A vacancy for a privacy officer, information security officer or compliance officer has been open for weeks. You have shared it widely, engaged recruiters, perhaps even re-promoted the role. Still, the right candidates are nowhere to be found.
The first assumption is usually that the labour market is tight. Yet the real issue often lies elsewhere: in the job advert itself.
At ICTRecht Recruitment & Selection, we see privacy, security and compliance vacancies every day in which organisations inadvertently filter out exactly the candidates they need. Sometimes the warning signs are obvious. A single role demands multiple specialisms, the job title does not match market expectations, or the text focuses on what a candidate must bring rather than what the organisation has to offer.
In earlier blogs we discussed the scarcity of hybrid profiles at the intersection of law, security and technology, and what happens when AI takes over traditional junior-level work. Both topics address the same question: how do you find and retain the right professionals in a changing labour market? The answer often starts earlier than organisations expect, with the job advert itself.
Wanted: someone with deep expertise in privacy, security and AI, experience in compliance, and preferably strong commercial skills as well.
On paper, that profile sounds appealing. In practice, this could mean you are trying to combine multiple roles into one position. We see this particularly in positions at the crossroads of privacy and security. An organization might be looking for a single person to handle both privacy matters and information security, or for someone to act simultaneously as Privacy Officer and Data Protection Officer (DPO). Some combinations make sense. Smaller organisations, in particular, may not have enough work or budget to hire a separate specialist for every discipline.
The problem arises when a single vacancy demands expert-level knowledge across multiple fields. A professional who meets four of the five requirements might conclude that the position is simply not the right fit for them. Ask yourself two questions: what must someone be able to do from day one, and what can they learn on the job?
Five clear core requirements are often more effective than fifteen separate demands. Not because you are lowering the bar, but because you are making clear what truly matters.
The content of a role may be interesting, but if the job title doesn't align with market standards, candidates might not even come across your vacancy. A title like "Compliance Specialist" can mean a wide range of things. Does it involve privacy compliance, regulatory compliance, information security, GRC, or a mix of all four? Titles such as "Legal & Compliance Officer" or "Security & Privacy Specialist" can likewise set very different expectations.
Moreover, candidates typically search for job titles they recognise from their own field. An organisation may use a particular name internally, while professionals outside the company search for something entirely different. Therefore, consider not only what you call the role in-house, but also how candidates search for similar positions.
Positioning goes beyond the job title, however. The way you describe the role shapes how candidates perceive it. A Privacy Officer vacancy might emphasise administrative tasks and compliance checks, even though the organisation is actually looking for someone to act as a strategic advisor and partner to the business.
Therefore, be clear about the role, responsibilities, and context. This ensures that a candidate knows not only the job title but also the role they will actually be performing.
Some job postings seem written for a single ideal candidate who has already mastered everything. For example: five years of experience in privacy and a background in security; knowledge of the GDPR, NIS2, DORA, and the AI Act; an affinity for technology; and strong commercial and communication skills. Such a candidate might exist. But the key question is whether someone really needs to be able to do all of this from day one. The field, particularly within privacy, security, and compliance, is evolving rapidly. New legislation, technologies, and responsibilities are constantly emerging. It is not always realistic to look for someone who already possesses all the relevant knowledge for every role. Therefore, distinguish between:
A candidate who does not tick every nice-to-have box may still be an excellent fit. By making clear what someone can learn, you widen your talent pool without materially lowering your standards.
A long list of requirements tells candidates what you expect from them. But for privacy, security and compliance professionals who already have a good job, a different question is just as important: Why should I choose this role?
What level of responsibility will someone have? What kind of challenges will they work on? How much influence will they enjoy? What opportunities are there for training and development? And what does the longer-term prospects look like? The context in which the person will be working can also be a key factor in their decision to switch jobs. So explain not only what someone will do, but also who they will be working with. How large is the team? What expertise is already in place? Which colleagues or disciplines will they collaborate with? This gives candidates a much clearer picture of the work environment.
Consider highlighting:
A job advert is not just a description of what you are looking for; it is also an outline of what you have to offer.
Beyond the nature of the work and opportunities for development, salary plays a major role. A specific salary range helps candidates determine upfront whether a position aligns with their expectations. Moreover, it prevents situations where a significant gap in salary expectations only comes to light after multiple interviews.
Pay transparency is becoming increasingly important from a regulatory perspective as well. The EU Pay Transparency Directive will introduce further obligations for employers in the coming years. Being open about remuneration is therefore not only good practice but also a matter of compliance.
Do you want to know if your vacancy is attractive enough? Try reading it as if you were a candidate yourself. Can you answer these questions immediately after reading it?
If those answers are not clear from the text in the job advert, that is probably an opportunity to improve the text.
Knowledge-sharing has been a core part of what we do at ICTRecht for years. Our blogs, white papers and training courses cover regulation, technology and the associated practical aspects.
But finding and retaining talented professionals is a discipline in its own right. That is why our recruitment & selection looks at more than just where to find candidates. We work with organisations on the job profile, the positioning of the role and the vacancy text itself.
Perhaps a hard-to-fill vacancy does not start with the question "Where can we find more candidates?" Perhaps it starts with a different question: "Are we really asking for what we need? And are we showing clearly enough what we offer in return?"
Want to know whether your privacy, security or compliance vacancy is attracting the right candidates? Let us review your job advert, free of charge. Get in touch. We are happy to help.
Please note: this page is currently in Dutch, but feel free to fill out the contact form at the bottom of the page in English. We are happy to assist you.