Information Security & Data Privacy Engineer - SKF Automotive Business

SKF Group

Poznań

On-site

PLN 180,000 - 300,000

Full time

41 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

SKF Vertevo seeks an Information Security & Data Privacy Engineer to embed security, privacy, and regulatory requirements across SKF Automotive's technology landscape. You will bridge Security, Legal, Procurement, Engineering and Business teams to enable safe innovation.

Based at Poznań (Poland) or other major SKF sites, you will lead DPIAs/PIAs, review DPAs, and ensure compliance for IT, OT, Cloud, Data and AI solutions while promoting Secure by Design and responsible data governance.

Qualifications

  • Experience in security governance, compliance, architecture, or assurance.
  • Expert knowledge of GDPR and data protection regulations.
  • Experience reviewing DPAs and data-sharing agreements.
  • Knowledge of IAM, DLP, encryption, cloud security, application security, and information protection.
  • Familiarity with ISO 27001/27701, NIS2, and related frameworks.
  • Experience supporting audits and regulatory assessments.
  • Ability to assess AI workloads for security and privacy considerations.
  • Strong analytical and stakeholder management skills.

Responsibilities

  • Translate security, privacy, regulatory, and contractual requirements into practical technical and operational controls.
  • Lead security and privacy assessments (DPIAs/PIAs), risk assessments, and compliance reviews.
  • Provide expert guidance on GDPR, data processing, retention, and records management.
  • Review DPAs, SCCs, and supplier contracts for privacy compliance.
  • Assess data residency, cross-border transfers, and third-party processing risks across cloud and SaaS.
  • Review architectures to ensure security and privacy alignment.
  • Validate controls (IAM, DLP, encryption, logging, monitoring).
  • Conduct due diligence of suppliers and technology partners.
  • Support internal and external audits and regulatory inquiries.
  • Manage remediation plans, security exceptions, and risk acceptance.
  • Support AI/data initiatives by evaluating privacy and governance implications.
  • Monitor evolving privacy, security, and AI regulations.

Skills

Cybersecurity governance
GDPR & privacy regulations
DPIA/PIA assessments
DPAs and data-sharing
IAM & DLP controls
Cloud & encryption security
Audit support
Stakeholder management

Job description

Information Security & Data Privacy Engineer - SKF Automotive Business

By creating bearings and solutions for everything from industrial applications to vehicles, SKF plays an essential role in our everyday lives. In Q4 2026, SKF intends to spin off its Automotive business and list it as a separate company under the name of SKF Vertevo. A company created to support the future of the automotive market, and to co-drive the future of mobility faster.

This role will be a part of that new company. Would you like to join us, and move people further?

As the Information Security & Data Privacy Engineer, you will play a key role in ensuring security, privacy, and regulatory requirements are effectively embedded across SKF Automotive's technology landscape. Combining strong cybersecurity expertise with specialist knowledge of GDPR, personal data protection, and regulatory compliance, you will act as the bridge between Security, Legal, Procurement, Engineering, and Business teams.

In this unique and specialised position, you will help ensure that IT, OT, Cloud, Data and AI solutions are designed, implemented, and operated in accordance with security, privacy, and compliance requirements. You will champion Secure by Design, Privacy by Design, and responsible data governance principles while enabling innovation and business growth.

What you can expect in the role
  • Translate security, privacy, regulatory, and contractual requirements into practical technical and operational controls.
  • Lead security and privacy assessments, including DPIAs, PIAs, risk assessments, and compliance reviews.
  • Provide expert guidance on GDPR, PII processing, data retention, data minimisation, lawful processing, data subject rights, and records management.
  • Review and provide security and privacy input into Data Processing Agreements (DPAs), Controller-to-Processor agreements, Controller-to-Controller agreements, Standard Contractual Clauses (SCCs), and supplier contracts.
  • Assess data residency, data sovereignty, cross-border transfer, and third-party processing risks across cloud and SaaS environments.
  • Review solution architectures and technology implementations to ensure compliance with security, privacy, and regulatory requirements.
  • Validate/audit technical safeguards including Identity and Access Management, Data Loss Prevention, encryption, logging, monitoring, vulnerability management, and information protection controls.
  • Conduct security and privacy due diligence of suppliers, technology partners, data processors, and cloud providers.
  • Support internal and external audits, certification activities, customer assessments, and regulatory enquiries.
  • Manage compliance gaps, remediation plans, security exceptions, and risk acceptance activities.
  • Support AI and data-driven initiatives by assessing data processing, privacy implications, information protection requirements, and compliance obligations.
  • Monitor emerging privacy, security, and AI regulations and ensure organisational policies and controls remain aligned.
You will enjoy working here if you have
  • Strong technical cybersecurity background with experience in security governance, compliance, architecture, or assurance.
  • Expert knowledge of GDPR, personal data processing, PII protection, controller and processor obligations, data sovereignty, and privacy regulations.
  • Experience reviewing and negotiating DPAs, privacy clauses, and data-sharing agreements.
  • Deep understanding of security controls including IAM, DLP, encryption, cloud security, application security, and information protection.
  • Knowledge of ISO 27001, ISO 27701, TISAX, NIS2, and other relevant security and privacy frameworks.
  • Experience supporting audits, regulatory assessments, and compliance programmes.
  • Ability to assess AI workloads through established security, privacy, and data governance principles.
  • Strong analytical, communication, and stakeholder management skills.
If you want to go further

