Al Khayyat Investments is looking for a Data Protection Officer to lead data protection and privacy activities across the Group.
This role is suitable for a technically strong professional with experience in IT audit, information security, technology compliance, data protection, and privacy governance.
Key Responsibilities
- Lead data protection and privacy activities across group operations and support functions.
- Ensure alignment with data protection policies, data classification standards, and applicable regulations.
- Support data governance activities, including data classification, labelling, and Records of Processing Activities.
- Conduct risk assessments, DPIAs, transfer impact assessments, and maintain the privacy risk register.
- Perform audits covering IT General Controls, information security, cyber security, data processing activities, systems, vendors, and third parties.
- Review vendor arrangements, data processing agreements, and privacy due diligence requirements.
- Support personal data breach response, including investigation, impact assessment, and regulatory notification.
- Deliver data protection awareness and training across the organisation.
- Work closely with Internal Audit, IT, and business teams to assess controls across ERP, CRM, HR, e-commerce, SaaS platforms, and emerging technologies.
Requirements
- Bachelor's degree in Information Technology, Computer Science, Information Security, or a related field.
- 2–3 years of experience in IT internal audit, information security audit, technology compliance, or consulting.
- Hands-on audit experience is essential.
- Knowledge of ISO 27001, COBIT, NIST CSF, UAE PDPL, ADHICS, KSA PDPL/SDAIA, Oman PDPL, GDPR, ISO/IEC 27701, or NIST Privacy Framework.
- Experience with enterprise systems such as SAP, Oracle, Microsoft Dynamics, cloud platforms, or SaaS applications.
- Strong report-writing, communication, and stakeholder management skills.
Preferred
- CIA, CISA, ISO 27701 Lead Implementer/Auditor, or equivalent certification.
- Experience in a large, diversified, or multi-entity organisation.
- Familiarity with GRC platforms and AI governance concepts.