Officer – Internal Audit

August 1, 2026

Job Description

Data Protection Officer – Internal Audit

Al Khayyat Investments is looking for a Data Protection Officer to lead data protection and privacy activities across the Group.

This role is suitable for a technically strong professional with experience in IT audit, information security, technology compliance, data protection, and privacy governance.

Key Responsibilities

  • Lead data protection and privacy activities across group operations and support functions.
  • Ensure alignment with data protection policies, data classification standards, and applicable regulations.
  • Support data governance activities, including data classification, labelling, and Records of Processing Activities.
  • Conduct risk assessments, DPIAs, transfer impact assessments, and maintain the privacy risk register.
  • Perform audits covering IT General Controls, information security, cyber security, data processing activities, systems, vendors, and third parties.
  • Review vendor arrangements, data processing agreements, and privacy due diligence requirements.
  • Support personal data breach response, including investigation, impact assessment, and regulatory notification.
  • Deliver data protection awareness and training across the organisation.
  • Work closely with Internal Audit, IT, and business teams to assess controls across ERP, CRM, HR, e-commerce, SaaS platforms, and emerging technologies.

Requirements

  • Bachelor’s degree in Information Technology, Computer Science, Information Security, or a related field.
  • 2–3 years of experience in IT internal audit, information security audit, technology compliance, or consulting.
  • Hands-on audit experience is essential.
  • Knowledge of ISO 27001, COBIT, NIST CSF, UAE PDPL, ADHICS, KSA PDPL/SDAIA, Oman PDPL, GDPR, ISO/IEC 27701, or NIST Privacy Framework.
  • Experience with enterprise systems such as SAP, Oracle, Microsoft Dynamics, cloud platforms, or SaaS applications.
  • Strong report-writing, communication, and stakeholder management skills.

Preferred

  • CIA, CISA, ISO 27701 Lead Implementer/Auditor, or equivalent certification.
  • Experience in a large, diversified, or multi-entity organisation.
  • Familiarity with GRC platforms and AI governance concepts.