Head of Data Privacy and Protection

Envision Employment SolutionsCairogulftalentpublicada em 14/09/2026
Obrigatório:CloudAgileFinTechSecurityHybrid

The role

There's no privacy program to inherit here, no policy manual to update. You design it, from the framework and classification standards down to how a single customer's data-subject request gets resolved. You act as the bank's DPO and its subject matter expert on privacy, and you're the one who makes sure innovation never outruns what the law, the regulator, or a customer's trust actually allows.

What you'll do

Design and implement a comprehensive data privacy framework, privacy policies, and data classification standards completely from scratch

Direct all compliance initiatives mapped to applicable laws, regulations, and standards, coordinating closely with regulatory authorities and acting as the primary subject matter expert on privacy mandates, serving as Data Protection Officer (DPO)

Institute and manage the Privacy Impact Assessment (PIA) lifecycle, embedding privacy-by-design and privacy-by-default principles directly into agile product development, analytics pipelines, and new feature launches

Build scalable workflows to manage Data Subject Access Requests (DSARs), consent management, opt-out mechanisms, and data rectification inquiries

Drive the implementation and integration of core data protection technologies, including Data Loss Prevention (DLP), Database Activity Monitoring (DAM), encryption key management, and data masking tools, to secure sensitive financial data across cloud and hybrid environments

Architect and scale enterprise-wide data discovery, tagging, and automated classification programs to ensure continuous visibility and contextual tracking of sensitive customer PII and banking assets

Oversee cross-border data transfer mechanisms, cloud data residency requirements, and contractual data processing agreements (DPAs) in coordination with legal and infosec teams

Collaborate with the CISO and Incident Response teams to manage privacy-related security incidents, regulatory breach notifications, and data leakage remediations

What we're looking for

10+ years of cumulative professional experience, including 4 to 5 years in a dedicated data privacy, data protection, or regulatory compliance leadership role within banking, financial services, or privacy-mature tech sectors

Deep familiarity with CBE regulations, applicable laws, and general cross-border privacy frameworks such as GDPR

Strong understanding of data classification tools (e.g., Microsoft Purview), data masking, encryption standards, and secure data storage architectures

Recognized privacy credentials such as CDPO, CISM, or CISA are strongly preferred

A proactive, builder mindset, able to balance rigorous legal and privacy controls with the fast-paced, data-driven innovation needs of a modern digital bank

Outstanding stakeholder management skills, with the ability to translate complex legal and regulatory requirements into clear, actionable guidance for engineering, product, and executive teams

You’ll thrive here if you

You'd rather design the framework than inherit a policy nobody's updated in years

You treat a DSAR or consent request as a promise to the customer, not paperwork to process

You can turn a dense regulatory requirement into something an engineer can actually build against

You see privacy-by-design as a discipline embedded from day one, not a review bolted on before launch

You want to build the function that keeps innovation and trust moving at the same speed