
COFRA Holding · Porto
About COFRA Holding AG COFRA Holding AG is a family-owned group, headquartered in Switzerland, with operations in Europe, the Americas and Asia. COFRA has a di...
About COFRA Holding AG
COFRA Holding AG is a family-owned group, headquartered in Switzerland, with operations in Europe, the Americas and Asia. COFRA
has a diverse portfolio of investment businesses in private equity (Bregal Investments), real estate (Redevco) and asset
management (Anthos Fund & Asset Management). Businesses and investments are also held in retail, clean energy and sustainable
food. Through business, COFRA strives to be a force for good in the world – a mission that began over 180 years ago. Today, we
actively direct our expertise, energy and capital into businesses and investments that we believe have the potential to create
superior value.
Think about Data Governance differently and make a real impact
A welcoming and supportive setting where you can develop and make a real difference in the world – that’s what you’ll find at
COFRA. We’re a family business, geared to creating lasting value and united by an ambition to change industries and society for
the better. Aspiration and entrepreneurism are encouraged and rewarded with opportunity. Teams are diverse yet close-knit.
Relationships matter. People matter.
What we can achieve together
One of our greatest strengths is our people: talented, dedicated professionals who are true experts in their field, committed to
the pursuit of excellence and open to new opportunities and ways of capturing them.
We're looking for an experienced Data Governance Lead to join our COFRA team in Porto. You will join a multi-generational family
business with a commitment to achieve systemic change across Liveable Cities, Responsible Capital, Clean Energy and Sustainable
Food together with our management teams and mission-aligned external partners.
About the role
The Data Governance Lead is responsible for establishing and maintaining the Group’s data governance framework, ensuring master
data quality, consistency, and control across all entities and systems. The incumbent will be focused on building a unified data
foundation by defining standards, enforcing governance, and partnering with Data Owners/SMEs to ensure end‑to‑end data integrity.
It acts as the central authority for data definitions, lineage, stewardship, and quality monitoring.
standards.
quality rules, and approval workflows, while setting up governance forums, stewardship roles, and operating procedures to
ensure clear data ownership and accountability.
platforms.
Group IT, Security, and application teams to ensure compliance with regulatory requirements, data protection standards, and
audit expectations.
Lead cross-entity data cleansing and harmonisation initiatives supporting consolidation, investment reporting, and digital
integration.
maintain group-wide data catalogues, business glossaries, and reference data sets.
governance initiatives, ensuring adherence to governance standards, security principles, and operating model expectations.
between governance design and operational execution. Train stakeholders on processes, quality expectations, and governance
rules, and support entities in adopting standardised data models and reporting hierarchies.
knowledge of enterprise data management, data governance, and data visualisation, as well as robust analytical skills. It also
demands solid experience in agile and waterfall project management, strong project delivery capabilities, and the ability to
conduct risk assessments, identify vulnerabilities, and implement effective mitigation strategies.
accountability, supporting continuous learning and adaptability, and promoting an inclusive and high-performing team
environment.
What You Bring
What we offer you in return
The opportunity itself is a great way to have a direct impact on the Group and realize potential across a multitude of areas.
COFRA offers notable benefits. Also, training and development is provided to all COFRA employees.
COFRA is an Equal Opportunity Employer and does not discriminate on the basis of age, race, colour, sex, sexual orientation,
gender identity, religion, national origin or disability. None of this gets in the way of hiring and retaining the best people.
WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. Why we're hiring: The Identity, AI and Data Access Governance Lead is responsible for governing who, and what, can access DTS systems, data, APIs, tools, workflows and AI-enabled capabilities. This is a hands-on governance and control role, reporting into the SVP Security and Compliance. The role ensures that access across DTS is appropriate, auditable, reviewed, least-privileged and aligned with security, privacy, compliance and client commitments. The scope covers traditional human access, external users, privileged access, service accounts, machine identities, API keys, tokens, dataset access, and the emerging governance of AI agents and agentic workflows. The role will work closely with Architecture, Security, Product, Engineering, Infrastructure, Privacy, Legal/DPO, TechOps, Enterprise Technology and the ISMS and Risk Officer to ensure DTS has a clear and controlled model for access across platforms such as WPP Open, Choreograph, InfoSum, Open Intelligence, Resolve and related DTS capabilities. What you'll be doing: 1. IDENTITY AND ACCESS GOVERNANCE FRAMEWORK Define and maintain the access governance framework for DTS. This includes: * Defining access governance standards, processes and control expectations. * Establishing how access should be requested, approved, provisioned, reviewed, revoked and evidenced. * Ensuring access governance covers internal users, external users, clients, partners, vendors, service accounts, machine identities and AI agents. * Aligning identity and access governance with DTS architecture, security, privacy, compliance and data governance requirements. * Ensuring access governance is practical for product and engineering teams to implement. 2. ACCESS REVIEWS AND RECERTIFICATION Own the process for regular access reviews and recertification across DTS. This includes: * Defining the scope, frequency and evidence requirements for access reviews. * Coordinating access reviews for critical DTS systems, production environments, privileged roles, sensitive datasets, client-facing platforms and administrative tools. * Ensuring access review outcomes are tracked, remediated and evidenced. * Identifying stale, excessive, orphaned or poorly owned access. * Escalating overdue, high-risk or unresolved access issues through the appropriate governance channels. 3. PRIVILEGED ACCESS GOVERNANCE Ensure privileged access across DTS is properly controlled, justified and auditable. This includes: * Reviewing access to production systems, cloud environments, security tools, databases, CI/CD tooling, administrative consoles and sensitive platforms. * Supporting least-privilege, just-in-time and time-bound access models where appropriate. * Working with Cloud and Platform Security and Infrastructure to improve privileged access controls. * Ensuring privileged access risks are visible in the DTS risk register where required. 4. EXTERNAL USER, CLIENT AND PARTNER ACCESS GOVERNANCE Govern access for external users, clients, agencies, partners and vendors. This includes: * Defining standards for external user onboarding, approval, permissions, expiry and offboarding. * Ensuring external access has a clear business owner and justification. * Supporting access governance across client workspaces, agency environments, partner integrations and shared collaboration areas. * Working with Product and Engineering to ensure tenant, workspace and client-level isolation is appropriately governed. * Tracking risks related to stale accounts, vendor access, partner permissions and external user overprivilege. 5. SERVICE ACCOUNT, MACHINE IDENTITY AND API ACCESS GOVERNANCE Govern non-human access across DTS systems and platforms. This includes: * Defining standards for service accounts, machine identities, automation users, API keys, tokens, secrets and integration credentials. * Ensuring non-human access has clear ownership, purpose, scope, rotation, expiry and auditability. * Working with Product, Engineering, Cloud Security and Infrastructure to reduce unmanaged credential risk. * Ensuring service accounts and machine identities are included in access reviews. * Supporting stronger governance of API access, token issuance, credential lifecycle and integration permissions. 6. AI AND AGENTIC ACCESS GOVERNANCE Define and oversee the governance model for AI agents and agentic workflows across DTS. This includes: * Defining how AI agents are identified, permissioned, monitored, reviewed and revoked. * Ensuring agents have clear ownership, scoped permissions and auditable actions. * Defining which agent actions require human approval or additional control. * Governing agent access to APIs, tools, datasets, workflows, client environments and production capabilities. * Ensuring agents act within delegated authority and cannot exceed the permissions of the user, system or business process they represent. * Working with Product, Architecture and Security to ensure agentic workflows are designed with clear action boundaries. * Working with the Product, Application and Offensive Security Lead to test whether agent permissions and action boundaries can be bypassed. * Working with Privacy Engineering to ensure AI access models support permitted use, minimisation and data protection requirements. 