Devoteam Cyber Trust | Privacy Counsel (GDPR & Data Protection) | FinTech Sector
Company Description
Devoteam Cyber Trust is the Cybersecurity specialist arm of the Devoteam Group. With our 800+ experts located across EMEA, we aim to establish cybersecurity as an enabler of business success rather than a gatekeeper. We leverage an end-to-end approach to Cyber Resilience, Applied Security, and Managed Security services to secure the tech journey of large and medium-sized companies from all sectors and industries.
Since 2009, previously known as INTEGRITY, our team based in Portugal is specialised in providing cutting-edge Managed Security Services that combine its expertise and proprietary technology to consistently and effectively reduce the cyber risk of our clients.
The comprehensive service range includes Persistent Intrusion Testing, ISO 27001, PCI-DSS, GRC Consulting and Solutions, and Third-Party Risk Management. ISO 27001 (Information Security) and ISO 9001 (Quality) certified, PCI-QSA, and member of CREST and CIS - Centre for Internet Security, we provide services to a considerable number of clients, operating in more than 20 countries.
Job Description
Advisory & Regulatory Guidance
GDPR & local law advice — Act as a trusted adviser to the business on the interpretation and application of the GDPR and national data protection laws across the Group's European markets, including local implementing legislation and sector-specific rules.
Regulatory monitoring — Track developments in EU and national privacy law, EDPB guidelines, supervisory authority decisions and related regimes, including ePrivacy, the EU AI Act, data governance and financial-services data rules. Assess their impact and translate them into practical guidance and updated policies.
Legal opinions — Provide clear, pragmatic written and verbal advice on complex privacy questions, balancing legal requirements with business objectives and risk appetite.
Privacy Governance & Documentation
Records of Processing (RoPA) — Establish, maintain and update the Article 30 records of processing activities across entities and functions.
Policies & procedures — Draft, review and maintain Group privacy policies, standards, internal guidelines, procedures and privacy notices, ensuring they remain aligned with regulatory developments.
DPIAs & risk assessments — Conduct and review Data Protection Impact Assessments and legitimate interest assessments, identify risks and recommend proportionate mitigation measures.
Privacy by Design, Projects & New Technology
Privacy by design & by default — Embed privacy requirements into new products, services, systems and business initiatives from the outset.
AI & new technology — Review data-driven, automated decision-making and artificial intelligence initiatives for privacy risk, coordinating with Legal, Technology and Risk teams and considering the interplay with the EU AI Act.
Project support — Provide privacy input to transformation, digital, marketing and data initiatives across the Group.
Vendors, Contracts & Data Transfers
Data Processing Agreements — Draft, review and negotiate DPAs, controller-to-controller and controller-to-processor arrangements and data-sharing agreements with vendors, clients and partners.
International transfers — Advise on cross-border and intra-group data transfers, implement Standard Contractual Clauses (SCCs) and conduct transfer impact assessments.
Third-party due diligence — Assess the privacy posture of vendors and third parties as part of procurement and third-party risk management.
Data Subject Rights & Incident Response
Data subject requests (DSARs) — Manage and coordinate responses to access, rectification, erasure, portability, objection and other data subject rights requests within statutory deadlines.
Breach & incident response — Manage the personal data breach process end to end, including triage, risk assessment, remediation, record-keeping and notifications to supervisory authorities and data subjects where required.
Regulator liaison — Support engagement with supervisory authorities on notifications, queries and investigations.
Awareness, Cooperation & Reporting
Training & awareness — Design and deliver privacy training and awareness sessions and promote a strong data protection culture across the Group.
Stakeholder cooperation — Work closely with Legal, Information Security, IT, HR, Procurement, Marketing and the business, and coordinate with local privacy contacts across jurisdictions.
Reporting — Prepare privacy metrics, dashboards and updates for compliance management, senior stakeholders and relevant governance committees.
Qualifications
Law degree; qualification/admission in an EU jurisdiction is strongly preferred.
4 to 7 years of relevant experience in data protection/privacy, gained in-house and/or in a law firm or consultancy.
Strong, demonstrable working knowledge of the GDPR and of national privacy laws in at least one relevant European jurisdiction.
Experience in financial services, market infrastructure or another regulated environment is an advantage.
Skills & Competencies
Ability to translate complex legal requirements into clear, practical and business-oriented advice.
Strong drafting and negotiation skills, particularly for DPAs and data transfer arrangements.
Rigorous, well-organised and able to manage multiple priorities autonomously in a fast-paced environment.
Excellent stakeholder management and communication skills, comfortable engaging with senior management.
Fluency in English is required; an additional European language such as French, Dutch, Italian or Portuguese is a strong plus.
Sound judgement, discretion and a high standard of professional integrity when handling confidential information.
Team spirit — A genuinely collaborative mindset, contributing positively to the Data Protection Office and building trusted relationships across teams and jurisdictions.
Leadership — The ability to take ownership of matters, drive them to resolution and constructively influence and guide stakeholders, including in the absence of direct authority.
Dynamism — An energetic, proactive and solutions-oriented approach, adapting readily to change and thriving in a fast-moving, international environment.
Additional Information
The Devoteam Group works for equal opportunities, promoting its employees based on merit and actively fights against all forms of discrimination. We are convinced that diversity contributes to the creativity, dynamism and excellence of our organization. All of our vacancies are open to people with disabilities.
What we offer:
- Professional development and monitoring talent;
- Commitment to our employees' development;
- Collaboration in a company that is constantly growing and evolving.
- Strong organisational culture: collaboration, sharing, flexibility, integrity and low ego.
Would you like to join our team? Then send your CV.