Head of Security & Compliance

Luzmo NV

Vlaams-Brabant

On-site

EUR 60,000 - 90,000

Part time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Luzmo NV seeks a Head of Security & Compliance (60% FTE) to establish and govern security and data protection across the product and data flows. You will report to the Board, act as DPO and CISO, and drive independent controls, audits and vendor risk management with direct influence on strategic decisions.

You will collaborate with engineering, legal and operations to implement GDPR compliance, DPIAs and incident response, while maintaining read-only access during audits and ensuring governance

Qualifications

  • 5+ years in security, incl. 2 in software security/compliance.
  • Technical background with ability to read code and cloud configs.
  • Experience running a SOC2 Type II audit.
  • Practical GDPR knowledge: DPAs, data transfers, DPIAs, breach notifications.
  • Public cloud security experience (AWS, GCP, Azure).
  • Experience with security questionnaires and client reviews.
  • Independent, pragmatic advisory with clear communication to engineers and board.

Responsibilities

  • Set and maintain security and data protection policies and standards.
  • Review controls, cloud infra configs, access reviews, and vulnerability handling.
  • Run SOC2 Type II program and annual audit with engineering owners.
  • Act as DPO: monitor GDPR compliance and data subject requests.
  • Answer security questionnaires and assess vendors/subprocessors.
  • Review feature designs for security/privacy before build.
  • Own incident response and breach notification processes.
  • Organize security awareness and secure coding training.
  • Report risks, compliance, and progress to the Board.

Skills

Security leadership
DPO/GDPR expertise
SOC2 Type II
Public cloud security
Security questionnaires & vendor risk
Independent advisory
Board-level communication
English fluency

Tools

ISO 27001 knowledge

Job description

The job

Luzmo is a fast-growing scale-up with a small team and limited means. Until now, security and privacy were handled by several people next to their main job. That no longer fits the clients we serve. So we are creating an independent role: a Head of Security & Compliance who sets our security and data protection policy, checks that we follow it, and tells us clearly when we don't.

You will be our CISO and our Data Protection Officer (DPO). To make sure you can do that independently, you report to our Board of Directors, not to the CTO or the founders. Our engineering team builds and runs the platform; you set the rules, test and challenge the controls, and advise. That separation is a deliberate choice.

This is a part-time role (60%), as an employee (preferred) or freelancer, from our Leuven office or remote within EU time zones.

If you want to build a security and privacy program you can stand behind, with real ownership and a direct line to the board, we'd like to talk to you.

Who we are

Luzmo is embedded AI analytics, everywhere your users work. We help data-centric companies, where data is the product, put governed, white-labeled AI analytics in front of their own customers: branded dashboards, self-service analytics, AI analytics chatbots, workflow analytics and white-labeled MCP. Build it once, and it works everywhere: in the product, in Slack or email, in ChatGPT and Claude, and in AI agents.

From our HQ in Leuven, Belgium and our office in New York, USA we serve customers across Europe and North America. We decide fast, own our work, and use AI across the company to punch above our weight.

Security and privacy are a key reason clients choose Luzmo. Clients increasingly connect their data to AI agents over MCP, in Slack, ChatGPT and Claude. As we move into larger clients and regulated sectors (telecom, banking, healthcare, public sector), security reviews, DPAs and SLAs are often part of closing a deal.

What you'll do
  • Set our security and data protection policies and standards, keep the risk register up to date and agree the priorities with management.

  • Check that the controls work in practice: review cloud and infrastructure configuration, run periodic access reviews, follow up on vulnerability and logging requirements, and manage pentests and the follow-up of findings.

  • Run our SOC2 Type II program and the yearly audit, together with the control owners in engineering.

  • Act as our Data Protection Officer: advise on and monitor GDPR compliance, DPIAs, records of processing, data subject requests and data transfers. Be the contact point for the Belgian Data Protection Authority.

  • Answer security questionnaires, advise on the security and data protection parts of client contracts, assess vendors and subprocessors, and join client calls about security.

  • Review designs of new features for security and privacy before they are built, and turn findings into clear requirements for the engineering team.

  • Own the incident response process, coordinate the response to security incidents and advise on breach notifications. Engineering does the technical fixing.

  • Organize security awareness training for everyone and secure coding training for engineers.