7. DATA ACCESS GOVERNANCE Govern access to sensitive, client, partner and WPP-owned data across DTS. This includes: * Defining standards for dataset access approval, review, revocation and evidence. * Supporting data classification from an access-control and security-governance perspective. * Ensuring access to sensitive data is role-based, purpose-based, least-privileged and auditable. * Supporting controls for cross-client, cross-market, cross-agency and partner data access. * Ensuring data access governance supports InfoSum, Open Intelligence, Resolve, WPP Open and other DTS data collaboration use cases. * Working with Privacy Engineering on data minimisation, permitted use, retention and privacy-by-design requirements. * Ensuring data access risks are surfaced through the DTS risk process. 8. GOVERNANCE OF ACCESS TO TOOLS, WORKFLOWS AND ACTIONS Ensure access governance extends beyond systems and datasets into tools, workflows and actions. This includes: * Defining governance for access to operational tools, workflow automation, orchestration systems, AI tools and administrative actions. * Ensuring high-risk actions are subject to appropriate approval, logging and monitoring. * Supporting segregation of duties across sensitive workflows. * Ensuring automated workflows and agents have clearly scoped authority. * Working with Security Operations to ensure high-risk access and actions are visible in monitoring and detection processes. 9. AUDITABILITY, EVIDENCE AND REPORTING Maintain clear evidence of access governance and support audit and assurance requirements. This includes: * Producing access governance evidence for SOC 2, ISO 27001, client assurance, internal audit and risk reviews. * Working with the ISMS and Risk Officer to ensure access controls, reviews, exceptions and remediation actions are documented. * Reporting on access review completion, high-risk access, overdue actions and access control gaps. * Supporting client and audit questions related to identity, access, privileged roles, service accounts, AI agents and data access. * Ensuring access governance is repeatable, measurable and auditable. Who you'll be working with: The Identity, AI and Data Access Governance Lead will be accountable for: * DTS identity and access governance standards. * Regular access reviews and recertification. * Privileged access governance. * External user, client, partner and vendor access governance. * Service account, machine identity, API key and token governance. * AI agent identity, permission and action governance. * Dataset and sensitive data access governance. * Governance of access to tools, workflows and high-risk actions. * Access governance evidence for audit, compliance and client assurance. * Escalation of material access risks into the DTS risk process. What you'll need: The successful candidate will have: * Experience in identity governance, access management, IAM, security governance, GRC, data access control or platform security. * Strong understanding of least privilege, role-based access control, attribute-based access control, access reviews, privileged access and segregation of duties. * Experience governing access across SaaS platforms, cloud environments, APIs, data platforms or enterprise technology estates. * Knowledge of identity platforms such as Okta, Auth0, Keycloak, Azure AD / Entra ID or similar. * Understanding of service accounts, machine identities, API keys, tokens, secrets and non-human access governance. * Understanding of AI agents, agentic workflows, delegated authority and tool-access governance would be highly valuable. * Understanding of data classification, dataset access governance, privacy-by-design and audit requirements. * Ability to work across security, architecture, product, engineering, infrastructure, legal, privacy and compliance teams. * Strong organisational skills and ability to coordinate reviews, evidence, remediation and reporting. * Ability to translate complex access issues into clear risks, controls and practical actions. LEADERSHIP EXPECTATIONS The Identity, AI and Data Access Governance Lead is expected to: * Be structured, disciplined and pragmatic. * Bring clarity to complex access and permission models. * Challenge excessive, unclear or poorly governed access. * Work constructively with product and engineering teams to design workable controls. * Avoid creating unnecessary bureaucracy while ensuring access is properly governed. * Treat human, machine and agent access as part of the same control landscape. * Escalate