About the role
Senior GRC, Privacy & Data Protection Consultant
Role Overview
We are looking for a highly skilled Senior GRC, Privacy & Data Protection Consultant to support governance, risk management, compliance, and personal data protection activities within a complex European institutional IT environment.
The consultant will contribute to the identification and assessment of privacy risks across IT systems, conduct and maintain Data Protection Impact Assessments (DPIAs) and Transfer Impact Assessments (TIAs), analyse changes affecting IT services and data processing activities, and support the development of governance and compliance frameworks. The role also includes contributing to policy and procedure development, compliance monitoring, audit activities, regulatory research, and awareness initiatives.
The ideal candidate combines strong expertise in EU data protection legislation with practical experience in information governance, risk management, internal controls, auditing, and cybersecurity compliance.
Key Responsibilities
Governance, Risk and Compliance (GRC)
- Support the establishment, implementation and continuous improvement of Governance, Risk and Compliance (GRC) processes.
- Develop, review and maintain policies, procedures, standards, guidelines, and governance documentation related to privacy, information security, and compliance.
- Support compliance assessments, internal control activities, and regulatory monitoring programmes.
- Participate in internal and external audits, prepare audit evidence, analyse findings, and follow up remediation actions.
- Contribute to risk management activities by identifying, evaluating, documenting, and monitoring privacy and compliance risks.
- Produce reports and recommendations for management, governance bodies, and compliance stakeholders.
Privacy Risk Assessment and Compliance
- Identify and assess Personal Data Protection (PDP) criticality across IT systems through questionnaires, interviews, and stakeholder consultations.
- Carry out and maintain PDP Critical Scoring (severity in case of personal data breaches).
- Perform and update General Risk Analysis and Mitigation (GRAM) assessments.
- Conduct, review and update Data Protection Impact Assessments (DPIAs).
- Conduct and maintain Transfer Impact Assessments (TIAs).
- Analyse notifications of changes affecting IT solutions, cloud services, processors, and sub-processors.
- Assess the impact of technical, organisational, contractual, and operational changes on personal data processing activities.
- Evaluate safeguards and controls to ensure compliance with GDPR, Regulation (EU) 2018/1725, and applicable data protection requirements.
- Provide pragmatic recommendations to mitigate identified risks.
Audit and Assurance
- Support compliance reviews and privacy audits of IT systems and data processing activities.
- Assess implementation and effectiveness of privacy and security controls.
- Verify compliance with approved policies, procedures, and regulatory obligations.
- Assist in the preparation of audit reports, management responses, and corrective action plans.
- Track remediation activities resulting from audits, assessments, and inspections.
Regulatory Analysis and Legal Monitoring
- Monitor developments in European and international data protection legislation.
- Research and analyse relevant case law and regulatory decisions from:
- Court of Justice of the European Union (CJEU);
- European Data Protection Supervisor (EDPS);
- European Data Protection Board (EDPB);
- National Data Protection Authorities of EU Member States.
- Translate legal and regulatory developments into operational and technical recommendations.
- Produce briefings, reports, and position papers for management and technical stakeholders.
Awareness and Stakeholder Engagement
- Develop training material, awareness campaigns, guidance documents, and communication material related to privacy and compliance.
- Deliver workshops and awareness sessions for technical and business stakeholders.
- Support Data Protection Officers (DPOs), Information Security Officers, ICT teams, procurement teams, legal services, and business owners.
- Promote Privacy by Design and Privacy by Default principles throughout the system lifecycle.
Required Qualifications
- University degree in Law, Information Security, Computer Science, Information Systems, Risk Management, Compliance, or a related field.
- Minimum 5 years of professional experience in privacy, compliance, governance, risk management, auditing, or related disciplines.
- Proven experience performing:
- DPIAs;
- TIAs;
- Privacy Risk Assessments;
- Compliance Reviews;
- Audit Activities.
- Strong knowledge of:
- GDPR (EU 2016/679);
- Regulation (EU) 2018/1725;
- International Data Transfers;
- Privacy by Design and by Default principles.
- Experience drafting policies, standards, procedures, and governance documentation.
- Experience working with risk management methodologies and control frameworks.
- Excellent analytical, reporting, stakeholder management, and communication skills.
- Professional fluency in English.
Desirable Qualifications
- Experience working in European Institutions, EU Agencies, or large public-sector organisations.
- Knowledge of:
- ISO 27001;
- ISO 27701;
- NIST Cybersecurity Framework;
- NIST Privacy Framework;
- COBIT;
- Risk Management Frameworks.
- Experience supporting compliance with cybersecurity and data governance regulations.
- Professional certifications such as:
- CIPP/E;
- CIPM;
- CIPT;
- ISO 27001 Lead Auditor;
- ISO 27701 Lead Implementer/Auditor;
- CRISC;
- CISA.
- Experience reviewing cloud services, processors, and sub-processors.
- Knowledge of third-party risk management and supplier assurance processes.
- Experience preparing awareness materials and training programmes.
Millions of jobs, with real people getting hired every day
Questions, answered
Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.
Yes. This role at Indra Group was screened before publishing – we confirmed the employer before listing it.
The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.
This position can be done from anywhere, with no in-office requirement.
Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.
