Skip to content
MVPeople Group Logo
MVPeopleGroup
GRC & Compliance

Privacy & Security Project Lead

Den HaagConsultancyHybridSenioroverige

About the assignment

You manage end-to-end privacy and security projects that impact the entire organisation. You translate regulatory requirements into actionable roadmaps, ensuring ISO 27001, GDPR, and emerging frameworks (NIS2, DORA) are embedded into operations.

Your challenge: balance rapid business growth with robust compliance. You coordinate cross-functional teams, manage vendor dependencies, and report progress to leadership. Impact is measured by reduced audit findings, faster time-to-compliance, and a security-first culture.

Your responsibilities

  • Lead privacy and security project portfolios from initiation through closure
  • Develop and execute compliance roadmaps aligned with ISO 27001, GDPR, NIS2, and DORA requirements
  • Manage stakeholder communication with technical teams, business units, and executive leadership
  • Oversee risk assessments, control testing, and remediation tracking across the organisation
  • Design and implement privacy impact assessments and data protection governance frameworks
  • Monitor regulatory changes and translate them into project priorities and control updates
  • Coordinate third-party security assessments and vendor risk management processes

Tech Stack & Tools

Platforms & Tooling

ServiceNow GRCArcherOneTrustCollibra

Frameworks & Standards

ISO 27001GDPRNIS2DORABIO 2.0COBITNIST CSF

Cloud & Infrastructure

Azure AD/Entra IDAWS IAM

Methodologies

Agile/Scrum for security projectsRisk-based prioritisationStakeholder managementChange management

Certifications (preferred)

CISACRISCCISSPCISM

Must-haves

  • 5+ years experience in privacy, security, or compliance project management
  • Strong knowledge of ISO 27001, GDPR, and regulatory frameworks
  • Proven ability to manage complex, cross-functional projects with competing priorities
  • Experience with GRC platforms (ServiceNow, Archer, OneTrust) or similar tools
  • Excellent stakeholder communication and board-level reporting skills
  • Fluent in Dutch and English

Nice-to-haves

  • CISA, CRISC, or CISM certification
  • Experience with NIS2, DORA, or sector-specific compliance frameworks
  • Background in privacy programme management or data protection
  • Experience in highly regulated industries (banking, healthcare, energy)

What we offer

  • Strategic role influencing organisational security direction
  • Lead compliance transformation across multiple regulatory domains
  • Cross-functional exposure across business, technology, and risk functions
  • Competitive compensation and professional development budget
  • Flexible hybrid working arrangement
  • Personal guidance from a dedicated MVPeople consultant who knows your niche

The process

1

Introduction

Phone call with your MVPeople consultant (within 24 hours)

2

Match & Brief

We discuss the assignment in detail and prepare you

3

Client meeting

Introduction to the client

4

Start

Contracting and onboarding

Details

Type

Consultancy

Location

Den Haag

Work model

Hybrid

Level

Senior

Industry

overige

Posted

25 March 2026


Contact

Apply nowMore information
Apply now