material access risks clearly and early. * Support DTS in building a secure, auditable and scalable access governance model. SUCCESS MEASURES Success in the role will be measured by: * DTS having clear identity, access and data access governance standards. * Regular access reviews completed on schedule with evidence. * Reduction in stale, excessive, orphaned or poorly owned access. * Stronger governance of privileged access and production access. * Clear ownership and review of service accounts, machine identities, API keys and tokens. * Defined governance for AI agent identities, permissions and actions. * Improved auditability of access to data, APIs, tools, workflows and production systems. * Better alignment between identity, security, privacy, architecture, product and engineering teams. * Material access risks being visible through the DTS risk register and Risk Review Board. * Increased confidence that DTS can answer: who or what has access to what, why, and when was it last reviewed? Who you are: You're open: We are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open-minded: to new ideas, new partnerships, new ways of working. You're optimistic: We believe in the power of creativity, technology and talent to create brighter futures or our people, our clients and our communities. We approach all that we do with conviction: to try the new and to seek the unexpected. You're extraordinary: we are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day. What we'll give you: Passionate, inspired people – We aim to create a culture in which people can do extraordinary work. Scale and opportunity – We offer the opportunity to create, influence and complete projects at a scale that is unparalleled in the industry. Challenging and stimulating work – Unique work and the opportunity to join a group of creative problem solvers. Are you up for the challenge? #LI-Hybrid We believe the best work happens when we're together, fostering creativity, collaboration, and connection. That's why we’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process. WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers. PLEASE READ OUR PRIVACY NOTICE (HTTPS://WWW.WPP.COM/EN/CAREERS/WPP-PRIVACY-POLICY-FOR-RECRUITMENT) FOR MORE INFORMATION ON HOW WE PROCESS THE INFORMATION YOU PROVIDE.
Securitas Group Securitas is a world-leading safety and security solutions partner that helps make your world a safer place. With nine decades of deep experience means we see what others miss. By leveraging technology in partnership with our clients, combined with an innovative, holistic approach, we’re transforming the security industry. With 322 000 employees in 44 markets, we see a different world and create sustainable value for our clients by protecting what matters most - their people and assets. Securitas IT in AMEA Securitas IT in AMEA deliver IT-services to our 12 countries within the region. We provide the technology needed to fulfill the Securitas business strategy to be client centric, data driven, and people focused. We transform, build and protect our IT landscape in a professional and cost-efficient way. We are a diverse and inclusive team that all help each other out and have a great deal of fun together. ---------------------------------------------------------------------------------------------------------------------------------- Role overview We are seeking an experienced and driven Data/BI Manager (Finance & Operations) to lead the reporting and data enablement function, bridging the gap between our requirements from our countries and divisional functions (including Finance, People/HR and IT) users and technical data teams. This role will translate business needs into actionable data solutions, manage end-to-end reporting delivery, ensure data quality and compliance, and guide the team of data analysts and engineers. A key aspect of this role will be to recruit, build, and lead a high-performing data reporting team, establishing scalable processes and robust governance for long-term success. The ideal candidate combines strong technical data capabilities with a deep understanding of Finance KPIs, compliance, and reporting needs. He/she will act as a Strategic Data Partner to become a bridge between business goals and technical execution, focusing on maximizing value by prioritizing critical requirements. ---------------------------------------------------------------------------------------------------------------------------------- Responsibilities 1. Reporting and Analytics • Translate Finance business needs into data & reporting requirements. • Design intuitive and interactive dashboards using Power BI. • Analyze financial data for trends, variances, and insights to support business strategy. • Present findings and recommendations to stakeholders, Finance leadership, and cross-functional teams. 