At a Glance
- Tasks: Support the Head of Privacy in ensuring data protection compliance and security.
- Company: Join Two Circles, a global sports agency connecting fans through data and technology.
- Benefits: Enjoy hybrid working, performance bonuses, and tickets to sporting events.
- Why this job: Be part of a dynamic team that values integrity and offers career progression.
- Qualifications: 2-4 years experience with UK GDPR, ISO frameworks, and risk management required.
- Other info: Diversity is key; all qualified applicants are encouraged to apply.
The predicted salary is between 36000 - 60000 £ per year.
Two Circles is a global sports agency. We drive growth for sports properties by delivering deeper connections with fans, through the intelligent use of data and technology.
As an executive supporting the Head of Privacy (Group DPO) at Two Circles, you play a key role in assisting in monitoring and advising on our compliance with relevant regulations, advising our colleagues on keeping our systems and data safe from external and internal threats, completing DPIAs and maintaining our ROPA, responding to incidents as they occur and guiding our solution design and architecture in a Privacy by Design manner. You are hands-on with our technology stack as required to proactively protect our data and that of our Clients, working closely with the client-facing teams as well as the Technology Operations and Legal teams to assure the work our Services & Product teams deliver by ensuring we have appropriate policies, procedures and controls that are kept up-to-date and are business enablers, not blockers.
Alongside suitably skilled colleagues, you help train and upskill your fellow Two Circlers on topics such as data protection and information security, as well as understanding and feeding into their processes and workflows to keep good practice on the agenda. When you are not delivering against specific projects or contributing to effective data protection and information security activities, you'll also be an integral part of supporting the business through our GRC process, and leading and supporting our data protection champions in the business. This role will be part of the Privacy capability and will report to the Head of Privacy.
Requirements
- Creating, reviewing and maintaining security policy, standards and procedures
- Providing expertise in compliance frameworks, such as GDPR and ISO 27XXX
- Coordinating internal and external audits for compliance frameworks
- Conducting vendor and partner due diligence
- Supporting internal stakeholders with assurance and audit questionnaires
- Responding to and investigating information security threats and incidents
- Day to day execution of data protection and information security tasks across multiple areas including DPIA and ROPA updates, third party security reviews, updating the risk register etc.
- Monitor industry updates, technologies and best practices to improve and audit our IT Security/Article 32 GDPR compliance
- Support the Technology team to keep information security infrastructure up to date with Privacy by Design principles
- Increase the levels of understanding of IT Security with end users, leading to improved user interactions and overall experience with IT Security
- Thinking of and implementing new ways to automate and improve security across the business
The ideal background and skills we are looking for include:
- 2-4 years of experience
- Understanding of UK GDPR, EU GDPR, and PECR
- Experience with ISO 27XXX frameworks
- Risk Management and governance
- Understanding of technical implementations of data protection practices (DLP, backups, MS Purview, MS Endpoint Manager/Intune)
- Tailoring advice through the lens of risk management to the particular audience
- Understanding Security by Design and able to influence solution design decisions, e.g. zero Trust principles, least privilege RBAC, comprehensive logging, etc.
Experience with the following would also be beneficial:
- International regulations and security frameworks (US State privacy laws, Australian Privacy Act, NIST, SOC2, etc)
- Wider MS Azure security tooling and data warehousing configuration
- AI Risk Frameworks (e.g. EU AI Act, NIST and the Framework Convention on Artificial Intelligence)
- Experience of, or a keen interest in, the business of sport
Though these are the basics written down, we will principally be recruiting for energy, values and commitment - both to Two Circles and to your career. Our recruitment process will be honest & thorough, and so will our roles. In return, we can offer honesty, integrity, and the chance to progress in the organisation as quickly as you develop within it. Two Circles is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, colour, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.
Benefits
- Hybrid working: we'd love for you to come into our office at least 2-3 days a week, especially during your onboarding
- Performance planning: potential to have a salary increase every 6 months and progress your career
- Discretionary company bonus
- Tickets to sporting events
- Renowned Team Days and events (this June, we went to Spain)
- Lunch on a Wednesday, breakfast and continuous supply of snacks
- Private healthcare schemes
- Cycle to work scheme
- Learning and Development opportunities, including certification in certain areas
Seniority level: Mid-Senior level
Employment type: Full-time
Job function: Business Development and Sales
Industries: IT Services and IT Consulting
Data Protection Executive employer: Two Circles
Contact Detail:
Two Circles Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Data Protection Executive
✨Tip Number 1
Familiarise yourself with the latest updates on UK GDPR, EU GDPR, and PECR regulations. Being well-versed in these areas will not only help you understand the role better but also demonstrate your commitment to data protection during discussions.
✨Tip Number 2
Network with professionals in the data protection field, especially those who have experience with ISO 27XXX frameworks. Engaging in conversations about best practices and challenges can provide valuable insights and may even lead to referrals.
✨Tip Number 3
Showcase your understanding of Security by Design principles in your interactions. Discuss how you would influence solution design decisions, as this aligns closely with the responsibilities of the Data Protection Executive role.
✨Tip Number 4
Stay updated on industry trends and technologies related to data protection and information security. Being able to discuss recent developments or tools like MS Purview and DLP during interviews can set you apart from other candidates.
We think you need these skills to ace Data Protection Executive
Some tips for your application 🫡
Understand the Role: Before applying, make sure you fully understand the responsibilities and requirements of the Data Protection Executive role. Tailor your application to highlight relevant experience and skills that align with the job description.
Highlight Relevant Experience: In your CV and cover letter, emphasise your experience with UK GDPR, EU GDPR, and ISO 27XXX frameworks. Provide specific examples of how you've implemented data protection practices or managed compliance in previous roles.
Showcase Your Skills: Detail your technical skills related to data protection, such as knowledge of DLP, backups, and security by design principles. Mention any tools or technologies you are familiar with, especially those mentioned in the job description.
Craft a Compelling Cover Letter: Use your cover letter to express your passion for data protection and the sports industry. Discuss how your values align with Two Circles and why you are committed to contributing to their mission of driving growth through data and technology.
How to prepare for a job interview at Two Circles
✨Know Your Regulations
Familiarise yourself with UK GDPR, EU GDPR, and PECR. Be prepared to discuss how these regulations impact data protection practices and how you can ensure compliance within the organisation.
✨Demonstrate Technical Knowledge
Showcase your understanding of technical implementations related to data protection, such as DLP, backups, and security frameworks like ISO 27XXX. Be ready to explain how these tools can enhance data security.
✨Emphasise Risk Management Skills
Highlight your experience in risk management and governance. Discuss how you tailor advice based on risk assessments and how you can influence solution design decisions with a focus on security by design.
✨Show Enthusiasm for the Role
Express your passion for data protection and the sports industry. Two Circles values energy and commitment, so make sure to convey your eagerness to contribute to their mission and grow within the company.