Back

Governance Risk and Compliance Expert (Warsaw, remote) – EU Public Institutions

Worldwide Salaried Open

Governance Risk and Compliance Expert (Warsaw, remote) – EU Public Institutions Profile: Governance Risk and Compliance Expert (GRCE) in support of DIG personal data protection activities (Data Protection, Data Privacy, Personal Data). Advanced Level. Place of performance: 100% remote. Duration of the mission: 48 months. Security Clearance: Confidential / EU Confidential. Minimum level of education: Level 7. Minimum English language skills: C1. Minimum IT relevant experience: 5 years (4 years in relevant Governance Risk roles). Award Criteria: 65% Price / 35% Quality. Minimum required scoring for interview: 70%. Rate: 475-495€/day NWH; 850-860€/day EWH. · Estimated NWH: 220days x4 years. · Estimated EWH: 10days x4 years. Required technical certificates: At least 3 certification among: · CISA (Certified Information Systems Auditor). · CISM (Certified Information Security Manager). · GSNA (GIAC Certified Systems and Network Auditor). · GCCC (GIAC Certified Critical Controls). · ISO 27001 Lead implementer. · ISO 27001 Lead Auditor. · ISO 27005 Risk Manager. · CAP ((ISC)2 Certified Authorization Professional). · CRISC (ISACA Certified in Risk and Information Systems Control). · CISSP-ISSMP ((ISC)2 Certified Information Systems Security Management Professional). · GIAC Certified ISO-27000 Specialist. · Or equivalent certification recognized internationally (subject to acceptance as a valid credential by the Contracting EU-I). Knowledge and Skills · [01] Excellent knowledge and understanding of the EU data protection legislation and regulations. · [02] Excellent knowledge of data protection standards, policies, methodologies and frameworks. · [03] Excellent knowledge and understanding of legal, regulatory and legislative compliance requirements, recommendations and best practices. · [04] Excellent knowledge and understanding of IT Operations and IT Services delivery. · [05] Practical experience with privacy impact assessment standards, methodologies and frameworks. · [06] Practical experience writing and reviewing records of processing activity on personal data for data controllers and privacy statements. · [07] Comprehensive understanding of the IT business strategy and services and ability to factor into legal, regulatory and standards’ requirements. · [08] Carry out working-life practices of the data protection and privacy issues involved in the implementation of the organizational and IT processes. · [09] Lead the development of appropriate standards and privacy policies and procedures that complement the business needs and legal requirements; further ensure its acceptance, comprehension and implementation and communicate it between the involved parties. · [10] Explain and communicate data protection and privacy topics to different types of audience. · [11] Understand, practice and adhere to ethical requirements and standards. · [12] Understand legal framework modifications implications to the organisation’s data protection strategy and policies. Specific Expertise · [01] - PSF - At least 5 years of personal data protection compliance experience in an ICT, EU institutional, public-sector or similarly technology-heavy environment, including hands-on work with real systems, services or processing activities. · [02] - PSF - At least 3 years of hands-on experience preparing, updating or reviewing RoPAs, DPIAs, DPA, TIA or related personal data protection documentation for real systems or processing activities, including data mapping and obtaining or validating input from system owners, technical owners, architects, operations, cybersecurity/SOC teams or vendors. · [03] - PSF - At least 2 years of experience analysing and documenting technical arrangements relevant to personal data protection, including access rights, privileged access, logs or SIEM/log exports, retention, hosting, data flows, support access, transfers, processors or subprocessors. · [04] - PSF - At least 2 years of experience analysing and documenting technical arrangements relevant to personal data protection, including data flows, access rights, privileged access, logs or SIEM/log exports, retention, hosting, support access, transfers, processors or subprocessors. · [05] - INT - Ability to work with incomplete or inconsistent ICT-related information, distinguish confirmed facts, assumptions, open questions and missing evidence, identify gaps or contradictions between declared system behaviour and likely technical reality, and structure clear next steps or status for review or management follow-up. Tasks and Responsibilities · Ensure compliance of IT operations with data privacy and data protection standards, laws and regulations. · Assist in designing, implementing, auditing and compliance testing activities in order to Ensure data and privacy compliance. · Identify, document and propose countermeasures to compliance gaps (if any). · Advise on data protection matters, in particular in the context of personal data processing. · Conduct privacy impact assessments. · Write and/or review records of processing activity on personal data for data controllers and privacy statements. · Develop, maintain, communicate and train upon the data privacy policies and procedures. · Provide legal advice and guidance on data privacy and data protection standards, laws and regulations. · Enforce and advocate organisation’s data privacy and protection program. · Ensure that data owners, holders, controllers, processors, subjects, internal or external partners and entities are informed about their data protection rights, obligations and responsibilities. · Act as a contact point to handle queries and complaints regarding data processing. · Monitor audits and data protection related training activities. · Cooperate and share information with authorities and professional groups. · Contribute to the development of the organisation’s strategy, policy and procedures. · Develop and propose staff awareness training to achieve compliance and foster a culture of data protection within the organization. · Manage legal aspects of information security responsibilities and third-party relations. Travel: By default, travelling in the interest of service is not foreseen for this position/profile. · Nevertheless, Frontex may exceptionally request to carry out some services at other locations than Frontex Headquarters or other Contracting Authority’s premises. Apply To This Job

More jobs

Scheduler/Logistician

Worldwide Salaried

Do Not Apply - Data Visualization Specialist 6/15/2026, 6:03:03 AM

Worldwide Salaried

Do Not Apply - Data Center Technician 6/15/2026, 6:04:02 AM

Worldwide Salaried

Senior Backend / Infrastructure Engineer (m/w/d) für das INSPO Team // Remote möglich

Worldwide Salaried

Senior Backend / Infrastructure Engineer (m/w/d) für das INSPO Team // Remote möglich

Worldwide Salaried

Senior Backend / Infrastructure Engineer (m/w/d) für das INSPO Team // Remote möglich

Worldwide Salaried

Maths teacher Analysis and approaches SL /HL

Worldwide Salaried

Paid Ads Specialist

Worldwide Salaried

Cloud Engineer - T Cloud Public (REF5058E)

Worldwide Salaried

Growth Marketing Manager

Worldwide Salaried

Healthcare Scheduler PART TIME

Worldwide Salaried

Experienced Data Analyst and Online Chat Assistant – Remote Opportunity at arenaflex

Worldwide Salaried

Experienced Remote Data Entry Specialist – Flexible Online Research Opportunities

Worldwide Salaried

Cloud Solution Architect - LatAm POD Lead

Worldwide Salaried

Mental Health Therapist Teletherapist (LCSW, LPC, or LCP)

Worldwide Salaried

Market Development Specialist

Worldwide Salaried

Experienced Data Entry Specialist – Call Support for arenaflex in the USA

Worldwide Salaried

Job Title: Entry-Level Remote Data Entry Specialist – Join arenaflex's Dynamic Entertainment Team (No Experience Required)

Worldwide Salaried

Experienced Virtual Customer Support Representative – Work from Home Opportunity

Worldwide Salaried

Transportation Support CoAustin

Worldwide Salaried