Trust & Compliance Manager – Data Protection, IT Compliance

Posted Sep 4

This is a fully remote position, open to applicants in United States.

📋 Description

• Collaborate closely with the Data Protection Officer, CTO, and CPO.

• Implement data protection and IT compliance processes operationally, aligning with the GDPR, the AI Act, and U.S. higher education requirements like HECVAT and SOC 2.

• Address security and data protection questionnaires, including HECVAT, VPAT/WCAG, and various other security assessments.

• Engage in technical discussions with IT security stakeholders at universities and healthcare facilities.

• Develop and sustain a centralized Trust & Compliance knowledge base, including a procedure for regular updates.

• Keep records and registers updated, such as records of processing activities (ROPA), sub-processors, certificates, deletion concepts, technical and organizational measures (TOMs), and incidents.

• Manage data subject requests operationally.

• Assess new IT and AI tools requested by business units.

• Create and maintain a central contract register, encompassing standard and customized agreements, versions of data processing agreements (DPA), and deviation analyses.

• Update DPA appendices from a technical standpoint.

• Develop scalable processes.

• Utilize AI and automation tools strategically, for instance, for document comparisons and drafting tasks.


⛳️ Requirements

• Around 3–5 years of experience in IT compliance, GRC, information security, data protection operations, or third-party risk, preferably within a SaaS or software context.

• Proven experience in responding to enterprise security questionnaires, such as HECVAT, VSA, and SIG.

• Strong foundational technical understanding, including knowledge of encryption, SSO, hosting, and backups.

• Proficient in written and spoken German and English, with at least a C1 level proficiency.

• A confident and discerning approach to utilizing AI tools.

• High level of independence and responsibility.

• Structured method for prioritization.

• Strong communication skills for direct interactions with customers and IT stakeholders.

• A law degree is not mandatory.

• Familiarity with automation tools like n8n or Zapier, or GRC platforms such as Vanta or Drata, is advantageous.


🏝️ Benefits

• Flexible working hours and remote working options.

• Commitment to work-life balance.

• Complimentary access to the entire Lecturio learning platform for both personal and professional growth.

• Team-building and company events.

• Free beverages and fresh fruit available in the office.

• Complimentary access to coaching sessions and additional mental health resources.

People also viewed

Yordas Group16 hours ago

Associate Regulatory Consultant – Hazard Communication

TR flagTurkey, +1 more countryFull-timeCompliance
ApplyView job
VELOCITY PORTFOLIO GROUP INC20 hours ago

Compliance Analyst

US flagNew Jersey OnlyFull-timeCompliance$95k – $110k/year
ApplyView job
Orca20 hours ago

Senior Director, Regulatory Affairs

US flagCalifornia OnlyFull-timeCompliance$250k – $300k/year
ApplyView job
Empower20 hours ago

Senior Director, Compliance Monitoring & Surveillance

US flagUnited States OnlyFull-timeCompliance$144.9k – $210.1k/year
ApplyView job
BCM One20 hours ago

Privacy and Compliance Analyst

GB flagUnited Kingdom OnlyFull-timeCompliance
ApplyView job
Exelixis20 hours ago

Associate Regulatory Affairs Director – Quality, Standards & Training

US flagUnited States OnlyFull-timeCompliance$163k – $231k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers