~1h ago
New

Head of Security & Compliance

BelgiumBelgium·Leuvenexecutive
Legal & ComplianceCompliance
2 views0 saves0 applied

Quick Summary

Key Responsibilities

review cloud and infrastructure configuration, run periodic access reviews, follow up on vulnerability and logging

Requirements Summary

advise on and monitor GDPR compliance, DPIAs, records of processing, data subject requests and data transfers. Be the contact point for the Belgian Data Protection Authority.

Technical Tools
Legal & ComplianceCompliance

Luzmo is a fast-growing scale-up with a small team and limited means. Until now, security and privacy were handled by several people next to their main job. That no longer fits the clients we serve. So we are creating an independent role: a Head of Security & Compliance who sets our security and data protection policy, checks that we follow it, and tells us clearly when we don't.

You will be our CISO and our Data Protection Officer (DPO). To make sure you can do that independently, you report to our Board of Directors, not to the CTO or the founders. Our engineering team builds and runs the platform; you set the rules, test and challenge the controls, and advise. That separation is a deliberate choice.

This is a part-time role (60%), as an employee (preferred) or freelancer, from our Leuven office or remote within EU time zones.

If you want to build a security and privacy program you can stand behind, with real ownership and a direct line to the board, we'd like to talk to you.

Luzmo is embedded AI analytics, everywhere your users work. We help data-centric companies, where data is the product, put governed, white-labeled AI analytics in front of their own customers: branded dashboards, self-service analytics, AI analytics chatbots, workflow analytics and white-labeled MCP. Build it once, and it works everywhere: in the product, in Slack or email, in ChatGPT and Claude, and in AI agents.

From our HQ in Leuven, Belgium and our office in New York, USA we serve customers across Europe and North America. We decide fast, own our work, and use AI across the company to punch above our weight.

Security and privacy are a key reason clients choose Luzmo. Clients increasingly connect their data to AI agents over MCP, in Slack, ChatGPT and Claude. As we move into larger clients and regulated sectors (telecom, banking, healthcare, public sector), security reviews, DPAs and SLAs are often part of closing a deal.

Responsibilities

~2 min read
  • →

    Set our security and data protection policies and standards, keep the risk register up to date and agree the priorities with management.

  • →

    Check that the controls work in practice: review cloud and infrastructure configuration, run periodic access reviews, follow up on vulnerability and logging requirements, and manage pentests and the follow-up of findings.

  • →

    Run our SOC2 Type II program and the yearly audit, together with the control owners in engineering.

  • →

    Act as our Data Protection Officer: advise on and monitor GDPR compliance, DPIAs, records of processing, data subject requests and data transfers. Be the contact point for the Belgian Data Protection Authority.

  • →

    Answer security questionnaires, advise on the security and data protection parts of client contracts, assess vendors and subprocessors, and join client calls about security.

  • →

    Review designs of new features for security and privacy before they are built, and turn findings into clear requirements for the engineering team.

  • →

    Own the incident response process, coordinate the response to security incidents and advise on breach notifications. Engineering does the technical fixing.

  • →

    Organize security awareness training for everyone and secure coding training for engineers.

  • →

    Report regularly to the Board of Directors on risks, compliance and the progress of the security program.

You will not run IT operations or manage the engineering team. You will not decide which personal data we process or why. You will not have commercial targets. You need to be able to look at our systems, so you get read-only access to cloud configuration and logs, and emergency access during incidents. This keeps you independent, as GDPR and the Belgian Data Protection Authority expect from a DPO.

  • Full ownership of security and data protection at Luzmo, with a direct line to the Board.

  • Real independence: your advice is documented, and as DPO you are legally protected against dismissal or penalties for doing your job.

  • Your own budget for tools, audits, pentests, external advice and training.

  • An exciting scale-up environment with growth opportunities.

  • Competitive salary (or day rate if you work as a freelancer).

  • Flexible holiday policy, remote working and international get-togethers.

  • The equipment, software and tech you need to do your job.


We empower success. We accomplish daily. We innovate fearlessly. Join a team of collaborative, driven and ambitious people at Luzmo.

  • 5+ years of experience in security, of which at least 2 owning security and/or compliance at a software company.

  • A technical background (e.g. as engineer, DevOps / SRE, security engineer or pentester). You can read code and cloud configuration, not only policies.

  • You have run a SOC2 Type II audit yourself.

  • Practical knowledge of GDPR: DPAs, subprocessors, international data transfers, DPIAs, breach notifications. You can take up the formal DPO role.

  • Experience with public cloud security (AWS, GCP or Azure).

  • Experience with security questionnaires, client contract reviews and security incidents.

  • You give independent advice, also when it is not what people want to hear, and you look for practical solutions.

  • You can explain security clearly to engineers, sales, clients and the board.

  • Fluent in English, written and spoken. Based in an EU time zone.

Nice to Have

~1 min read
  • Experience with ISO 27001, NIS2, DORA or the EU AI Act.

  • Interest in AI security: LLM data flows, prompt injection, MCP / agent access control.

  • Experience at a scale-up of 50–200 people.

  • Certifications like CISSP, CISM, CCSP, OSCP or CIPP/E.

  • Dutch or French.

Location & Eligibility

Where is the job
Leuven, Belgium
On-site at the office
Who can apply
BE

Listing Details

First seen
October 5, 2026
Last seen
October 5, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
56%
Scored at
October 5, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Head of Security & Compliance