Full-Time

Senior IT Lawyer

Spektrum Management Group

Spektrum Management Group

No salary listed

Freiburg im Breisgau, Germany

In Person

Some travel to other NATO sites may be required.

Category
Legal & Compliance (2)
,
Requirements
  • Minimum 9 years of experience in Information Technology law.
  • Knowledge and proven skills regarding contract management and large-scale information technology system projects.
  • Good knowledge in Data Protection matters, including Privacy by Design.
  • Good knowledge in Intellectual Property Rights.
  • Proven experience of at least 8 years as a Data Protection Practitioner.
  • Proven experience of at least 8 years in implementing personal data management aspects in a complex IT environment.
  • Six years proven experience in conducting comprehensive Data Protection Impact Assessments (DPIA) in line with Article 35 of Regulation (EU) 2016/679 (General Data Protection Regulation) or Article 39 of Regulation (EU) 2018/1725 (EU Data Protection Regulation), as a separate document produced independently from other documentation such as Security Risk Assessments, risk screening or threshold assessments.
  • Six years proven experience in implementing privacy enhancing technologies.
  • Three years proven experience in handling data breaches, in particular within large-scale information technology systems, in compliance with applicable data protection regulations including assessment and mitigation measures to reduce the impact on data subjects.
  • University degree in law.
  • Degree or equivalent experience demonstrating focus on privacy engineering is particularly applicable.
Responsibilities
  • Providing legal advice and legal assistance in any area associated with the procurement, provision, delivery, maintenance, or effective use of information systems and their environments and intellectual property rights.
  • Implementing personal data management aspects in a complex information technology environment.
  • Ensure privacy by design and by default solutions for the large scale IT systems.
  • Assist and/or perform records, compliance checks, risk screening, threshold and data protection impact assessments (DPIA).
  • Assist in developing and maintaining DPIA methodology.
  • Assist in providing training on DPIA methodology.
  • Assist in handling data breaches in particular within the large scale IT systems from detection, response and final report.
  • Assist in drafting data protection policies and procedures.
  • Identify gaps and contribute to the development of project plans to close the gaps and meet data protection requirements set forth by applicable regulation applicable to the large scale IT systems and data protection Regulation (EU) 2018/1725.
Desired Qualifications
  • Specific certification on how to carry out Data Protection Impact Assessments (DPIAs) – including, at least, 40 hours course and exam – is an asset and considered an advantage.
  • Basic Privacy/Data Protection certification such as Certified Information Privacy Professional/Manager (CIPP/E or CIPM) and other listed certifications (EIPA – Data Protection Certification, University of Maastricht - Data Protection Certification, Practitioner Certificate in Data Protection from PDP Training (UK) - including ‘Conducting Data Protection Impact Assessments’ in the certification programme, any other equivalent certification in data protection and/or conducting data protection impact assessments officially recognised by any EU/EEA National Data Protection Authorities.)
Spektrum Management Group

Spektrum Management Group

View

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A