- Industry recognised accreditations or courses (CISA, CISM, CRISC, CCSP or similar)
- Demonstrable knowledge of external audit/compliance/security processes such as GDPR, ISO27001, Cyber Essentials, or PCI DSS.
- Inspect, evaluate and improve existing IT systems, management procedures, security protocols and controls.
- Develop, maintain, evidence, and improve accreditations and management systems including GDPR, ISO 27001, Cyber Essentials, PCI DSS, BACS and others in line with business and legal requirements.
- Identify and report risks to security and to suggest improvement solutions.
- Assist with supplier and sub-processor GDPR and security requirements.
- Implement and assist with internal and external audits and assist other departments in the development and usage of appropriate processes and procedures.
- Liaising with teams responsible for data subject rights request and privacy queries.
- Oversee and coordinate responses to personal data breaches and incidents.