GDPR, Privacy

2 weeks ago


Tallinn, Harjumaa, Estonia Selkirk Sport - We Are Pickleball Full time

About
Selkirk Sport
Pickleball is the fastest growing sport in the US and Selkirk Sport is the market leader in manufacturing all things Pickleball We are an agile company with a collaborative management style whose mission is to fuel Pickleball players' obsession by creating a premier product ecosystem through a variety of brands.

This not only applies to delivering the foremost in creative excellence through high-performance equipment manufactured in the USA, but also in how Selkirk Sport strives to improve the Pickleball community through grass-roots programs, professional athlete sponsorship, and supporting local non-profits & schools. We look for people who are focused, tech-savvy, fast-paced, problem solvers, and complete tasks while being a stickler for the details. We also want a fun personality that enjoys getting results.

We are seeking a proactive and technically skilled
GDPR, Privacy & Security Engineer
to join our team. This is a critical role responsible for designing, developing, and implementing technical solutions to ensure our software ecosystem is compliant with GDPR and other data privacy regulations, while also maintaining robust security postures across all our platforms.

You will be the technical authority on data privacy and security, working across our entire technology stack—from our public-facing consumer applications and Shopify e-commerce platform to our internal business tools built on Palantir. You will collaborate closely with our engineering, product, legal, and security teams to translate complex privacy and security requirements into concrete, robust, and scalable software features.

Key Responsibilities

  • Develop Privacy-Enhancing Features: Design, build, and maintain tools and services to automate and manage data privacy obligations. This includes:

  • Data Subject Access Request (DSAR) Automation: Implement systems to handle user requests for data access, rectification, portability, and erasure (the "Right to be Forgotten") across all our platforms.

  • Consent Management: Build and integrate robust consent management solutions to track user consent for cookies, marketing communications, and data processing activities.
  • Data Anonymization & Pseudonymization: Develop scripts and services to anonymize or pseudonymize data in development, testing, and analytics environments.
  • Data Expiration and Retention: Develop tools and automations to track data expirations and ensure that we are not storing data longer than necessary.

  • Implement and Maintain Security Measures: Design, implement, and monitor security controls to protect sensitive data and systems from unauthorized access, use, disclosure, disruption, modification, or destruction. This includes:

  • Security Architecture Review: Participate in the design and review of system architectures to ensure security best practices are integrated from the outset ("Security by Design").

  • Vulnerability Management: Implement and manage tools for identifying, assessing, and remediating security vulnerabilities in applications and infrastructure.
  • Incident Response Support: Assist in the development and execution of incident response plans for security breaches and data privacy incidents.
  • Security Awareness: Promote and educate engineering teams on secure coding practices and security best practices.

  • Shopify Platform Integration:

  • Audit our Shopify store's data collection and security practices, including apps, scripts, and custom themes.

  • Utilize Shopify APIs to manage customer data, fulfill DSARs, and ensure third-party app integrations are GDPR compliant and secure.
  • Manage our cookie consent banners and privacy settings within the Shopify environment.

  • Palantir Platform Integration:

  • Audit our Palantir data restrictions, retention, and security practices.

  • Learn and become the team expert on Palantir's data privacy and security tools and systems in order to help other devs build with "Privacy by Design and by Default" and "Security by Design" principles.

  • Technical Guidance:

  • Act as the go-to expert for developers on privacy and security-related questions.

  • Help maintain our Record of Processing Activities (RoPA) by documenting data flows, storage locations, and processing purposes for our applications.

  • System Auditing & Compliance:

  • Regularly audit our applications, databases, and internal tools to identify and remediate potential privacy and security risks or compliance gaps.

  • Collaborate with the legal and security teams to conduct Data Protection Impact Assessments (DPIAs) and Security Impact Assessments (SIAs) for new projects and features.
  • Develop monitoring and alerting systems to detect potential data privacy incidents and security breaches.

Required Qualifications & Skills

  • Experience: 3+ years of professional software development experience.
  • Privacy & Security Engineering Experience: Prior experience in a Privacy Engineering, Security Engineering, or similar role.
  • Programming Proficiency: Strong proficiency in one or more of our core languages, such as python or typescript.
  • Database Knowledge: Solid experience with data and databases.
  • API Expertise: Proven experience working with RESTful APIs and/or GraphQL for system integration.
  • Strong GDPR Understanding: Deep technical understanding of GDPR principles and their practical application in software development (e.g., Lawful Basis for Processing, Data Minimization, Purpose Limitation).
  • Security Best Practices: Strong knowledge of data security principles like encryption, access control, secure coding practices, and common web application vulnerabilities.
  • Problem-Solving: Excellent analytical and problem-solving skills, with the ability to translate legal and regulatory requirements into technical solutions.

