Information Security Compliance Manager and Data Protection Officer (DPO)
Information Security Compliance Manager and Data Protection Officer (DPO)

Information Security Compliance Manager and Data Protection Officer (DPO)

Luton Full-Time 48000 - 72000 £ / year (est.) No home office possible
T

At a Glance

  • Tasks: Lead data protection strategies and ensure compliance with GDPR and other regulations.
  • Company: Join a rapidly expanding organisation focused on data security across Europe.
  • Benefits: Enjoy a remote-first role with travel opportunities and a chance to shape data policies.
  • Why this job: Be the go-to expert in data protection while making a real impact in a dynamic environment.
  • Qualifications: Strong knowledge of GDPR, ISO27001, and experience in privacy law or data security required.
  • Other info: Not essential, but experience with ISO 42001 related to AI is a plus.

The predicted salary is between 48000 - 72000 £ per year.

Remote-first role with travel to UK (London & Sussex) and European offices if / when required.

ISO 27001 (ideally Lead Auditor level), NIS2 or experience with European data protection/compliance/cybersecurity laws/implementing policies related to these areas for a company's European operations as this organisation is expanding massively across Europe.

Ultimately, they need a real champion in this area who can be the go-to person within the organisation for all things data protection/compliance and implement policies, provide training sessions and keep up-to-date with changing laws and regulations to ensure the UK and European entities remain compliant in an ever-changing landscape.

NOT ESSENTIAL, but ask if they have experience with ISO 42001 which is a course related to AI as this will be useful for the future.

Role Summary

Our client is seeking an Information Security Compliance Manager and Data Protection Officer (DPO) to ensure compliance with applicable Information Security Standards (e.g. ISO27001 / Cyber Essentials Plus, NIS2) as well as the General Data Protection Regulation (GDPR) and other applicable data protection laws. This role reports into the Director of Governance, Risk & Compliance and will coordinate with the Compliance department. You will oversee data protection strategies, implement policies, and ensure the secure processing of data within the organisation. The role requires strong expertise in information security compliance, data privacy, legal compliance, and risk management.

Job Responsibilities

  • Data Privacy Compliance & Advisory
  • GDPR Compliance: Monitor and ensure compliance with GDPR, national data protection laws, and internal privacy policies; provide internal expert advice on data protection matters and privacy risks; act as the primary point of contact with supervisory authorities (e.g. ICO, CNIL, AEPD); conduct regular privacy impact assessments (DPIAs) for high-risk data processing activities; maintain Record of Processing Activities (ROPA).
  • Policies & Training: Develop and implement privacy policies, guidelines, and best practices; develop and deliver training for employees on data protection obligations.
  • DSAR: Oversee and respond to Data Subject Access Requests (DSARs), including rights to access, erasure, and rectification.
  • Breach Management: Ensure breaches are identified, investigated, and reported according to applicable laws and standards.
  • Audit: Conduct internal audits and ensure continuous improvement in data protection practices; support external audits and regulatory assessments.
  • Assessments: Provide guidance on data privacy and information security in contracts, vendor agreements, and responsible for addressing third-party risk assessment requirements.
  • Information Security Compliance
    • Certifications: Manage certification compliance programs (ISO27001 / Cyber Essentials Plus); lead and coordinate annual certification efforts.
    • Other Cybersecurity Laws and Regulations: Support compliance efforts regarding EU’s emerging data and cyber laws (e.g. NIS2, Data Act).
    • Governance: Support ongoing information security compliance and governance activities.
  • Collaboration & Stakeholder Engagement
    • Work closely with Legal, IT, Compliance, HR, Internal Audit, and external partners to align data protection strategies.

    Job Skills Requirements

    • Essential
    • Strong knowledge of GDPR, ePrivacy Directive, ISO27001 and national data protection laws.
    • Experience in privacy law, compliance or data security.
    • Familiarity with data governance, cybersecurity and IT security frameworks.
    • Strong communication skills to engage with internal teams and external regulators.
    • Ability to handle sensitive and confidential information with integrity.
  • Preferred
    • Legal, IT security or compliance background.
    • Certification in CIPP/E, CIPM, CIPT, CISSP or equivalent privacy or cybersecurity qualification.
    • ISO 27001 Lead Auditor certifications and experience.
    • Experience conducting privacy impact assessments (DPIAs) and managing data breaches.

    Key Competencies

    • Strong attention to detail and analytical skills.
    • Ability to work independently and make risk-based decisions.
    • Strong organizational skills for managing compliance documentation.
    • Proactive approach to identifying and mitigating data protection risks.

    The above statements reflect the general details necessary to describe the principal functions of the occupation described and shall not be construed as a detailed description of all the work requirements that may be inherent in the occupation.

