Data Protection Officer

منذ 7 أيام

Riyadh, المملكة العربية السعودية Bahwan CyberTek دوام كامل
.

Key Responsibilities
Regulatory Compliance & Governance Lead compliance with KSA Personal Data Protection Law (PDPL) and related implementing regulations. Interpret and operationalize guidance issued by the Saudi Data & AI Authority (SDAIA) and other relevant authorities. Design, implement, and maintain data protection policies, standards, and procedures aligned with Saudi regulations. Ensure ongoing compliance with cross-border data transfer requirements and data localization mandates. Advisory & Stakeholder Engagement Serve as the primary Data Protection advisor to Grant Thornton UAE leadership and client-facing teams operating in KSA. Provide guidance on privacy-by-design and privacy-by-default principles across systems, processes, and engagements. Act as the main point of contact for regulatory authorities on data protection matters, including audits, inquiries, and inspections. Risk Management & Controls Conduct Data Protection Impact Assessments (DPIAs) and privacy risk assessments. Identify data privacy risks and recommend mitigation strategies. Monitor compliance through internal audits, reviews, and ongoing assessments. Incident Management Lead data breach response activities, including investigation, documentation, regulatory notification, and remediation. Develop and test incident response and breach notification procedures in line with KSA requirements. Training & Awareness Develop and deliver data protection training and awareness programs for staff and key stakeholders. Promote a strong data protection and privacy culture across the organization. Documentation & Reporting Maintain Records of Processing Activities (RoPA). Prepare compliance reports, management updates, and regulatory documentation as required. Required Experience & Qualifications 7-10 years of progressive experience in data protection, privacy, or information governance roles. Demonstrated, hands-on experience with Saudi Arabia’s PDPL and associated regulations. Experience working with professional services firms, consulting organizations, or regulated environments is strongly preferred. Prior experience acting as a named or de-facto DPO is highly desirable. Knowledge & Skills In-depth understanding of: KSA PDPL and implementing regulations SDAIA compliance requirements Data localization and cross-border data transfer controls Strong risk assessment, policy development, and compliance monitoring skills. Ability to engage confidently with regulators, senior leadership, and client stakeholders. Excellent written and verbal communication skills in English (Arabic is a strong plus). Certifications (preferred) CIPP/E, CIPP/M, CIPM, or equivalent privacy certifications. ISO 27701 / ISO 27001 knowledge or certification is a plus.

Job Type
s
: Full-time, Contract