530,536open jobs
18,649companies
73,554added this week
Browse all
Salary
$62k – $171k per year (Estimated)
Location
Remote/Hybrid (Porto, Portugal)
Seniority
Senior · 4+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Devoteam is a French technology consultancy founded in 1995 by the brothers Stanislas and Godefroy de Bentzmann, which built its position by going deep on a small number of platform partnerships rather than staying vendor-neutral. It is one of the largest European partners for Google Cloud, Microsoft, Amazon Web Services and ServiceNow, and organises its practices around those ecosystems plus cybersecurity, data and creative technology. Operating across Europe, the Middle East and Africa with headquarters near Paris, the firm was taken private in 2021 and works largely with mid-size and large enterprises modernising their infrastructure and applications.

Devoteam Cyber Trust is the Cybersecurity specialist arm of the Devoteam Group. With our 800+ experts located across EMEA, we aim to establish cybersecurity as an enabler of business success rather than a gatekeeper. We leverage an end-to-end approach to Cyber Resilience, Applied Security, and Managed Security services to secure the tech journey of large and medium-sized companies from all sectors and industries.

Since 2009, previously known as INTEGRITY, our team based in Portugal is specialised in providing cutting-edge Managed Security Services that combine its expertise and proprietary technology to consistently and effectively reduce the cyber risk of our clients.

The comprehensive service range includes Persistent Intrusion Testing, ISO 27001, PCI-DSS, GRC Consulting and Solutions, and Third-Party Risk Management. ISO 27001 (Information Security) and ISO 9001 (Quality) certified, PCI-QSA, and member of CREST and CIS - Centre for Internet Security, we provide services to a considerable number of clients, operating in more than 20 countries.

Advisory & Regulatory Guidance

  • GDPR & local law advice - Act as a trusted adviser to the business on the interpretation and application of the GDPR and national data protection laws across the Group's European markets, including local implementing legislation and sector-specific rules.

  • Regulatory monitoring - Track developments in EU and national privacy law, EDPB guidelines, supervisory authority decisions and related regimes, including ePrivacy, the EU AI Act, data governance and financial-services data rules. Assess their impact and translate them into practical guidance and updated policies.

  • Legal opinions - Provide clear, pragmatic written and verbal advice on complex privacy questions, balancing legal requirements with business objectives and risk appetite.

Privacy Governance & Documentation

  • Records of Processing (RoPA) - Establish, maintain and update the Article 30 records of processing activities across entities and functions.

  • Policies & procedures - Draft, review and maintain Group privacy policies, standards, internal guidelines, procedures and privacy notices, ensuring they remain aligned with regulatory developments.

  • DPIAs & risk assessments - Conduct and review Data Protection Impact Assessments and legitimate interest assessments, identify risks and recommend proportionate mitigation measures.

Privacy by Design, Projects & New Technology

  • Privacy by design & by default - Embed privacy requirements into new products, services, systems and business initiatives from the outset.

  • AI & new technology - Review data-driven, automated decision-making and artificial intelligence initiatives for privacy risk, coordinating with Legal, Technology and Risk teams and considering the interplay with the EU AI Act.

  • Project support - Provide privacy input to transformation, digital, marketing and data initiatives across the Group.

Vendors, Contracts & Data Transfers

  • Data Processing Agreements - Draft, review and negotiate DPAs, controller-to-controller and controller-to-processor arrangements and data-sharing agreements with vendors, clients and partners.

  • International transfers - Advise on cross-border and intra-group data transfers, implement Standard Contractual Clauses (SCCs) and conduct transfer impact assessments.

  • Third-party due diligence - Assess the privacy posture of vendors and third parties as part of procurement and third-party risk management.

Data Subject Rights & Incident Response

  • Data subject requests (DSARs) - Manage and coordinate responses to access, rectification, erasure, portability, objection and other data subject rights requests within statutory deadlines.

  • Breach & incident response - Manage the personal data breach process end to end, including triage, risk assessment, remediation, record-keeping and notifications to supervisory authorities and data subjects where required.

  • Regulator liaison - Support engagement with supervisory authorities on notifications, queries and investigations.

Awareness, Cooperation & Reporting

  • Training & awareness - Design and deliver privacy training and awareness sessions and promote a strong data protection culture across the Group.

  • Stakeholder cooperation - Work closely with Legal, Information Security, IT, HR, Procurement, Marketing and the business, and coordinate with local privacy contacts across jurisdictions.

  • Reporting - Prepare privacy metrics, dashboards and updates for compliance management, senior stakeholders and relevant governance committees.

  • Law degree; qualification/admission in an EU jurisdiction is strongly preferred.

