AL AHLI BANK OF KUWAIT logo

Expert Data Privacy and Security

AL AHLI BANK OF KUWAIT
2 hours ago
Full-time
On-site
Al Asimah, Al Asimah, Kuwait
Specialists & SMEs

Reports To

Head of Information Security

Job Purpose

Oversees the development and implementation of privacy policies, conducts audits and assessments to identify and mitigate risks, educate and train employees on data protection, serves as a point of contact for individuals regarding their personal data and play a crucial role in incident response, particularly in the event of data breaches.

Generic Accountabilities

2. Corporate Governance and Compliance Work fully within risk policies and procedures and compliance regulations and ensure all divisional activities comply with corporate governance & regulatory/legal frameworks
2. Policy & Processes Define ABK and divisional policies, processes and structures.
3. Risk management Identify, manage, mitigate and report on risk and potential risk in divisional activities
Compliance: Work fully within ABK’s Compliance regulations and standards.
5. People Management Manage people in line with people policies and best practices.

Specific Accountabilities

•    Policy Development: Develop, implement, and update privacy policies and procedures to ensure the organization's activities align with data privacy and security principles and legal requirements.
•    Audits and Assessments: Conduct regular data protection audits and privacy impact assessments to identify and address potential risks associated with the processing of personal data.
•    Education and Training: Provide education and training to employees on data protection policies, procedures, and best practices to foster a culture of awareness and adherence to data privacy best practice within the organization.
•    Point of Contact for Data Subjects: Serve as the primary contact point for individuals (data subjects) regarding their personal data, responding to inquiries and facilitating the exercise of data subject rights as outlined in relevant data protection laws.
•    Monitoring and Reporting: Monitor the organization's data protection adherence, report regularly to senior management on key metrics and areas of concern, and act as a liaison with data protection authorities when necessary.
•    Incident Response: Lead the organization's response to data breaches or other data protection incidents, coordinating efforts to investigate, contain, and remedy the situation while ensuring timely and accurate notifications to affected parties and regulatory authorities.
•    Legal Adherence: Ensure the organization's adherence to data protection laws and regulations, including staying informed about changes in legislation and advising the organization on necessary adjustments to maintain adherence to regulatory requirements regarding data privacy and security.
•    Independence and Impartiality: Operate independently within the organization, free from conflicts of interest, to ensure impartiality in carrying out data protection duties and responsibilities.
•    Data Governance: Contribute to the establishment and maintenance of effective data governance practices, ensuring that data protection considerations are integrated into various processes and activities.
•    Continuous Improvement: Stay abreast of industry best practices, technological developments, and changes in data protection regulations to recommend and implement continuous improvement measures in the organization's data protection program
 

Job Success Factors

Education

Bachelor's Degree or Equivalent Certification/Experience in Information Sciences and Technology or Computer Science

Experience

•    7 years of experience in data privacy, data governance, risk management or related roles.
•    Strong knowledge of data privacy frameworks, standards, and best practices (e.g., GDPR, ISO 27701 etc.).
•    Expertise in data protection laws and practices, including deep understanding of GDPR and local regulations. 

•    Professional certifications such as Certified Information Privacy Manager (CIPM), Certified Information Privacy Professional (CIPP-E), ISO 27701 Lead Implementer, Certified in Risk and Information Systems Control (CRISC) is preferred.

Skills

•    Ability to work effectively under pressure and to manage sensitive and confidential information.
•    Excellent verbal and written communication skills, with strong attention to detail.
•    Excellent analytical and problem-solving skills.
•    Leadership and Strong project management skills.
 

Work Contact

Internal: All Division    
External:Vendors & IT Consultants

Interview Questions

JD Code

RMD 24.07