LEXAUPDATES
PostAdvertiseAboutContact
jobsPosted 19 days ago

Data Protection Officer - Internal Audit at Al Khayyat Investments (AKI)

A

Al Khayyat Investments (AKI)

📅Primary

last date

Open Access

📍

Location/Place/Mode

Dubai, United Arab Emirates

🔖

Eligibility

Bachelor's degree in Information Technology, Computer Science, Information Security, or a related field; 2–3 years of experience in IT internal audit, information security audit, technology compliance, or consulting; hands-on audit experience; knowledge of ISO 27001, COBIT, NIST CSF, UAE PDPL, ADHICS, KSA PDPL/SDAIA, Oman PDPL, GDPR, ISO/IEC 27701, or NIST Privacy Framework; experience with enterprise systems such as SAP, Oracle, Microsoft Dynamics, cloud platforms, or SaaS applications; strong report-writing, communication, and stakeholder management skills. Preferred: CIA, CISA, ISO 27701 Lead Implementer/Auditor, or equivalent; experience in a large, diversified, or multi-entity organisation; familiarity with GRC platforms and AI governance concepts.

Opportunity

In the heart of the Gulf's booming commercial hub, Al Khayyat Investments (AKI) is setting a new benchmark for corporate governance with a rare and highly consequential opening: a Data Protection Officer - Internal Audit based in Dubai. For professionals at the intersection of privacy law, IT risk, and forensic auditing, this is not merely a job posting—it is a strategic invitation to shape how a diversified conglomerate protects its most valuable digital assets. As the UAE tightens its data protection regime and companies across the region scramble for compliance, the role of a Data Protection Officer (DPO) has morphed from a back-office checkbox into a critical, board-level function. This comprehensive guide unpacks the opportunity, the ideal candidate, and the career-transforming potential of joining the AKI universe.

The Privacy Boom in the Gulf: Why This Role Is a Career Catalyst

The United Arab Emirates has become a laboratory for data regulation. With the enactment of the UAE Personal Data Protection Law (PDPL) and sectoral frameworks like ADHICS for healthcare, organisations are under unprecedented pressure to demonstrate accountability. Meanwhile, Saudi Arabia's PDPL and Oman's new data protection law extend the compliance net across the region. For a conglomerate like AKI—with diverse interests spanning retail, automotive, healthcare, and real estate—the complexity multiplies. This is precisely why the DPO role has evolved into a hybrid position that requires both technical audit acumen and deep privacy governance expertise.

“Data protection is no longer an IT issue; it is a corporate survival strategy. The professional who can bridge the gap between internal audit and privacy compliance will define the next decade of risk management in the Gulf.” — Senior Compliance Recruiter, Dubai

AKI's decision to embed the Data Protection Officer within the Internal Audit function signals something important: they are treating privacy as a risk to be audited, measured, and continuously improved, rather than a policy paper to be filed away. For the right candidate, this means unparalleled exposure to the full lifecycle of enterprise data systems, from cloud platforms to e-commerce engines.

Decoding the AKI Role: More Than Just Compliance

Let's dissect the responsibilities listed in the posting. The DPO at AKI will lead data protection and privacy activities across group operations and support functions. This is a mandate that touches every part of the business. You will not be sitting in a corner performing privacy impact assessments all day—you will be embedded in internal audit teams, scrutinising IT general controls, information security protocols, and cyber defence mechanisms.

  • Conducting risk assessments, DPIAs, and transfer impact assessments to ensure every new process or vendor relationship is vetted for privacy risk.
  • Maintaining the privacy risk register, a living document that senior leadership relies on for data-driven decisions.
  • Auditing ERP, CRM, HR, e-commerce, and SaaS platforms to verify that data processing aligns with contractual and regulatory obligations.
  • Managing data breach response, from forensic investigation to regulatory notification—a high-stakes competency in the age of swift enforcement.
  • Delivering training and awareness programs that transform employees from a liability into a first line of defence.

What distinguishes this position is the dual demand for audit rigour and privacy fluency. You are not just ticking boxes on a compliance checklist; you are providing assurance to the board that the group's data assets are handled with the same discipline as its financial ones.

The Blueprint of a Perfect Candidate

If you are reading this and wondering whether you qualify, the posting offers a clear, though demanding, blueprint. The minimum bar is a Bachelor's degree in Information Technology, Computer Science, Information Security, or a related field. But the non-negotiables go further: you need two to three years of hands-on experience in IT internal audit, information security audit, technology compliance, or consulting. This is not a role for a newly minted graduate; it is for someone who has already cut their teeth in the trenches of control testing and risk assessment.

