top of page
79f8034fe4.jpg

JOIN
OUR
TEAM

at Allendevaux & Company

  • Allendevaux & Company is seeking a hardworking and motivated individual to join the data protection team. As a data protection analyst, the role is an exciting opportunity to build policies, practice and procedures to support the data protection programmes of several multinational companies. You will be an integral player in helping customers prepare for and undergo audit, maintain ISMS programmes, assist with data subject requests, provide updates regarding legislative and regulatory changes, perform risk assessments and more.

     

    The role will report directly to a senior partner at the firm. Due to the pandemic, this is a teleworking role supported by daily meeting participation over videoconference. Normally travel is customary to support onsite audit, but nearly all travel has been suspended as of this writing.

     

    Personal Characteristics and Skills

     

    • Adaptable, welcomes change, comfortable as a self-starter.

    • Comfortable with ambiguities that need problem-solving.

    • Effectively educates, evangelizes, and promotes data protection best practices.

    • Firmly understands impact of global data protection requirements.

    • Comfortable with HR and marketing data protection practices.

    • Drives programmatic goals while building close relationships with business partners.

    • Organized, responsive, and persistent with good follow-through; customer service oriented.

    • Demonstrates initiative, passion, and resourcefulness.

    • Maintains a strong work ethic and a high degree of accountability.

    • Effectively balances competing priorities in a rapidly growing, fast-paced environment.

    • Passionate about data protection and building a culture of data protection.

    • Maintains a sense of humor.

     

    Responsibilities

    • As a Privacy Analyst on the data protection team, you will:

    • Analyze and evaluate compliance with relevant data protection regulations, standards, and frameworks (e.g ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018) to help ensure customers continue to embrace best-in-class practices.

    • Assist with breach processes and facilitate breach notifications.

    • Develop, maintain, and evolve privacy programs to manage privacy inquiries and requests for access to personal information internally and externally.

    • Review marketing and HR data collection practices and help embed in them Privacy by Design principles.

    • Maintain GDPR Article 30 Records of Processing.

    • Assist with the administration of data processing agreements (DPA), standard contractual clauses (SCCs) and BCR process for the transfer of personal data.

    • Participate in ISO/IEC 27001 audit prep, internal audit and external third-party audit.

    • Conduct supplier vetting activities.

    • Maintain asset registers.

    • Facilitate management security review meetings.

    • Monitor and maintain effective measures of controls.

    • Interface with the cybersecurity team in their role of conducting vulnerability scanning and penetration testing.

    • Assist with security and compliance questionnaires.

    • Help monitor data collection practices, investigate and document how data is shared within an organisation’s ecosystem, and maintain data protection policies.

    • Conduct data protection impact assessments (DPIAs) for new and existing processes, services, and applications.

    • Assist with overseeing and appropriately responding to internal/external audits of data protection processes and procedures.

    • Intake, triage, and analyze reported data protection incidents to ensure appropriate escalation to the team for rapid response and remediation.

    • Support the integration of acquired companies and technologies through data protection due diligence.

    • Advise on complex data protection best practices through consistent analysis, feedback, and follow-through with internal business partners.

    • Support the development of data protection infrastructure and process automation across the enterprise.

    • Develop data protection awareness campaigns and training programs.

    • Represent the team in day-to-day activities across business, legal, and technology business partners.

    Minimum Qualifications

    • Bachelor’s degree; Advanced degree is desirable.

    • 5-8 years professional experience in a role involving privacy compliance.

    • Must have privacy or security certifications (e.g. CISSP, CIPP, CIPT, or CIPM).

    • Deep knowledge of global data protection laws, standards, and associated frameworks (e.g. GDPR, CCPA, HIPAA, and others).

    • Strong track record of working collaboratively with cross-functional business partners.

    • History of managing privacy programs relating to web, advertising, and analytics technologies and practices (e.g. cookies and other tracking technologies).

    • Expresses complex ideas in easily understandable ways.

    • Strong technical understanding of data ecosystems and the technology that powers them.

    • Demonstrated ability to analyze sophisticated privacy and security concepts and apply them to real-world situations.

    • Comfort influencing business leaders in the promotion of consistent practices and policy.

    • Experience working with legal, marketing, HR, IT, product, and security teams.

     

    Preferred Qualifications

    • Legal academic and professional background.

    • Sophisticated skills with Microsoft Office and G-Suite.

    • Familiarity with privacy program management tools (e.g. OneTrust or Nymity).

    • Knowledge of data related initiatives such as ingestion, report and dashboard creation, and web analytics.

    • Strong command and certification in ISO/IEC 27001.

    • Strong competence in ISO/IEC 27005, ISO/IEC 27032, ISO/IEC 27004

     

    We value diversity at our company. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, or any other applicable legally protected characteristics in the location in which you are applying.

