About this role
<p style="margin:12.0pt 0.0in 6.0pt;line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><strong><span style="font-family:Aptos, sans-serif;color:windowtext">Your area of work:</span></strong></p> <p style="margin:0.0in 0.0in 12.0pt;line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">As part of the Cyber Protection – Detect & Prevent unit, you will act as the Group’s senior specialist for Data Leakage Prevention (DLP) governance, with end</span><span style="font-family:'Cambria Math', serif;color:windowtext">‑</span><span style="font-family:Aptos, sans-serif;color:windowtext">to</span><span style="font-family:'Cambria Math', serif;color:windowtext">‑</span><span style="font-family:Aptos, sans-serif;color:windowtext">end accountability for the DLP governance framework and the effective delivery of the DLP service. The role focuses on policy and rule</span><span style="font-family:'Cambria Math', serif;color:windowtext">‑</span><span style="font-family:Aptos, sans-serif;color:windowtext">setting, governance oversight, risk management, and assurance, while also ensuring that the DLP service is reliably operated, performance</span><span style="font-family:'Cambria Math', serif;color:windowtext">‑</span><span style="font-family:Aptos, sans-serif;color:windowtext">managed, and continuously improved through close coordination with IT delivery teams and business stakeholders. Technical implementation is executed by dedicated operational teams; this role is responsible for direction, oversight, and service outcomes.</span></p> <p style="margin:0.0in 0.0in 12.0pt;line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"> </p> <p style="margin:12.0pt 0.0in 6.0pt;line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><strong><span style="font-family:Aptos, sans-serif;color:windowtext">Your responsibilities:</span></strong></p> <ul> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Define, maintain, and evolve DLP governance requirements, internal security policies, and written rules in alignment with the ICT risk framework and regulatory expectations.</span></li> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Establish clear requirements for information handling, classification, data transfer, endpoint usage, and media protection etc.</span></li> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Ensure governance documentation is clear, consistent, risk based, and fit for practical adoption across the organisation.</span></li> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Define and oversee the DLP control framework, including mandatory controls, criteria, and governance expectations.</span></li> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Ensure clear accountability across governance, operational, and delivery functions, with appropriate separation of duties.</span></li> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Monitor adherence to DLP requirements and support corrective actions where gaps are identified.</span></li> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Support responsible teams with data leakage risk assessments, deviations, and exception handling, advising stakeholders on risk implications and mitigation options.</span></li> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Assess the impact of regulatory, organisational, or technology changes on DLP governance and service obligations.</span></li> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Manage audit and assurance activities by providing governance evidence, expert input, and remediation oversight.</span></li> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Act as the governance owner of the enterprise DLP service, ensuring it is delivered in line with defined policies, risk expectations, and service objectives.</span></li> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Oversee service performance, operational stability, and lifecycle evolution, including monitoring and reporting on KPIs, SLAs, and recurring issues.</span></li> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Coordinate incidents, changes, and improvement initiatives with responsible delivery teams to ensure timely resolution and risk aligned outcomes.</span></li> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Drive continuous improvement of the DLP service to enhance effectiveness, efficiency, and user experience.</span></li> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Serve as the primary point of contact for DLP related governance and service matters for business units, IT, and risk stakeholders.</span></li> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Provide expert guidance on DLP requirements, service capabilities, and acceptable data handling practices.</span></li> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Support projects, new solutions, and organisational changes by advising on DLP governance and service implications.</span></li> </ul> <p style="margin:0.0in 0.0in 10.0pt;line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"> </p> <p style="margin:6.0pt 0.0in;line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><strong><span style="font-family:Aptos, sans-serif;color:windowtext">Your profile:</span></strong></p> <ul> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Bachelor’s or Master’s degree in Cybersecurity, Information Security, IT, Risk Management, or a related discipline.</span></li> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Experience in information security governance, data protection, or risk management within a regulated or complex environment.</span></li> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Solid understanding of Data Leakage Prevention principles, including information handling, classification, secure data transfer, email and endpoint controls.</span></li> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Experience in information security governance, data protection, or risk management within a regulated environment, including practical application of requirements arising from GDPR, DORA, and related industry standard frameworks such as ISO/IEC 27001, NIST</span></li> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Strong analytical, documentation, and stakeholder management skills.</span></li> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Ability to translate governance requirements into practical, business aligned rules and service expectations.</span></li> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">Proficiency in English; German language skills are an advantage.</span></li> <li style="line-height:115%;font-size:11.0pt;font-family:Arial, sans-serif;color:#333333"><span style="font-family:Aptos, sans-serif;color:windowtext">High degree of ownership, adaptability, and a proactive, quality driven mindset.</span></li> </ul>