Overview
In this role you will lead the technical implementation of the organisation’s privacy and data security strategy, embedding privacy-by-design across data processing and customer-facing systems. You will design a comprehensive data ring-fencing framework and enforce separation controls for sensitive data, enabling secure data sharing and compliant analytics. You will collaborate with engineering, DevOps, cloud and data teams to implement micro-segmentation and IAM across environments, integrating privacy controls into CI/CD and data workflows. You will advocate for privacy-preserving technologies and ensure ongoing compliance with GDPR, CCPA/CPRA, data residency rules and external standards.
Responsibilities
- Lead the technical implementation of the privacy and data security strategy
- Design and implement data ring-fencing and data separation controls for high-sensitivity data
- Establish secure data-sharing mechanisms including data clean rooms
- Collaborate with Engineering, DevOps, Cloud and Data teams on micro-segmentation and granular access controls
- Embed privacy and security controls into system architecture, CI/CD pipelines and workflows
- Deploy privacy-preserving technologies (tokenisation, hashing, salting, de-identification, differential privacy)
- Develop controls to support GDPR, CCPA/CPRA and data sovereignty requirements
- Create monitoring, testing, evidence gathering, and audit-ready controls for compliance and certifications (SOC 2, ISO 27001)
- Maintain a Control Rationale framework mapping configurations to regulatory requirements
- Translate regulatory/privacy requirements into technical controls with stakeholders
- Support governance of exceptions to ring-fencing and data protection controls
- Develop and deliver developer-friendly guidance and training on secure data handling
- Stay abreast of privacy engineering, data security, cloud security and threat intelligence developments
Key requirements
- 3+ years in Privacy Engineering, Data Security, Cloud Infrastructure Security or related field
- Strong understanding of privacy-by-design and data protection controls
- Knowledge of GDPR, CCPA/CPRA, data residency and data sovereignty
- Experience with IAM, micro-segmentation, Zero Trust Architecture and DLP technologies
- Experience with privacy-preserving tech (tokenisation, hashing, salting, de-identification, differential privacy)
- Experience with AWS, Azure and/or GCP, including identity, access control and network segmentation
- Familiarity with Snowflake, Databricks and Airflow
- Experience producing technical control documentation and compliance artefacts (ISO 27001, SOC 2)
- Relevant qualifications (CIPT, CIPM, CISSP, CISM advantageous)
- Excellent written and verbal communication; ability to explain complex concepts to diverse stakeholders
- Strong analytical and problem-solving skills
- Desirable understanding of Data Clean Rooms and secure data-sharing architectures
- excellent communication
- analytical mindset
- detail-oriented
- privacy-by-design implementation
- data protection controls
- data ring-fencing
…