2. Business-Technology Interface • Serve as the primary liaison between our country and divisional stakeholders and technical data teams • Convert business objectives into detailed functional and technical specifications. • Review and validate data models, source-to-target mappings, and metric definitions. • Ensure proper implementation by collaborating closely with data engineers and BI developers. 3. Data Management and Governance • Lead initiatives on data quality, lineage, consistency, and regulatory compliance (e.g., GDPR). • Establish and enforce data governance policies, processes, and metadata standards, in alignment with the Global IT guardrails. • Conduct root cause analysis for data issues and define quality rules and reconciliation frameworks. • Oversee the data lifecycle management across source systems, warehouses, and reporting layers. 4. Team Leadership and Collaboration • Manage and mentor a team of data analysts, report developers, and data engineers. • Promote collaboration, resolve escalations, and drive continuous improvement in data practices. • Foster a culture of transparency, documentation, and knowledge sharing. Make feedback part of that culture to grow your way of working and your team members • Develop project plans, ensure executing efficiency • Roadmap to achieve department goals • Stakeholder collaboration – bridge between the different departments for a smooth coordination (IT, HR, Finance) across the different countries of the team members 5. Technical Oversight • Understand end-to-end data flows, system integrations, and data architecture. • Oversee development of data pipelines and cloud-based infrastructure (Azure preferred). • Support DevOps and CI/CD-based deployment for reporting and data assets. • Collaborate with IT for performance optimization, platform upgrades, and solution scalability. ---------------------------------------------------------------------------------------------------------------------------------- Requirements * 6+ years of experience in data analytics, BI/reporting including 2+ years in data management roles. * Demonstrated success in Finance reporting transformation. Reporting within sales and HR is advantageous. * Strong knowledge of Finance processes, KPIs, and regulatory reporting. * Demonstrated success in building reporting teams. * Hands-on experience with reporting platforms (Power BI), data modelling, and cloud architecture (Azure Data Factory) * Proficiency in SQL and familiarity with scripting (Python preferred). * Experience working in Agile/Scrum environments and leading delivery in distributed teams. * Proven track record of driving team initiatives to meet company goals and fostering a culture of accountability. * Demonstrated ability to mentor, motivate, and develop high-performing teams. * Extensive experience working with cross-functional teams to deliver complex projects. * Excellent interpersonal, verbal, and written communication skills to influence stakeholders at all levels. * Excellent verbal and written English; ability to present and influence at all levels. * Prior experience in working with ERP (Dynamics), Finance and HR applications is a plus. Core Skills and Competencies Technical • SQL, Python, Advanced Excel • Power BI (Visualization) and Fabric features • Fabric Knowledge: Understand Lakehouse architecture, OneLake, Dataflows, and integration with Synapse and Notebooks. • DAX expertise • Azure DevOps Cloud Platform: Azure preferred • Data Modelling, Metadata Management (Collibra, Databricks) • Data warehousing, Data Lake • CI/CD, ETL/ELT tools (Azure Data Factory, SSIS) Analytical • Financial KPIs (P&L, AP/AR, Cost Centers, Forecasts) • Problem-Solving & Root Cause Analysis • Critical Thinking & Data Interpretation • Statistical & Trend Analysis Leadership and Soft Skills • People management, hiring and team building • Stakeholder Engagement & Communication • Team Leadership & Coaching • Attention to Detail, Time Management • Adaptability & Cross-Functional Collaboration • Needs vs. Wants Assessment: Skilled in prioritizing features based on business value. ---------------------------------------------------------------------------------------------------------------------------------- Working conditions The role is open for candidates based in Gurugram, India. It's a hybrid working model. ---------------------------------------------------------------------------------------------------------------------------------- WHAT WE OFFER At Securitas we believe in doing the right thing and doing it well. For our customers and our employees. Our employees come from all walks of life and bring with them a multitude of talents and perspectives. We aim for diverse representation throughout the company, and we are committed to equal pay, safe working conditions, gender balance and an inclusive work environment with a wide range of skills and development opportunities. If it all sounds good to you, don’t hesitate to apply!
