Skip to content

Open nowPosted 3 days ago

Head of Security & Compliance

Luzmo2 open roles

Pay
€57,000 – €69,000 a year
Where
Leuven, Vlaams Gewest, Belgium
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowHead of Security & ComplianceLuzmo · Leuven, Vlaams Gewest, Belgium
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Luzmo's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.8%1 day
  2. 3.6%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.0%30 days
This job: posted 3 days ago

The posting

The job

Luzmo is a fast-growing scale-up with a small team and limited means. Until now, security and privacy were handled by several people next to their main job. That no longer fits the clients we serve. So we are creating an independent role: a Head of Security & Compliance who sets our security and data protection policy, checks that we follow it, and tells us clearly when we don't.

You will be our CISO and our Data Protection Officer (DPO). To make sure you can do that independently, you report to our Board of Directors, not to the CTO or the founders. Our engineering team builds and runs the platform; you set the rules, test and challenge the controls, and advise. That separation is a deliberate choice.

This is a part-time role (60%), as an employee (preferred) or freelancer, from our Leuven office or remote within EU time zones.

If you want to build a security and privacy program you can stand behind, with real ownership and a direct line to the board, we'd like to talk to you.

Who we are

Luzmo is embedded AI analytics, everywhere your users work. We help data-centric companies, where data is the product, put governed, white-labeled AI analytics in front of their own customers: branded dashboards, self-service analytics, AI analytics chatbots, workflow analytics and white-labeled MCP. Build it once, and it works everywhere: in the product, in Slack or email, in ChatGPT and Claude, and in AI agents.

From our HQ in Leuven, Belgium and our office in New York, USA we serve customers across Europe and North America. We decide fast, own our work, and use AI across the company to punch above our weight.

Security and privacy are a key reason clients choose Luzmo. Clients increasingly connect their data to AI agents over MCP, in Slack, ChatGPT and Claude. As we move into larger clients and regulated sectors (telecom, banking, healthcare, public sector), security reviews, DPAs and SLAs are often part of closing a deal.

What you'll do

  • Set our security and data protection policies and standards, keep the risk register up to date and agree the priorities with management.
  • Check that the controls work in practice: review cloud and infrastructure configuration, run periodic access reviews, follow up on vulnerability and logging requirements, and manage pentests and the follow-up of findings.
  • Run our SOC2 Type II program and the yearly audit, together with the control owners in engineering.
  • Act as our Data Protection Officer: advise on and monitor GDPR compliance, DPIAs, records of processing, data subject requests and data transfers. Be the contact point for the Belgian Data Protection Authority.
  • Answer security questionnaires, advise on the security and data protection parts of client contracts, assess vendors and subprocessors, and join client calls about security.
  • Review designs of new features for security and privacy before they are built, and turn findings into clear requirements for the engineering team.
  • Own the incident response process, coordinate the response to security incidents and advise on breach notifications. Engineering does the technical fixing.
  • Organize security awareness training for everyone and secure coding training for engineers.
  • Report regularly to the Board of Directors on risks, compliance and the progress of the security program.

What you won't do (by design)

You will not run IT operations or manage the engineering team. You will not decide which personal data we process or why. You will not have commercial targets. You need to be able to look at our systems, so you get read-only access to cloud configuration and logs, and emergency access during incidents. This keeps you independent, as GDPR and the Belgian Data Protection Authority expect from a DPO.

What this job offers

  • Full ownership of security and data protection at Luzmo, with a direct line to the Board.
  • Real independence: your advice is documented, and as DPO you are legally protected against dismissal or penalties for doing your job.
  • Your own budget for tools, audits, pentests, external advice and training.
  • An exciting scale-up environment with growth opportunities.
  • Competitive salary (or day rate if you work as a freelancer).
  • Flexible holiday policy, remote working and international get-togethers.
  • The equipment, software and tech you need to do your job.

How we work

We empower success. We accomplish daily. We innovate fearlessly. Join a team of collaborative, driven and ambitious people at Luzmo.

Who we're looking for

  • 5+ years of experience in security, of which at least 2 owning security and/or compliance at a software company.
  • A technical background (e.g. as engineer, DevOps / SRE, security engineer or pentester). You can read code and cloud configuration, not only policies.
  • You have run a SOC2 Type II audit yourself.
  • Practical knowledge of GDPR: DPAs, subprocessors, international data transfers, DPIAs, breach notifications. You can take up the formal DPO role.
  • Experience with public cloud security (AWS, GCP or Azure).
  • Experience with security questionnaires, client contract reviews and security incidents.
  • You give independent advice, also when it is not what people want to hear, and you look for practical solutions.
  • You can explain security clearly to engineers, sales, clients and the board.
  • Fluent in English, written and spoken.
  • Belgium based, with regular presence in our headquarter (Leuven).

Nice to have

  • Experience with ISO 27001, NIS2, DORA or the EU AI Act.
  • Interest in AI security: LLM data flows, prompt injection, MCP / agent access control.
  • Experience at a scale-up of 50–200 people.
  • Certifications like CISSP, CISM, CCSP, OSCP or CIPP/E.
  • Dutch or French.
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Luzmo's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Luzmo's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Luzmo's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.