Personal Data Management and Information Security Officer
Personal Data Management and Information Security Officer

Personal Data Management and Information Security Officer

London Temporary 48000 - 72000 £ / year (est.) Home office (partial)
Go Premium
E

At a Glance

  • Tasks: Lead personal data protection and support information security efforts at the EBRD.
  • Company: Join the European Bank for Reconstruction and Development, promoting sustainable development across 30+ countries.
  • Benefits: Enjoy flexible working, development opportunities, and an attractive compensation package.
  • Why this job: Make a real impact in a diverse, innovative environment focused on sustainability and inclusion.
  • Qualifications: Bachelor's or Master's degree in IT, Security, or related fields; relevant certifications required.
  • Other info: Work in a dynamic team, collaborating with experts from various sectors.

The predicted salary is between 48000 - 72000 £ per year.

The European Bank for Reconstruction and Development (EBRD) is seeking a Personal Data Management and Information Security Officer to support the Head of Information Security in managing the Bank's information security and personal data protection landscape. You will play a dual role-leading on the Bank's Personal Data Protection efforts and supporting the InfoSec agenda. Your work will ensure that the Bank maintains high standards of security, privacy, and compliance, contributing to our mission of promoting sustainable development across our regions of operation.

Operational Risk Management (ORM) is part of the Bank's Risk Management group and forms the second line of defence. ORM is responsible for independently identifying, assessing, and supporting the mitigation of key operational risks, including those related to information security and personal data protection. ORM works in close collaboration with the IT Department and business units across the Bank.

You will act as the Bank's:

  • Primary Personal Data Protection Officer (PDPO) and contact point.
  • Key advisor on privacy and information security risks.
  • Manager of critical programmes, including the Bank's InfoSec and Personal Data Protection Frameworks and Training & Awareness initiatives.
  • Coordinator for internal/external reviews related to InfoSec and privacy compliance.

You will work closely with IT and business functions to identify risks, manage incidents, and advise on good practices aligned with ISO 27001 and/or NIST.

Key Responsibilities:

  • Develop, review, and update the Bank's Information Security and Personal Data Protection (PDP) Frameworks (policies, directives, guidance, and procedures).
  • Manage and implement internal training for staff and Bank users, including writing training materials and managing the Bank's eLearning platform.
  • Conduct compliance assessments to evaluate adherence to InfoSec and privacy policies and procedures.
  • Advise the Bank and data subjects on implementing, applying, and complying with the PDP Framework.
  • Provide support on incident remediation, especially in cases involving personal data breaches.
  • Respond to data subject requests and support the Personal Data Review Panel on personal data-related complaints.
  • Advise on IT and business projects with respect to InfoSec and privacy risks.
  • Maintain risk registers, provide ongoing risk analysis, and contribute to risk mitigation plans.
  • Support completion and review of Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs).
  • Manage BAU activities, including social engineering exercises, supplier assurance assessments, and risk assessments for business processes and technologies.
  • Research emerging threats and evaluate applicability to the Bank's operations.
  • Monitor changes in regulations and best practices, document and propose updates, agree on changes with the Head of Information Security, and implement project plans.
  • Work extensively with IT, particularly the IT Security team, to address technical security and risk issues with a sound understanding of underlying technologies.

Required Qualifications & Experience:

  • Education: Bachelor's or Master's degree, ideally in IT, Security, Risk Management, or a related field (other fields will also be considered).
  • Certifications: At least one recognised information security qualification (e.g., CISM, CISA, CISSM, ISO 27001 Lead Auditor/Implementer). At least one data protection certification (e.g., EU-GDPR-P, CIPP/E).
  • Technical and Professional Skills:
  • Excellent written and verbal communication and presentation skills in English.
  • Ability to present technical information in business and risk language.
  • Strong project management and problem-solving skills.
  • High attention to detail and accuracy.
  • Ability to work independently and handle multiple priorities.
  • Strong relationship management and influencing skills across all levels.
  • Expertise in:
    • Information security tools and practices (e.g., mobile device security, information classification).
    • Supplier assurance, social engineering testing, and security awareness training.
    • Privacy principles, including Privacy by Design, DPIAs, handling data subject requests, and investigating personal data breaches.

    Why Join EBRD?

    • Contribute to sustainable impact in 30+ countries.
    • Be part of a values-driven institution that fosters transparency, innovation, and inclusion.
    • Collaborate with experienced professionals in a dynamic and supportive environment.
    • Access development opportunities and an attractive compensation package.

    Our agile and innovative approach is what makes life at the EBRD a unique experience! You will be part of a pioneering and diverse international organisation, and use your talents to make a real difference to people's lives and help shape the future of the regions we invest in. The EBRD environment provides you with:

    • Varied, stimulating and engaging work that gives you an opportunity to interact with a wide range of experts in the financial, political, public and private sectors across the regions we invest in.
    • A working culture that embraces inclusion and celebrates diversity.
    • An environment that places sustainability, equality and digital transformation at the heart of what we do.

