Role Overview
We are hiring a Data Protection & Privacy Specialist to act as a techno-functional bridge between privacy technology platforms (BigID / Securiti AI / OneTrust) and regulatory / business stakeholders within a banking environment in the UAE. The role combines hands-on technical implementation and administration of privacy tools with advisory-level engagement on data protection compliance, governance, and reporting — supporting the client's ongoing and future rollout of these platforms.
Minimum Qualifications & Experience
- Engineering or Post-Graduate Degree with 4–8 years of overall experience in Data Privacy / Data Protection, ideally within BFSI or another regulated industry.
- Prior experience with a Big 4 / consulting firm or similar advisory environment is highly preferred, demonstrating exposure to client-facing, techno-functional delivery.
- Hands-on, working-level experience configuring and administering at least one enterprise privacy platform — BigID, Securiti AI, or OneTrust — is mandatory (not purely functional/advisory exposure).
- Demonstrated ability to operate at both a technical level (tool configuration, data discovery/classification, DSAR workflow automation) and a functional/advisory level (policy interpretation, stakeholder guidance, gap assessments, reporting).
Skills
Regulatory & Domain Knowledge
- Strong working knowledge of CBUAE Consumer Data Protection requirements and UAE Privacy Laws.
- Familiarity with global and regional data protection regulations (GDPR, KSA PDPL, Qatar PDPPL, CCPA/CPRA or similar).
- Solid understanding of Information Security fundamentals, data privacy frameworks, and the end-to-end IT data lifecycle.
- Preferred certifications: CIPP/E, CIPM, CIPT, CDPO, or equivalent BigID / Securiti / OneTrust product certifications.
Technical Skills (Hands-On)
- Privacy Platform Administration: BigID and/or Securiti AI and/or OneTrust — modules such as Sensitive Data Intelligence (SDI), Data Subject Rights (DSR/DSAR), RoPA, Assessments (DPIA/PIA), Consent & Preference Centre.
- Data Discovery & Classification: configuring scanning profiles, classification schemas, and sensitive/PII data detection tuning across structured, semi-structured, and unstructured sources.
- Platform Integration: onboarding data sources (databases, cloud, file shares, SharePoint, Exchange, Teams) and integrating with SIEM / DAM / DSPM tooling.
- Working familiarity with adjacent data security tooling (e.g., IBM Guardium, Imperva, Thales, CyberArk) is an advantage.
- Reporting & Dashboards: building compliance and governance dashboards/KPIs (Power BI, Tableau, or SSRS) for regulatory and management reporting.
Functional / Advisory Skills
- Advise business and technology teams on privacy-by-design, data protection requirements, and regulatory obligations.
- Draft and maintain RoPA, DPIA/PIA templates, and privacy assessment frameworks.
- Conduct privacy monitoring, gap assessments, audits, and compliance testing; drive remediation of identified gaps.
- Design and support operating models (BAU, RACI) that embed privacy into day-to-day business processes.
- Coordinate with third-party vendors to ensure compliance with privacy and data protection requirements.
- Deliver training and awareness sessions to internal teams and support knowledge transfer to operations/BAU teams.
- Support auditors and external assessors during regulatory reviews and assessments.
Key Responsibilities
- Implement, configure, and maintain data protection tooling (BigID / Securiti AI / OneTrust) in line with client architecture (e.g., Kubernetes/OpenShift environments).
- Maintain an accurate inventory of personal data and data processing activities (RoPA) across the organization.
- Ensure ongoing compliance with UAE data protection laws (CBUAE, PDPL) and applicable global privacy regulations.
- Lead and coordinate cross-functional data protection initiatives spanning IT, Legal, Compliance, and Risk.
- Identify control gaps in current privacy/data protection frameworks and drive remediation plans to closure.
- Produce regulatory and management dashboards/reports on privacy compliance posture, DSAR turnaround, and risk metrics.
- Support the client's roadmap for expanding privacy tool adoption, given the anticipated future rollout of these platforms.
What Makes a Strong Fit
- Someone who has personally configured/administered a privacy platform (not only used it as an end-user or advised on it from a policy perspective).
- Comfortable moving between a technical conversation with platform/IT teams and an advisory conversation with compliance/business stakeholders in the same day.
- Prior exposure to banking/BFSI clients in the GCC region is a strong plus.