ABOUT AVEPOINT AvePoint is the global leader in data protection, unifying data security, governance, and resilience to provide a trusted foundation for AI. More than 28,000 customers rely on the AvePoint Confidence Platform to secure, govern, and rapidly recover data across Microsoft, Google, Salesforce, and other cloud environments. With a single platform for lifecycle control, multicloud governance, and rapid recovery paired with clear ownership across the business, we prevent overexposure and sprawl, modernize legacy and fragmented data, and minimize data loss and interruption. Our global partner ecosystem includes approximately 6,000 MSPs, VARs, and SIs, and our solutions are available in over 100 cloud marketplaces. To learn more, visit www.avepoint.com [https://www.avepoint.com/]. ABOUT THE ROLE Enterprises are adopting AI faster than they can govern it, and they're looking for a partner who can do two things exceptionally well: * Speak credibly about AI trust, governance and security. * Build real AI solutions that solve business problems. As a Forward Deployed Engineer (AI), you'll be the technical face of AvePoint inside enterprise customers. You'll be equally comfortable: * Whiteboarding AI trust and governance concepts with CISOs and executives. * Translating business challenges into scoped AI delivery projects. * Building the first working prototype yourself. You'll embed with customers, own engagements end-to-end, and deliver tangible outcomes. This isn't a traditional pre-sales role or a back-office delivery position. It's a highly autonomous customer-facing engineering role inspired by the engagement models used by leading AI companies—owning problems from discovery workshops through to production. WHAT YOU'LL DO Advise on AI Trust & Governance * Lead AI governance and discovery workshops. * Help customers understand and govern their AI landscape (agents, copilots, models and shadow AI). * Explain AI governance, security posture and resilience to both technical and executive audiences. * Help establish: * AI inventories * Approval workflows * Risk classifications * Audit evidence * Practical AI operating models. Scope & Shape AI Projects Work directly with business stakeholders to understand the real business problem behind AI initiatives. You'll: * Identify high-value AI use cases. * Define success criteria. * Translate ambiguous requirements into deliverable technical scopes. * Produce: * Architecture outlines * Data & integration requirements * Delivery phases * Effort estimates * Risk assessments * Write Statements of Work (SoWs) customers can sign and engineering teams can deliver. Build & Deliver Develop both prototypes and production-ready AI solutions including: * AI agents * RAG pipelines * LLM integrations: * Azure OpenAI * AWS Bedrock * Google Vertex AI * Anthropic * MCP-based tool integrations * Governance and security controls You'll also build custom tooling for regulated, cloud-restricted or air-gapped environments where SaaS solutions aren't suitable. Own Customer Delivery Remain the trusted technical advisor throughout the engagement by: * Running enablement sessions. * Supporting customer adoption. * Troubleshooting production issues. * Identifying opportunities to expand engagements where genuine customer value exists. WHAT WE'RE LOOKING FOR Must-Haves * 5+ years in Software Engineering, Solutions Architecture or Technical Consulting. * 2+ years building modern AI/LLM solutions in production (not just experimentation). * Hands-on experience with: * Azure OpenAI * AWS Bedrock * Google Vertex AI * LangChain * Semantic Kernel * Experience building: * RAG solutions * Agentic workflows * Tool/function calling * Strong programming skills in: * Python * C# * TypeScript * Experience with Azure, AWS or GCP, including identity, networking and data services. * Proven ability to scope technical projects from ambiguous business requirements. * Excellent communication skills—from board-level conversations through to deep technical discussions. * Comfortable working autonomously in fast-moving client environments. * Willingness to travel (~40%). Strong Pluses * AI Security: * Prompt injection * Data leakage * Agent permissions * AI-SPM / DSPM * Experience with: * Model Context Protocol (MCP) * Agent runtimes * Pinecone * Milvus * Weaviate * Chroma * Enterprise data governance, backup, resilience or Microsoft 365 ecosystems. * Experience delivering into regulated industries: * Public Sector * Defence * Financial Services * Healthcare * Experience in air-gapped or sovereign cloud environments. * Previous Forward Deployed Engineering, embedded consulting or customer-facing engineering experience. Any personal data you share with us during the application process will be processed strictly in compliance with applicable data protection laws and our Privacy Notice [https://www.avepoint.com/company/privacy-notice]. #LI-SB1 Any personal data you share with us during the application process will be processed strictly in compliance with applicable data protection laws and our Privacy Notice [https://www.avepoint.com/company/privacy-notice].