    Work from home

    Contractor

    Located within: UK, Europe, Uruguay or India

    Apply Now
  • Allendevaux & Company is seeking an experienced data protection / privacy attorney to join its growing team. The purpose of the role is to work with a distributed base of clientele as an objective legal advisor to identify and evaluate privacy compliance issues. You will provide subject matter expertise along with a team of experienced privacy professionals, designing corporate privacy training and monitoring regulatory trends. Your contribution will enable businesses to protect the privacy of stakeholders including employees, customers, vendors and others.

     

    The role will report directly to a senior partner at the firm. Due to the pandemic, this is a teleworking role supported by daily meeting participation over videoconference. Normally travel is customary to support onsite meetings, but nearly all travel has been suspended as of this writing. Should have a home-based office that is fairly insulated (within reason) from distracting noises, with access to stable Internet connectivity.

     

    Personal Characteristics and Skills

     

    • Attention to detail and consistent high standard of work.

    • Comfortable with ambiguities that need problem-solving.

    • Good time management skills with the ability to prioritise workload with a flexible approach to ensure deadlines are met.

    • Substantially well-developed written and oral communication skills in English, with the ability to use footnotes, bibliographic references, documentation styles and mature layout.

     

    What You Will Do

    • Design global data privacy strategies and lead efforts to comply with relevant privacy and data protection laws in various jurisdictions, especially the European Union.

    • Provide legal expertise on interpretation and application of data protection law.

    • Design and implement strategies to enable intra-company and cross-border data transfers, understanding case law such as Schrems II decisions.

    • Understanding of data privacy issues relating to data storage and IT infrastructure.

    • Draft, review, and implement company-wide privacy related policies, procedures and controls; adjust policies and procedures to reflect latest developments in privacy globally.

    • Scope and perform periodic data privacy risk assessments including DIPAs, mitigation and remediation, including data control design and monitoring, as well as the mitigation of privacy and security risks.

    • Strategically advise on the development of new services or enhancements to existing services to ensure “privacy by design” and “privacy by default” principles.

    • Support HIPAA risk assessment and company’s compliance obligations as a HIPAA Business Associate.

    • Provide support and guidance to investigations and security teams to enable compliance with privacy laws when transferring or analysing data.

    • Provide privacy and data protection issue spotting and advice for ethics hotline reports.

    • Support contract negotiation and drafting for complex privacy and data protection issues.

    • Design training courses for privacy and data protection, including annual company-wide Privacy and Data Protection training.

    • Provide support to M&A team for privacy and data protection topics. Work with management, functional leaders and business leaders to formalize, implement and maintain privacy compliance policies and procedures and to ensure compliance training is completed.

    • Coordinate with internal audit to conduct periodic assessments of the effectiveness and performance of company’s privacy compliance program.

     

    Minimum Qualifications

     

    • Juris Doctorate; Advanced degree (PhD) is also desirable.

    • 5-8 years professional experience in a role involving privacy compliance.

     

    Preferred Qualifications

     

    • CIPP/E, CIPM, CISM certifications

     

    We value diversity at our company. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, or any other applicable legally protected characteristics in the location in which you are applyi

    Located within: UK, Europe, Uruguay or India

    Contractor

    Work from home

  • Allendevaux & Company is seeking a systems administrator to join its growing team. The purpose of the role is to increase effectiveness and overall value in using Microsoft O365 technology, including support for hardware and applications, mobile computing and device management, Active Directory, security management and file management.

     

    You will be an integral player in helping the enterprise collaborate, especially during this teleworking modus operandi during pandemic times. The role will be mostly remote until the pandemic subsides, and as such, you will participate in daily meetings over videoconference. Should have a home-based office that is fairly insulated (within reason) from distracting noises, with access to stable Internet connectivity.

     

    The role will report directly to a senior partner at the firm. Due to the pandemic, this is a teleworking role supported by daily meeting participation over videoconference. Normally travel is customary to support onsite audit, but nearly all travel has been suspended as of this writing.

     

    Personal Characteristics and Skills

    • Attention to detail and consistent high standard of work.

    • Comfortable with ambiguities that need problem-solving.

    • Good time management skills with the ability to prioritise workload with a flexible approach to ensure deadlines are met.

    • Excellent written and oral communication skills in English.

    Responsibilities

     

    • Design, implement, document and maintain the firm’s Microsoft O365 technology stack.

    • Administrate the Microsoft O365 technology stack, both in the cloud and on endpoint computing devices including mobile device management.

    • Design, implement and maintain the firm’s group policies and active directory.

    • Monitor and manage security compliance and issues across all computing devices.

    • Build workflows and integrated forms using Microsoft tools.

     

    Minimum Qualifications

    • Bachelor’s degree; Advanced degree is desirable.

    • 5-8 years professional experience in a role involving privacy compliance.

    • MCSE or equivalent knowledge.

    • Azure AD, Teams, Sharepoint, Intune, Exchange.

     

    Preferred Qualifications

    • VMWare helpful.

    • RHCE (Red Hat) helpful but not necessary.

    • CISSP, CISA or CISM desirable.

     

    We value diversity at our company. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, or any other applicable legally protected characteristics in the location in which you are applying.

    Located within: India or Uruguay

    Contractor

    Work from home

    Apply Now
bottom of page