English).
Advantages:
Information security certificate from an industry-leading organization (e.g., CISSP, CISA, CISM CIPP/e)
An academic degree (B.A/M.A/M.Sc.) in a relevant field.
Experience in the automotive industry.
This position is open to all candidates.