The knowledge requirements read like a checklist for modern compliance professionals: familiarity with ISO 27001, COBIT, NIST CSF, UAE PDPL, ADHICS, KSA PDPL/SDAIA, Oman PDPL, GDPR, ISO/IEC 27701, or NIST Privacy Framework. If you have worked with enterprise systems such as SAP, Oracle, Microsoft Dynamics, or cloud platforms, you already understand the architecture that stores personal data. Strong report writing and stakeholder management skills are also mandatory, because your findings will be presented to audit committees and C-suite executives.

Preferred Qualifications That Make You Stand Out

While the essential requirements are enough to apply, the “preferred” qualifications offer a crystal-ball vision of what AKI truly wants. Professional certifications like CIA, CISA, or ISO 27701 Lead Implementer/Auditor are more than letters after your name—they are proof that you understand the standards in their practical, auditable form. Experience in a large, diversified, multi-entity organisation is a huge plus, as is familiarity with GRC platforms and AI governance concepts. The mention of AI governance is particularly forward-looking; it shows that AKI is already thinking about the privacy implications of artificial intelligence.

Career Benefits: Beyond a Paycheck

Let's talk about why this opportunity is a golden ticket for your professional trajectory. First, the cross-industry exposure is unmatched. AKI operates in sectors as varied as automotive distribution and healthcare, meaning you will grapple with different data landscapes, each with its own regulatory nuances. Second, the internal audit seat gives you visibility into the entire group's risk architecture, not just the privacy silo. Third, Dubai's status as a global business gateway means your network will expand to include top-tier consultants, regulators, and technology vendors.

Moreover, the role sits at the intersection of two of the hottest career tracks in the decade: privacy and technology audit. Professionals who can demonstrate competence in both are scarce, and executive search firms are actively poaching them. After two or three years as a DPO in a group like AKI, you could step into a Chief Information Security Officer, Head of Compliance, or Group Risk Director position. The move is not just a lateral step; it is a strategic leap.

How to Position Yourself for Success

If this opportunity resonates, your application strategy needs to be as disciplined as the audit work. Start by tailoring your CV to bridge the language of IT audit and privacy. Highlight specific engagements where you assessed IT general controls, supported DPIA processes, or responded to a data breach. Show that you understand the regulatory landscape by naming the frameworks you have applied in practice. If you lack a certification, consider starting a online course on ISO 27701 or CISA to demonstrate ambition.

Networking is another critical lever. Connect with current or former AKI employees on LinkedIn, reach out to the internal audit leadership, and ask informed questions about the group's data governance journey. A recommendation can double your chances. Finally, prepare for an interview that will likely combine technical case studies with behavioural questions. Be ready to explain how you would audit a SaaS vendor's data processing, or what steps you would take to notify the regulator of a personal data breach under the UAE PDPL.

Frequently Asked Questions

What does a Data Protection Officer do in an internal audit context?

In an internal audit context, a DPO goes beyond policy-making and operational compliance. They evaluate the effectiveness of data protection controls as part of assurance activities, incorporating privacy risks into the internal audit plan. They assess data flows, perform audit tests on access controls, encryption, and data minimisation, and advise the board on whether the organisation is meeting regulatory expectations like the UAE PDPL.

Is a legal background necessary to apply for this DPO role at AKI?

No, this specific posting is heavily weighted toward IT and audit expertise. The requirements emphasise a Bachelor's degree in IT, Computer Science, or Information Security, and hands-on audit experience. Legal knowledge is helpful but not mandatory; the focus is on technical implementation and assurance.

How soon should I apply, and what is the deadline?

The posting highlights a job that was published "two days ago" and had already attracted more than 200 applicants, signalling the urgency and competitiveness of the role. However, no explicit application deadline is provided. In such situations, it is prudent to apply immediately, as LinkedIn job postings can close at any time once the pipeline is full.

Can candidates from non-audit backgrounds apply if they are strong on privacy?

While it is possible, the employer has stressed that "hands-on audit experience is essential." Candidates from a privacy pure-play background without exposure to IT general controls or audit methodology would likely find the interview challenging. That said, if you have relevant transferable skills—such as cybersecurity consulting with audit components—you could make a compelling case.

Advertisement
Ad slot — configure in AdSense

More Legal Job Opportunities

jobs

Fund Legal – Assistant Vice President

State Street

📅 Open

View Details →
jobs

Legal Counsel / Senior - Real Estate Investments

SD Legal

📅 Open

View Details →
jobs

Legal Counsel – Calvin James Recruitment (Abu Dhabi, UAE)

Calvin James Recruitment

📅 Open

View Details →
jobs

Senior Legal Counsel - Digital Banking

SD Legal

📅 Open

View Details →
Advertisement
Ad slot — configure in AdSense