This position is located at one of our major SKF sites in Poznań (Poland), Pune or Bangalore (India), Saint-Cyr (France), or Cajamar (Brazil).

You will report to Malonie Guha, Chief Information Security Officer, who is located in Milton Keynes, United Kingdom. For questions regarding the recruitment process, please contact Martin Andersson, Talent Acquisition Specialist, by email martin.n.andersson@skfvertevo.com. Please note that we can't accept applications via email.

If you want to know more about SKF Automotive business, please visit our webpage: SKF Automotive: Bearings & aftermarket solutions since 1907

Transparency and fairness matter to us

At SKF, we see diversity in our workforce as an asset that supports better business results. We are committed to having a fair and inclusive recruitment process where all hiring decisions are based on objective, job-related criteria, ensuring equal opportunities for all candidates.

To support a fair and transparent recruitment process, the process may include assessments, and before hiring, we may also carry out background checks and verify application information. We will discuss your salary expectations during the first interview, and our final offer will be based on an objective evaluation of your experience, skills, and potential, aligned with the scope of the role and our internal salary guidelines. Our recruitment process may differ from country to country and will always be in line with applicablecountry-specific laws and regulations.

Come as you are – just be yourself. #weareSKF

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security & Data Privacy Engineer - SKF Automotive Business
Information Security & Data Privacy Engineer - SKF Automotive Business

SKF Sverige AB • Poznań

On-site
PLN 150,000 - 230,000
Security & Data Privacy Engineer - GDPR & AI
Security & Data Privacy Engineer - GDPR & AI

SKF Group • Poznań

On-site
PLN 180,000 - 300,000
Digital Account Manager OEM - Poland
Digital Account Manager OEM - Poland

Gruppo SKF • Warszawa

On-site
PLN 90,000 - 130,000
Tool Designer
Tool Designer

Gruppo SKF • Poland

On-site
PLN 90,000 - 120,000
Metallographic Laboratory Specialist
Metallographic Laboratory Specialist

Gruppo SKF • Poznań

On-site
PLN 90,000 - 120,000
Identity & Data Security Manager
Identity & Data Security Manager

Look4IT Sp. z o. o. (KRAZ: 7880) • Wrocław

Hybrid
PLN 260,000 - 380,000
Hybrid work model (2–3 days in Wroclaw
Senior DevOps Engineer (AI & Automation Platform) (All Genders)
Senior DevOps Engineer (AI & Automation Platform) (All Genders)

Schaeffler • Wrocław

Hybrid
PLN 253,000 - 339,000
Medical and dental care
Sports card
Life insurance
+3
Privacy and Cyber Law Specialist
Privacy and Cyber Law Specialist

National Society for Black Engineers • Katowice

Hybrid
PLN 180,000 - 240,000
Volunteer Paid Time off after 6 months
Volunteer matching program
On-demand digital course library
+3
Senior DevOps Engineer (AI & Automation Platform) (All Genders)
Senior DevOps Engineer (AI & Automation Platform) (All Genders)

Schaeffler Technologies AG & Co. KG • Wrocław

Hybrid
PLN 120,000 - 150,000
Medical and dental care
Sports card
Life insurance
+2
Identity & Data Security Manager
Identity & Data Security Manager

Look4IT Sp. z o. o. • Wrocław

Hybrid
PLN 260,000 - 380,000
Hybrid work model (2–3 days per week)