Data Protection Officer - FinTech
Nutné:CloudCI/CDAIFinTechSecurityLead
The Data Protection Officer will oversee and manage all aspects of data protection compliance and data privacy across the organisation.
Client Details
A growing firm in the Middle East.
Description
- Build and operate the privacy and data governance programme, including its policies, standards, procedures, controls and operating cadence.
- Own data mapping and Records of Processing Activities across cloud services, data platforms and AI/ML workflows.
- Lead Data Protection Impact Assessments and data related risk assessments for products and AI use cases.
- Work directly with Tech and Information Security teams to embed privacy-by-design within technology architecture, SDLC/CI-CD and the data lifecycle.
- Implement practical controls covering data minimisation, access, logging, classification, retention, deletion and transparency.
- Establish and manage data subject rights operations, including identity verification, fulfilment, audit trails and service levels.
- Support privacy incident response and breach notification activities alongside Information Security, Legal and Operations.
- Manage privacy controls for technology vendors, cloud providers and AI partners, including due diligence and ongoing monitoring.
- Maintain programme metrics and evidence to support audits, regulatory readiness, security questionnaires and institutional-client due diligence.
Job Offer
- A permanent, hands on role with responsibility for building the data protection and privacy control environment.
- Direct involvement with leadership
- At least 7 years' experience in data protection, technical privacy, information security or data governance within a technology led or Fintech environment.
- An IT, cybersecurity, information security or technical data governance background is essential.
- Hands-on experience designing and operating privacy and data protection controls across cloud services, applications, APIs or data platforms.
- Experience delivering data mapping, RoPA, DPIAs, data subject rights processes, data classification, retention controls and privacy incident support.
- Demonstrable experience working directly implementing controls.
- Practical experience of privacy-by-design within cloud-native architectures and software or product development processes.
- Tangible experience addressing data protection and governance risks associated with AI/ML workflows, AI-enabled products or third-party AI services.
- Experience in fintech, financial services, payments or another regulated or high-trust environment is preferred.
- Privacy qualifications such as CIPP/E, CIPP/US or CIPM are advantageous but will not replace the required technical background.