Senior Information Security Engineer
VacoAbout the role
Vaco offers consulting, contract, and direct hire solutions in the areas of accounting, finance, technology, healthcare, operations, and general administration. Vaco’s Director, Head of Security, Compliance, & Risk, to which this position reports, supports systems, infrastructure, and projects for Vaco offices providing world class service to our customers. This is a fast-paced environment. Candidates should thrive in an environment with high volumes of work, managing multiple projects/assignments at a time, and working in a highly collaborative atmosphere.
Description: The Senior Information Security Engineer/ Data Protection Official (Sr. InfoSec Eng./DPO) is responsible for providing overall data protection and security engineering expertise in the areas of compliance management, monitoring and analysis, security vulnerability management, penetration testing and risk mitigation; project management for key initiatives to implement appropriate processes related to security, compliance, & risk, management, planning and system controls. This role will lead our compliance with Data Protection/Privacy regulations globally and serve as the designated DPO in all jurisdictions, as required. They will communicate effectively with members from all levels of the company to educate, guide, and inform of our obligations to protect customer information. This person will also engage in any "event" where privacy may have been violated and take an active role to ensure that our disclosure and reporting requirements are fulfilled. This position will work within the legal department and report to the Director, Head of the Security, Compliance, & Risk (SCR) function. This is a highly visible position in a fast-paced environment. The position will collaborate with Business Stakeholders, Business Leaders, Business Analysts, and Subject Matter Experts both internally and externally to plan and deliver projects effectively and timely.
Duties and Responsibilities:
The following duties are normal for this job. These are not to be construed as exclusive or all-inclusive. Other duties may be required and assigned.
- Review data protection approaches and methodologies ensuring all data protection practices are in compliance with applicable mandates.
- Participate and contribute data protection compliance aspects to all Vaco policies and procedures as applicable.
- Review all Vaco agreements ensuring appropriate data protection and privacy is addressed as applicable.
- Manage application security penetration testing to ensure Vaco services, applications and websites are designed and implemented to the highest security and compliance standards and in accordance with Vaco’s risk appetite.
- Provide leadership on data protection, privacy, and information security risk mitigation.
- Coordinate vulnerability remediation activities and work with the IT operations function to mature the patch management lifecycle based on vulnerability management SLAs created by the Security, Compliance & Risk function.
- Create hardening standards for all IT platform technologies.
- Establish, manage, and maintain a secure web/applications program that will include identification of appropriate security reviews at key project milestones, manage training requirements for developers on secure coding/development practices and their management of tools and services that will enable validation of controls during the design and build phase.
- Facilitate corporate wide and focused information security awareness training.
- Maintain web application, source code and penetration assessment tools.
- Deploy and maintain risk management framework and processes.
- Develop and maintain vendor risk management processes.
- Develop, implement, and maintain a data privacy program in accordance with GDPR and other relevant international data protection regulations as well as national & local mandates.
- Ensure proper registration with data privacy authorities for all Vaco subsidiaries globally.
- Inform, advise, and issue recommendations to the company regarding data privacy and protection compliance.
- Actively collaborate and coordinate with all stakeholders in the event of a data breach or other incident.
- Foster a data protection culture within the company and help to implement essential elements of the GDPR, such as the principles of data processing, data subjects’ rights, data protection by design and by default, records of processing activities, security of processing, and notification and communication of data breaches.
- Conduct data protection impact assessments (DPIAs).
- Draft policies and standard operating procedures related to privacy and data storage.
- Se
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s