Data Protection Officer

Techconnect

Asia

Presencial

PEN 180.000 - 300.000

Jornada completa

Hace 2 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Consigue una respuesta de este empleador — un currículum y una carta de presentación adaptados exactamente a lo que busca para contratar.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Private Health Insurance
Pension Plan
Training & Development
Performance Bonus

Descripción de la vacante

Techconnect is seeking a senior privacy leader to drive enterprise data protection, ensuring compliance with UU PDP, GDPR, and ISO 27701 across all entities. You will author policies, govern DPAs, oversee DPIAs and risk assessments, and align privacy with security programs while coordinating with regulators and the C-suite.

You will guide privacy training, manage cross-border transfers, and shape the organization’s privacy culture with a focus on governance and accountability.

Formación

  • Bachelor's degree in Law or IT or related field and postgraduate qualification preferred.
  • 10+ years in Data Privacy/Cybersecurity/IT GRC with senior DPO or leadership.
  • Deep knowledge of Indonesian UU PDP and GDPR; experience implementing compliance at scale.
  • Ability to lead enterprise privacy programs including DPIAs, RoPAs, risk assessments, and incident response.
  • Proven experience advising Board/C-Suite and translating requirements into strategy.
  • Familiarity with ISO 27701, ISO 27001, NIST, COBIT, PCI-DSS.
  • Experience negotiating DPAs and cross-border transfers with regulators.
  • Executive communication and stakeholder management skills.
  • Certifications: CIPP/E, CIPM, FIP, CDPO; plus CISM, CISSP, ISO 27001/27701 LA is a plus.

Responsabilidades

  • Lead enterprise privacy strategy and governance across all entities.
  • Authorize data protection policies, privacy frameworks, DPAs and binding rules.
  • Implement Privacy by Design and Default across products and processes.
  • Coordinate with C-Suite and regulators to embed privacy culture.
  • Oversee DPIAs, RoPAs, and privacy risk assessments organization-wide.
  • Negotiate DPAs and cross-border transfer mechanisms with third parties.
  • Lead response to data subject rights requests and breaches, including regulatory notifications.
  • Engage regulators and act as primary contact for inquiries and audits.
  • Oversee privacy training programs for all staff and leadership.
  • Align privacy controls with ISMS and PIMS programs (ISO 27001/27701).
  • Develop privacy maturity models and benchmarks against best practices.
  • Assess AI, Cloud, IoT, and mobile tech privacy risks across the landscape.
  • Coordinate with SOC/CSIRT on breach detection and notification procedures.

Conocimientos

Privacy governance
DPIA leadership
Regulatory compliance
Stakeholder management
Board/C-Suite advisory
Cross-functional leadership
Indonesian UU PDP knowledge
Contract negotiations (DPAs)
Information security coordination
Privacy by Design & Default

Educación

Bachelor's degree in Law or IT or related field
Master's in Data Privacy or Information Security

