SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Filigran, founded in October 2022, is a fast-growing cybersecurity company trusted by over 6,000 public and private organizations worldwide. The company develops innovative open-source solutions designed to anticipate cyber threats, identify security gaps, and strengthen organizational security posture.
You will serve as Filigran's formal Data Protection Officer and lead the design and implementation of the company's practical, scalable compliance program. This is a dual-reporting role: you report directly to the CEO for statutory DPO responsibilities (ensuring independence and access to senior management), and to the General Counsel for all other compliance workstreams.
Key responsibilities include:
- Acting as the formal DPO and primary point of contact for supervisory authorities (including CNIL) and data subjects
- Designing and operating Filigran's privacy program, including Records of Processing Activities (ROPAs), Data Protection Impact Assessments (DPIAs), privacy by design, data retention, data-subject rights, breach assessment, and international data transfers
- Leading design and operational implementation of compliance controls across AI governance, NIS2, operational resilience, export controls, and economic sanctions
- Maintaining a proportionate compliance framework with policies, risk mapping, monitoring plans, internal controls, and clear reporting
- Partnering with Security, Product, and Engineering to embed privacy, AI, and regulatory requirements into product development, vendor management, and customer assurance
- Monitoring regulatory developments across the EU, UK, US, and other relevant markets, providing recommendations to leadership
- Supporting enterprise sales and procurement on privacy, AI governance, and compliance matters
- Leveraging AI tools and methodologies to enhance productivity and impact
You will work closely with the General Counsel, CEO, CISO, Security, Product, Engineering, Sales, People, and Finance teams in a fully remote, async-first environment.
REQUIREMENTS:
- 7 to 10 years' experience as a DPO, data privacy lead, or compliance officer, ideally in a fast-growing technology or SaaS company
- Demonstrable expert knowledge of data protection law and practice; recognized DPO certification or IAPP qualification (such as CIPP/E) strongly preferred
- Experience with company-wide implementation of the EU AI Act
- Deep, hands-on command of GDPR and UK GDPR, including ROPAs, DPIAs, breach management, data-subject rights, and international transfers
- Demonstrable ownership of at least two adjacent regulatory programmes (e.g., AI governance, cybersecurity regulation, operational resilience, export controls, or economic sanctions)
- Ability to lead unfamiliar workstreams with sound judgment and appropriate specialist support
- Comfortable translating complex legal and regulatory requirements into proportionate, operationally viable controls
- Strong relationship-building and credibility with technical, commercial, and executive stakeholders
- Autonomy, ownership, and team spirit
- Strong interest in AI and its applications in privacy and compliance
- Comfortable working with and leveraging AI-powered tools (LLMs, automation, copilots) to improve workflows
- Bonus: experience in cybersecurity, threat intelligence, or technical B2B SaaS; fluency in English and French