  • 4 to 7 years of relevant experience in data protection/privacy, gained in-house and/or in a law firm or consultancy.

  • Strong, demonstrable working knowledge of the GDPR and of national privacy laws in at least one relevant European jurisdiction.

  • Experience in financial services, market infrastructure or another regulated environment is an advantage.

Skills & Competencies

  • Ability to translate complex legal requirements into clear, practical and business-oriented advice.

  • Strong drafting and negotiation skills, particularly for DPAs and data transfer arrangements.

  • Rigorous, well-organised and able to manage multiple priorities autonomously in a fast-paced environment.

  • Excellent stakeholder management and communication skills, comfortable engaging with senior management.

  • Fluency in English is required; an additional European language such as French, Dutch, Italian or Portuguese is a strong plus.

  • Sound judgement, discretion and a high standard of professional integrity when handling confidential information.

  • Team spirit - A genuinely collaborative mindset, contributing positively to the Data Protection Office and building trusted relationships across teams and jurisdictions.

  • Leadership - The ability to take ownership of matters, drive them to resolution and constructively influence and guide stakeholders, including in the absence of direct authority.

  • Dynamism - An energetic, proactive and solutions-oriented approach, adapting readily to change and thriving in a fast-moving, international environment.

The Devoteam Group works for equal opportunities, promoting its employees based on merit and actively fights against all forms of discrimination. We are convinced that diversity contributes to the creativity, dynamism and excellence of our organization. All of our vacancies are open to people with disabilities.

What we offer:

  • Professional development and monitoring talent;
  • Commitment to our employees' development;
  • Collaboration in a company that is constantly growing and evolving.
  • Strong organisational culture: collaboration, sharing, flexibility, integrity and low ego.

Would you like to join our team? Then send your CV.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
530,536 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Porto
$152k – $285k per year (Estimated) • Remote • Full-Time • 10+ years exp
AI/ML
RAG
EU AI Act
Cybersecurity
SOC 2
GDPR
HIPAA
Apply
$113k – $226k per year (Estimated) • Remote • Full-Time • 10+ years exp
AI/ML
RAG
EU AI Act
Cybersecurity
SOC 2
GDPR
HIPAA
Apply
$71k – $167k per year (Estimated) • In office • 4+ years exp • London
AI/ML
AI Agents
Cybersecurity
ISO 27001
GDPR
Apply
$34k – $89k per year (Estimated) • In office • Full-Time • Brazil
Cybersecurity
ISO 27001
PCI DSS
Apply
$120k – $140k per year • Remote • Full-Time • 3+ years exp
Cybersecurity
ISO 27001
NIST CSF
Apply
$80k – $204k per year (Estimated) • Remote • Full-Time • 5+ years exp • Lisbon
JavaScript
TypeScript
SQL
Node JS
Node JS
Express
DevOps
Git
Docker
Management
Agile
Apply
$106k – $276k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Casablanca
Apply
$108k – $257k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Berlin
AI/ML
AI Agents
Gemini
OpenAI
Anthropic
DevOps
GCP
AWS
Management
ServiceNow
Marketing
Salesforce
HubSpot
Apply
$108k – $257k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Munich
AI/ML
AI Agents
Gemini
OpenAI
Anthropic
DevOps
GCP
AWS
Management
ServiceNow
Marketing
Salesforce
HubSpot
Apply
$108k – $257k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Frankfurt am Main
AI/ML
AI Agents
Gemini
OpenAI
Anthropic
DevOps
GCP
AWS
Management
ServiceNow
Marketing
Salesforce
HubSpot
Apply
$20k – $32k per year (Estimated) • In office • Internship • Bachelor's Degree • Porto
Apply
Chief Accountant 9 hours ago
$53k – $119k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Porto
Analytics
Microsoft Excel
Apply
AI Architect 10 hours ago
$69k – $153k per year (Estimated) • In office • 3+ years exp • Porto
Databases
Databricks
DevOps
GCP
Azure
CI/CD
AWS
Docker
Kubernetes
Management
WhatsApp
Apply
AI Principal 10 hours ago
$52k – $119k per year (Estimated) • In office • 8+ years exp • Porto
Databases
Databricks
DevOps
GCP
Azure
CI/CD
AWS
Docker
Kubernetes
Management
WhatsApp
Apply
Epidemiologist 12 hours ago
$42k – $97k per year (Estimated) • In office • Full-Time • 5+ years exp • Master's Degree • Porto • Turku • London • Athens • Madrid
SAS
Apply
See all jobs
This is one of many
530,536 more open roles from verified company boards, updated every day.