Fortsätt till innehåll

Data Protection & Security Governance Consultant (réf.: 449)

  • Hybrid
    • LUXEMBOURG VILLE, Luxembourg, Luxembourg

Job description

Job Offer: Data Protection and Security Governance Specialist

MISSION: The primary objective is to drive the implementation and enhancement of data protection, DLP, encryption, and security governance frameworks for the Bank. This role is crucial in ensuring regulatory compliance, effective data classification, and the establishment of robust data protection measures across internal teams and third-party providers.

KEY ACCOUNTABILITIES:

  • Undertake the leadership of the Data Loss Prevention (DLP) project scope, planning, and controls implementation.

  • Govern and enhance data classification and protection frameworks by meticulously reviewing and updating policies and procedures.

  • Construct and uphold a comprehensive data inventory, meticulously mapping data flows and ownership.

  • Define, delegate, and elucidate data protection requirements across all pertinent teams and third parties.

  • Supervise the integration of data discovery/classification tools (e.g., Varonis) with DLP solutions.

  • Oversee the migration/upgrade of DLP tools (e.g., Symantec DLP replacement).

  • Revise and advocate Information Classification and Protection policies while enhancing the skill set of employees.

  • Strengthen and supervise the cryptography framework and cryptographic asset registry.

  • Ensure comprehensive key lifecycle management and address non-compliant assets/protocols promptly.

  • Engage in collaboration with project managers, IT, and business stakeholders to embed security in data-related processes and projects.

Job requirements

REQUIRED SKILLS & EXPERIENCE

  • 5+ years in IT Security with hands-on DLP, data classification, and encryption experience.

  • Strong knowledge of security frameworks (ISO 27001/2, NIST, PCI-DSS) and regulatory requirements.

  • Experience in implementing and managing DLP and data classification solutions.

  • In-depth understanding of cryptography and key management.

  • Excellent documentation, communication, and stakeholder management skills.

  • Fluency in French and English.

  • University degree in Computer Science, Information Security, or related field.

  • Relevant certifications are a plus (CISSP, CISM, CISA, GIAC, ISO 27001 Lead Implementer/Auditor, etc.).

  • Capable of working autonomously, proactive, and results-oriented.

  • Proven experience in regulated environments, preferably financial, and with third-party providers.

  • Able to prioritize, manage multiple projects, and deliver results under pressure.

or

Apply with Xing unavailable