Privacy & DPO
Security & Privacy Officer
AmsterdamConsultancyHybridSenioroverige
About the assignment
You are the linchpin between security operations and privacy governance. You bridge technical controls with regulatory requirements, ensuring data protection doesn't compromise business agility.
Your role sits at the intersection of GRC and privacy law. You translate complex regulations into actionable policies and monitor their implementation across the organisation.
Your responsibilities
- Design and maintain privacy frameworks aligned with GDPR, NIS2, and sector-specific regulations
- Conduct Data Protection Impact Assessments (DPIA) for new systems and process changes
- Develop security policies that embed privacy by design into operations
- Monitor compliance status and report findings to leadership and relevant authorities
- Lead incident response protocols when data breaches or privacy violations occur
- Advise business units on privacy risks during M&A, vendor selection, and cloud migrations
- Manage relationships with external auditors, supervisory authorities, and third-party processors
Tech Stack & Tools
Platforms & Tooling
OneTrustTrustArcCollibra
Frameworks & Standards
GDPRNIS2DORABIO 2.0ISO 27001NIST Cybersecurity Framework
Cloud & Infrastructure
AzureAWS
Methodologies
Privacy by DesignData Protection Impact Assessment (DPIA)Risk-based compliance
Certifications (preferred)
CIPP/E (Certified Information Privacy Professional/Europe)CIPM (Certified Information Privacy Manager)CISA (Certified Information Systems Auditor)
Must-haves
- 5+ years in security, privacy, GRC, or related compliance roles
- Deep understanding of GDPR, NIS2, and EU privacy regulations
- Experience designing and implementing privacy policies and controls
- Proven ability to communicate complex compliance requirements to non-technical stakeholders
- Strong project management and documentation skills
Nice-to-haves
- CIPP/E, CIPM, or CISA certification
- Experience with OneTrust, TrustArc, or Collibra platforms
- Background in financial services, healthcare, or critical infrastructure sectors
What we offer
- Shape security and privacy strategy at an organisational level
- Work with modern GRC and privacy platforms
- Influence board-level discussions on data protection and risk
- Collaborate with international teams on evolving regulatory landscapes
- Personal guidance from a dedicated MVPeople consultant who knows your niche
The process
1
Introduction
Phone call with your MVPeople consultant (within 24 hours)
2
Match & Brief
We discuss the assignment in detail and prepare you
3
Client meeting
Introduction to the client
4
Start
Contracting and onboarding
Details
Type
Consultancy
Location
Amsterdam
Work model
Hybrid
Level
Senior
Industry
overige
Posted
16 March 2026
Contact
MVPeople Group
jobs@mvpeoplegroup.com