    Diversity is one of the Bank's core values which are at the heart of everything it does. A diverse workforce with the right knowledge and skills enables connection with our clients, brings pioneering ideas, energy and innovation. The EBRD staff is characterised by its rich diversity of nationalities, cultures and opinions and we aim to sustain and build on this strength. As such, the EBRD seeks to ensure that everyone is treated with respect and given equal opportunities and works in an inclusive environment. The EBRD encourages all qualified candidates who are nationals of the EBRD member countries to apply regardless of their racial, ethnic, religious and cultural background, gender, sexual orientation or disabilities. As an inclusive employer, we promote flexible working and expect our employees to attend the office 50% of their working time.

    Please note, that due to the high volume of applications received, we regret to inform you that we are unable to provide detailed feedback to candidates who have not been shortlisted.

    Personal Data Management and Information Security Officer employer: EBRD

    The European Bank for Reconstruction and Development (EBRD) is an exceptional employer, offering a dynamic and inclusive work environment in London where you can contribute to sustainable development across 30+ countries. With a strong focus on employee growth, EBRD provides access to development opportunities, a competitive compensation package, and the chance to collaborate with experienced professionals in a values-driven institution that prioritises transparency, innovation, and diversity.
    E

    Contact Detail:

    EBRD Recruiting Team

    StudySmarter Expert Advice 🤫

    We think this is how you could land Personal Data Management and Information Security Officer

    ✨Tip Number 1

    Familiarise yourself with the latest trends and regulations in information security and data protection. Being well-versed in frameworks like ISO 27001 and GDPR will not only boost your confidence but also demonstrate your commitment to the role.

    ✨Tip Number 2

    Network with professionals in the field of information security and data protection. Attend relevant workshops, webinars, or conferences to connect with industry experts and gain insights that could set you apart from other candidates.

    ✨Tip Number 3

    Prepare to discuss real-world scenarios where you've successfully managed data protection or information security challenges. Having concrete examples ready will showcase your problem-solving skills and practical experience during interviews.

    ✨Tip Number 4

    Stay updated on emerging threats and best practices in the field. This knowledge will not only help you in interviews but also show that you're proactive about continuous learning and adapting to the evolving landscape of information security.

    We think you need these skills to ace Personal Data Management and Information Security Officer

    Personal Data Protection Knowledge
    Information Security Management
    ISO 27001 Familiarity
    NIST Framework Understanding
    Compliance Assessment Skills
    Incident Remediation Expertise
    Risk Management Proficiency
    Privacy Impact Assessment (PIA) Skills
    Data Protection Impact Assessment (DPIA) Skills
    Strong Written and Verbal Communication
    Project Management Skills
    Attention to Detail
    Relationship Management
    Technical Security Knowledge
    Supplier Assurance Experience
    Social Engineering Testing Skills
    Training and Awareness Programme Development

    Some tips for your application 🫡

    Tailor Your CV: Make sure your CV highlights relevant experience in information security and personal data management. Use keywords from the job description to demonstrate that you meet the qualifications and skills required for the role.

    Craft a Compelling Cover Letter: Write a cover letter that clearly outlines your motivation for applying and how your background aligns with the responsibilities of the Personal Data Management and Information Security Officer position. Be specific about your experience with compliance assessments and risk management.

    Showcase Relevant Certifications: List any relevant certifications such as CISM, CISA, or GDPR-related qualifications prominently in your application. This will help demonstrate your expertise and commitment to the field of information security and data protection.

    Highlight Communication Skills: Since excellent communication is crucial for this role, provide examples in your application of how you've effectively communicated complex information to various stakeholders. This could include presentations, training sessions, or written reports.

    How to prepare for a job interview at EBRD

    ✨Understand the Role

    Make sure you have a clear understanding of the responsibilities and expectations of the Personal Data Management and Information Security Officer role. Familiarise yourself with the Bank's Information Security and Personal Data Protection Frameworks, as well as relevant regulations like GDPR.

    ✨Showcase Relevant Experience

    Prepare to discuss your previous experience in information security and data protection. Highlight any certifications you hold, such as CISM or CIPP/E, and be ready to provide examples of how you've successfully managed similar responsibilities in past roles.

    ✨Demonstrate Communication Skills

    Since the role requires excellent written and verbal communication skills, practice articulating complex technical concepts in simple terms. Be prepared to explain how you would communicate privacy risks and compliance issues to non-technical stakeholders.

    ✨Prepare for Scenario-Based Questions

    Expect scenario-based questions that assess your problem-solving abilities and decision-making skills. Think about potential data breach situations or compliance challenges and how you would handle them, demonstrating your analytical thinking and risk management capabilities.

    Personal Data Management and Information Security Officer
    EBRD
    Location: London
    Go Premium

    Land your dream job quicker with Premium

    You’re marked as a top applicant with our partner companies
    Individual CV and cover letter feedback including tailoring to specific job roles
    Be among the first applications for new jobs with our AI application
    1:1 support and career advice from our career coaches
    Go Premium

    Money-back if you don't land a job in 6-months

    E
    • Personal Data Management and Information Security Officer

      London
      Temporary
      48000 - 72000 £ / year (est.)
    • E

      EBRD

    Similar positions in other companies
    UK’s top job board for Gen Z
    discover-jobs-cta
    Discover now
    >