What we do. Electric Car Leasing
Why we do it. Greener. Fairer. Future.
We're looking to hire an Information Security and Data Protection team at Octopus Electric Vehicles! This will be a 3 Month Contract role (Inside IR35)
You'll be supporting our business and ensuring that we remain fully operational and compliant with UK GDPR legislation and processes while also working with various teams to expand our capabilities and develop creative solutions to business challenges and opportunities to improve our service to both new and existing customers.
What you'll do
- Subject Rights Management: Lead and conduct the end to end process for Data Subject Access Requests (SARs) and other data subject rights (e.g., erasure, rectification) in a timely and compliant manner.
- Compliance and Governance: Maintain and develop the company's data protection strategy, policies, procedure, and compliance framework in line with UK GDPR, the Data Protection Act 2018, and PECR.
- Records and Risk Documentation: Lead and conduct Data Protection Impact Assessments (DPIAs), update our Records of Processing Activities (RoPA), conduct Legitimate Interest Assessments (LIAs) and any other expected activity records.
- Breach Management: Manage the company's data breach response plan, including investigation, reporting, remediation, and communication with the Information Commissioner's Office (ICO) and affected individuals where necessary.
- Advisory: Act as the primary point of contact and subject matter expert for all data privacy matters, providing pragmatic advice to internal and external stakeholders, at all levels of the business.
- Third Party Risk: Conduct due diligence and manage data protection risks associated with third party suppliers, including SaaS vendors, finance providers, vehicle dealerships, data brokers, and marketing partners.
- Training and Awareness: Design and deliver engaging data protection training and awareness campaigns across the business to foster a strong privacy aware culture.
- Monitoring and Reporting: Monitor the evolving privacy regulatory landscape and report on the company's compliance posture and risk level.
- ICO Liaison: Serve as a point of contact for the ICO and support the designated Data Protection Officer (DPO).
What you'll need
- A passion for Data Protection, Privacy and Information Security and an ability to explain these concepts in a clear and meaningful way to those who may not be familiar with them.
- Expert handling of DSARs.
- Excellent understanding and practical experience of the principles/issues involved in Data Protection and compliance with UK GDPR legislation and the expectations of the ICO.
- Excellent understanding of the UK Data Protection Act 2018 and of the principles/issues involved in maintaining compliance. Forward thinking, self motivated and able to take responsibility for your own initiatives and drive them to implementation.
- Ability to work in a pressured environment while prioritising work in a considerate way.
- Supportive and reliable team member, with excellent attention to detail.
- Awareness of Information Security principles and requirements for ISO27001 compliance would be valuable.
- Any knowledge of the FCA or experience in the financial services industry would be valuable.
As an equal opportunity employer, we do not discriminate on the basis of any protected attribute. Our commitment is to provide equal opportunities, an inclusive work environment, and fairness for everyone.