    Information Security Compliance Manager and Data Protection Officer (DPO) employer: Tiger Resourcing Group

    As an Information Security Compliance Manager and Data Protection Officer (DPO) at our rapidly expanding organisation, you will thrive in a remote-first environment that encourages flexibility and work-life balance, with opportunities for travel to vibrant locations such as London and Sussex. We pride ourselves on fostering a collaborative work culture that prioritises employee growth through continuous training and development, while also offering competitive benefits and a commitment to staying ahead of evolving data protection laws across Europe. Join us to be at the forefront of compliance and data security, making a meaningful impact in a dynamic and supportive setting.
    T

    Contact Detail:

    Tiger Resourcing Group Recruiting Team

    StudySmarter Expert Advice 🤫

    We think this is how you could land Information Security Compliance Manager and Data Protection Officer (DPO)

    ✨Tip Number 1

    Network with professionals in the information security and data protection fields. Attend relevant webinars, conferences, or local meetups to connect with others who are already working in compliance roles. This can help you gain insights into the industry and potentially lead to referrals.

    ✨Tip Number 2

    Stay updated on the latest changes in GDPR and other European data protection laws. Follow reputable blogs, join online forums, or subscribe to newsletters that focus on data protection and compliance. This knowledge will not only prepare you for interviews but also demonstrate your commitment to the field.

    ✨Tip Number 3

    Consider obtaining additional certifications related to data protection and compliance, such as CIPP/E or ISO 27001 Lead Auditor. These qualifications can enhance your credibility and show potential employers that you are serious about your professional development.

    ✨Tip Number 4

    Prepare to discuss real-world scenarios during interviews. Think of examples where you've successfully implemented compliance measures or handled data protection challenges. Being able to articulate your experience will set you apart from other candidates.

    We think you need these skills to ace Information Security Compliance Manager and Data Protection Officer (DPO)

    ISO 27001 Lead Auditor Certification
    GDPR Compliance Expertise
    Data Protection Law Knowledge
    Privacy Impact Assessments (DPIAs)
    Data Subject Access Requests (DSAR) Management
    Internal Audit Experience
    Risk Management Skills
    Strong Communication Skills
    Data Governance Familiarity
    Cybersecurity Framework Knowledge
    Attention to Detail
    Analytical Skills
    Organisational Skills
    Proactive Risk Mitigation
    Collaboration and Stakeholder Engagement

    Some tips for your application 🫡

    Tailor Your CV: Make sure your CV highlights relevant experience in information security compliance, data protection, and GDPR. Use specific examples that demonstrate your expertise in these areas, particularly any roles where you implemented policies or conducted audits.

    Craft a Compelling Cover Letter: In your cover letter, express your passion for data protection and compliance. Mention your familiarity with ISO 27001 and NIS2, and how your skills align with the company's needs. Be sure to include any experience you have with training employees on data protection obligations.

    Showcase Relevant Certifications: If you hold certifications such as CIPP/E, CIPM, or ISO 27001 Lead Auditor, make them prominent in your application. These qualifications are essential for this role and will set you apart from other candidates.

    Demonstrate Communication Skills: Since the role requires strong communication skills, provide examples in your application of how you've effectively engaged with internal teams and external regulators. Highlight any experience you have in conducting training sessions or presenting complex information clearly.

    How to prepare for a job interview at Tiger Resourcing Group

    ✨Showcase Your Expertise in GDPR and Compliance

    Be prepared to discuss your knowledge of GDPR, ePrivacy Directive, and ISO 27001. Highlight any specific experiences where you ensured compliance or handled data protection issues, as this will demonstrate your capability to be the go-to person for compliance within the organisation.

    ✨Demonstrate Strong Communication Skills

    Since the role involves engaging with various stakeholders, practice articulating complex compliance concepts in a clear and concise manner. Prepare examples of how you've effectively communicated data protection policies or trained employees in the past.

    ✨Prepare for Scenario-Based Questions

    Expect questions that assess your problem-solving skills in real-world scenarios, such as handling data breaches or responding to Data Subject Access Requests (DSARs). Think through your past experiences and be ready to explain your thought process and actions taken.

    ✨Stay Updated on Emerging Laws and Regulations

    Research recent developments in data protection laws, especially those relevant to the EU, like NIS2 and the Data Act. Showing that you are proactive about staying informed will reflect your commitment to compliance and your ability to adapt to changes in the legal landscape.

    Information Security Compliance Manager and Data Protection Officer (DPO)
    Tiger Resourcing Group
    T
    • Information Security Compliance Manager and Data Protection Officer (DPO)

      Luton
      Full-Time
      48000 - 72000 £ / year (est.)

      Application deadline: 2027-04-22

    • T

      Tiger Resourcing Group

    Similar positions in other companies
    UK’s top job board for Gen Z
    discover-jobs-cta
    Discover now
    >