Preferred Qualifications (Nice to Have)

  • Shopify Experience: Direct experience with the Shopify platform, its APIs (Admin, Storefront), and the Liquid templating language.
  • Palantir Experience: Direct experience with the Palantir platform, its APIs and data controls.
  • Cloud Infrastructure: Familiarity with cloud platforms (e.g., AWS, GCP, Azure) and their data storage and security services.
  • Other Privacy Regulations: Familiarity with other privacy laws such as CCPA/CPRA, LGPD, etc.

Security Certifications:
Relevant security certifications (e.g., CISSP, CISM, CompTIA Security+).

What We Offer:

  • Opportunity to work with a fast-growing, industry-leading international brand, in a dynamic, innovative, and supportive work environment
  • Hybrid work model, office located at Ülemiste, Tallinn
  • Well-being: Weekly Team Lunches, monthly sports allowance/private health insurance, and mental health support and 6 paid wellness/ health days
  • Work-life balance: You will receive paid time off for your birthday and you are granted one Friday off per quarter (four per year) to rest, reset and recharge.
  • Professional development and learning opportunities


  • Tallinn, Harjumaa, Estonia SEB Eesti Full time

    The Baltic Customer Data and Strategic Transformations Unit is 50 people working on common purpose to explore and work on strategic insight so that SEB is valuable for Baltic societies today and in the future.Management of data privacy is vital for the regulatory compliance but more over for the business success of the bank. As the regulatory landscape grows...


  • Tallinn, Harjumaa, Estonia SEB Full time €42,000 - €60,000 per year

    The Baltic Customer Data and Strategic Transformations Unit is 50 people working on common purpose to explore and work on strategic insight so that SEB is valuable for Baltic societies today and in the future. Management of data privacy is vital for the regulatory compliance but more over for the business success of the bank. As the regulatory landscape...


  • Tallinn, Harjumaa, Estonia Bolt Full time €60,000 - €120,000 per year

    You will join a cross-functional team that blends first-party user insights with a privacy-first marketing experience. Your mission is to build an internal platform for email templates, in-app surveys, consent collection, and language policy that lets teams communicate better and faster while respecting user trust and local regulations. You will partner with...


  • Tallinn, Harjumaa, Estonia Wise Full time €40,000 - €80,000 per year

    Company Description Wise is a global technology company, building the best way to move and manage the world's money.Min fees. Max ease. Full speed.Whether people and businesses are sending money to another country, spending abroad, or making and receiving international payments, Wise is on a mission to make their lives easier and save them money.As part of...

  • Legal Counsel, EU

    7 days ago


    Tallinn, Harjumaa, Estonia Lightspark Full time €72,061 - €84,594

    Lightspark is building open payments for the Internet—always-on payment solutions powered by Bitcoin, the only open, neutral network for moving value. With enterprise tools like Connect, UMA, and Spark, businesses can send and receive money instantly, securely, and at a fraction of the cost, anytime, anywhere. Lightspark is headquartered in Los Angeles,...

  • Product Counsel

    6 days ago


    Tallinn, Harjumaa, Estonia Bolt Full time €5,400 - €36,000 per year

    We're looking for a Product Counsel to support Bolt's Rentals vertical — Europe's largest shared e-scooter fleet and growing car rental service via Bolt Drive. You'll work across our app, website, and back-end services, partnering closely with product, engineering, and policy teams to ensure compliance as we scale fast.About usWith over 200 million...

  • B2B Account Manager

    2 days ago


    Tallinn, Harjumaa, Estonia Pax8 Full time €40,800 - €68,720 per year

    Come and joinPax8,Microsoft's Global Partner of the Year 2024, as an Account Manager, based inTallinn, Estoniain our stellar Sales Team.It's an exciting time to become part of Pax8 Estonia as we enter the next significant stage of our incredible growth. This role offers immense opportunities to make an impact, build your legacy, and contribute to our...

  • Tech Lead

    3 hours ago


    Tallinn, Harjumaa, Estonia Inbank Full time €40,000 - €80,000 per year

    Hello from Inbank If you've ever bought something in three instalments or financed your gadget purchase online or in a shop, there's a good chance you've used something we built. Since you're reading this, you're probably looking around, or at least curious about what's out there. We get it: choosing your next role is a big decision. Let's get...

  • Tech Lead

    3 hours ago


    Tallinn, Harjumaa, Estonia Inbank Full time €80,000 - €120,000 per year

    Hello from Inbank If you've ever bought something in three instalments or financed your gadget purchase online or in a shop, there's a good chance you've used something we built.Since you're reading this, you're probably looking around, or at least curious about what's out there. We get it: choosing your next role is a big decision. Let's get...

  • Legal Counsel, EU

    7 days ago


    Tallinn Metropolitan Area, Estonia Lightspark Full time €72,061 - €84,594 per year

    Lightspark is building open payments for the Internet—always-on payment solutions powered by Bitcoin, the only open, neutral network for moving value. With enterprise tools like Connect, UMA, and Spark, businesses can send and receive money instantly, securely, and at a fraction of the cost, anytime, anywhere. Lightspark is headquartered in Los Angeles,...