Herramientas

GRC platforms
Regulatory reporting tools

Descripción del empleo

  • Lead the enterprise-wide data protection strategy, ensuring full compliance with UU PDP, GDPR, ISO 27701, and all applicable national and international privacy regulations.
  • Authorize data protection policies, privacy frameworks, data processing agreements, and binding corporate rules across all business entities and subsidiaries.
  • Strategize and oversee the implementation of Privacy by Design and Privacy by Default principles across all new products, systems, processes, and digital transformation initiatives.
  • Synergize with C-Suite, Board of Directors, Legal, IT, Compliance, and Business Units to embed privacy governance into organizational culture and decision-making.
  • Lead and manage Data Protection Impact Assessments (DPIAs), Records of Processing Activities (RoPAs), and privacy risk assessments across the organization.
  • Negotiate and authorize data sharing agreements, data processing agreements (DPAs), and cross-border data transfer mechanisms with third parties and regulatory bodies.
  • Strategize and lead the organization’s response to data subject rights requests (access, erasure, portability, objection) and personal data breach incidents, including regulatory notifications.
  • Lead engagement with regulators, including the National Data Protection Authority (Kominfo/BSSN), and serve as the primary point of contact for all regulatory inquiries and audits.
  • Authorize and oversee privacy training programs, awareness campaigns, and capability uplift initiatives for all staff levels, including senior leadership.
  • Synergize with the Cybersecurity and IT GRC functions to ensure alignment of information security controls with privacy obligations, including ISMS (ISO 27001) and PIMS (ISO 27701) programs.
  • Lead the development and continuous improvement of the organization’s privacy maturity model, benchmarking against global best practices and frameworks.
  • Strategize on emerging technology risks related to AI, Cloud, IoT, and Mobile, ensuring privacy considerations are proactively addressed across the technology landscape.
  • Lead the development and operationalization of a Data Security Framework covering data classification, Data Loss Prevention (DLP), encryption standards, and access governance in coordination with the CISO and Cybersecurity function.
  • Oversee and authorize cybersecurity-related privacy risk assessments including third-party vendor security reviews, cloud security assessments, and technology due diligence for data-intensive systems and digital platforms.
  • Lead coordination with the Security Operations Center (SOC) and CSIRT on personal data breach detection, containment, and regulatory notification procedures under UU PDP and applicable sectoral regulations (including BSSN directives).
  • Bachelor’s degree in Law, Information Technology, Computer Science, Cybersecurity, or a related field; Master’s degree or postgraduate qualification in Data Privacy, Information Security, or Law is highly preferred.
  • Minimum 10 years of progressive experience in Data Privacy, Cybersecurity, IT GRC, or a related discipline, with at least 2 years in a senior DPO, privacy advisory, or data governance leadership role.
  • Demonstrated expertise in Indonesian Personal Data Protection Law (UU PDP No. 27 Tahun 2022) and GDPR, with a proven track record of regulatory compliance implementation across large or complex organizations.
  • Strong capability to lead, design, and authorize enterprise privacy programs including DPIAs, RoPAs, privacy risk assessments, and incident response frameworks.
  • Proven ability to synergize with and advise at Board and C-Suite level, translating complex privacy and regulatory requirements into strategic business guidance.
  • In-depth knowledge of international privacy and security standards and frameworks including ISO 27701, ISO 27001, NIST Privacy Framework, NIST CSF, COBIT, and PCI-DSS.
  • Experience in negotiating data processing agreements, cross-border transfer mechanisms, and regulatory submissions with government authorities and regulators.
  • Broad understanding of cybersecurity domains including Cyber Strategy, Security Architecture, Cloud Security, DevSecOps, OT/ICS Security, and Emerging Technology Risks (AI, IoT, Mobile, Cloud).
  • Strong knowledge of IT Audit, IT Risk Management, IT Governance, Enterprise Architecture, Business Continuity Management (ISO 22301), and Digital Transformation.
  • Excellent executive communication, stakeholder management, and cross-functional leadership skills, with the ability to influence and drive change at all organizational levels.
  • Demonstrated experience in acting as an Independent or External Advisor to Boards, Audit Committees, or regulatory bodies is a strong advantage.
  • Professional certifications required: one or more of CIPP/E, CIPM, FIP, CDPO, or equivalent privacy credentials. Additional preferred certifications include CISM, CISSP, ISO 27001 LA, ISO 27701 LA, ISO 22301 LA, GRCP, GRCA, CCSK, or OT Privacy Expert.
  • Private Health Insurance
  • Pension Plan
  • Training & Development
  • Performance Bonus
Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

AVP-Head of Legal Commercial B2C
AVP-Head of Legal Commercial B2C

Indosat • Asia

Presencial
PEN 285.000 - 570.000
Associate Security Operations Analyst Durianpay Hybrid • Jakarta Min. Fresh Grad Negotiable Actively hiring 2d ago
Associate Security Operations Analyst Durianpay Hybrid • Jakarta Min. Fresh Grad Negotiable Actively hiring 2d ago

Durianpay • Asia

Presencial
PEN 24.000 - 36.000
M - IT Audit
M - IT Audit

Prudential Hong Kong Limited • Asia

Presencial
PEN 86.000 - 143.000
[LI] Head of Communications
[LI] Head of Communications

Dana Indonesia • Asia

Presencial
PEN 171.000 - 285.000
Sr Officer-Legal Business Enablement
Sr Officer-Legal Business Enablement

Indosat • Asia

Presencial
PEN 34.000 - 57.000
MDM Operations Team Lead
MDM Operations Team Lead

Fitch Group • Asia

Híbrido
PEN 114.000 - 171.000
Hybrid Work Environment: 3 days a week
A Culture of Learning & Mobility: Ment
Investing in Your Future: Retirement &
+4
Manager – Technology Policy and Innovation
Manager – Technology Policy and Innovation

MicroSave • Asia

Presencial
PEN 302.000 - 504.000
Travel opportunities
Professional development
IT Security
IT Security

Doku • Asia

Presencial
PEN 120.000 - 180.000
FY27 - Intern - Team Assistant/Secretary
FY27 - Intern - Team Assistant/Secretary

PwC International • Asia

Presencial
PEN 3200 - 5300
Compensation & Benefit Administration Lead
Compensation & Benefit Administration Lead

UOB • Asia

Híbrido
PEN 171.000 - 285.000