  • Report regularly to the Board of Directors on risks, compliance and the progress of the security program.

What you won't do (by design)

You will not run IT operations or manage the engineering team. You will not decide which personal data we process or why. You will not have commercial targets. You need to be able to look at our systems, so you get read-only access to cloud configuration and logs, and emergency access during incidents. This keeps you independent, as GDPR and the Belgian Data Protection Authority expect from a DPO.

What this job offers
  • Full ownership of security and data protection at Luzmo, with a direct line to the Board.

  • Real independence: your advice is documented, and as DPO you are legally protected against dismissal or penalties for doing your job.

  • Your own budget for tools, audits, pentests, external advice and training.

  • An exciting scale-up environment with growth opportunities.

  • Competitive salary (or day rate if you work as a freelancer).

  • Flexible holiday policy, remote working and international get-togethers.

  • The equipment, software and tech you need to do your job.

How we work

We empower success. We accomplish daily. We innovate fearlessly. Join a team of collaborative, driven and ambitious people at Luzmo.


Who we're looking for
  • 5+ years of experience in security, of which at least 2 owning security and/or compliance at a software company.

  • A technical background (e.g. as engineer, DevOps / SRE, security engineer or pentester). You can read code and cloud configuration, not only policies.

  • You have run a SOC2 Type II audit yourself.

  • Practical knowledge of GDPR: DPAs, subprocessors, international data transfers, DPIAs, breach notifications. You can take up the formal DPO role.

  • Experience with public cloud security (AWS, GCP or Azure).

  • Experience with security questionnaires, client contract reviews and security incidents.

  • You give independent advice, also when it is not what people want to hear, and you look for practical solutions.

  • You can explain security clearly to engineers, sales, clients and the board.

  • Fluent in English, written and spoken.

  • Belgium based, with regular presence in our headquarter (Leuven).

Nice to have
  • Experience with ISO 27001, NIS2, DORA or the EU AI Act.

  • Interest in AI security: LLM data flows, prompt injection, MCP / agent access control.

  • Experience at a scale-up of 50–200 people.

  • Certifications like CISSP, CISM, CCSP, OSCP or CIPP/E.

  • Dutch or French.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Privacy & Information Security Consultant
Privacy & Information Security Consultant

Datashift NV • Antwerpen

On-site
EUR 90,000 - 130,000
Security & Privacy Expert
Security & Privacy Expert

Rhox • Schaarbeek

On-site
EUR 95,000 - 140,000
DPO certification (nice to have)
Belgian energy market expertise (nice)
Agile project experience (nice)
+1
DevSecOps Security Analyst
DevSecOps Security Analyst

Luminus • Brussel

On-site
EUR 65,000 - 100,000
Meal vouchers
Group insurance
Mobility allowance
+2
Senior Information Security Officer
Senior Information Security Officer

TechWolf • Gent

Hybrid
EUR 90,000 - 130,000
Equity
Hybrid working
Mobility budget
+4
Senior Business Consultant - Cybersecurity
Senior Business Consultant - Cybersecurity

Orange Cyberdefense • Wijnegem

Hybrid
EUR 90,000 - 130,000
32 vacation days
Meal vouchers
Eco-cheques
+2
Data Protection Expert
Data Protection Expert

Orange • Brussel

On-site
EUR 85,000 - 120,000
Company car or mobility budget
Homeworking and net allowance
Performance bonus
+2
Technical Support Engineer - Network & Security
Technical Support Engineer - Network & Security

Lansweeper NV • Oost-Vlaanderen

On-site
EUR 35,000 - 47,000
Meal vouchers (€10/day)
ecocheques (€250/year)
13th month
+6
Senior Data Protection professional
Senior Data Protection professional

Data Trust Associates • Antwerpen

Hybrid
EUR 70,000 - 110,000
Digital Sales Manager - Enterprise
Digital Sales Manager - Enterprise

Lansweeper NV • Belgium

On-site
EUR 72,000 - 120,000
Meal vouchers
ecocheques
Vacation payout
+7
Risk and Compliance Officer
Risk and Compliance Officer

Zepz • Brussel

Remote
EUR 70,000 - 110,000
Unlimited annual leave
Great healthcare benefits
Employee discounts