📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

وظيفة مستشار خصوصية بيانات شاغرة لدى Acuative Middle East في جدة

Data Privacy Consultant
🕒 نُشرت: (منذ 4 أيام) 📍 جدة وظائف الهندسة والتقنية

تفاصيل الوظيفة

تعلن شركة Acuative Middle East عن توفر وظيفة استشاري أول لخصوصية البيانات (Senior Data Privacy Consultant) في مكة وجدة، السعودية. ستعمل ضمن فريق حماية البيانات الشخصية في جامعة بحثية رائدة في المملكة.

نبذة عن الوظيفة

سيكون هذا الدور عمليًا وليس استشاريًا فقط، حيث ستقوم بتشغيل برنامج الخصوصية اليومي وتعزيز الامتثال للوائح حماية البيانات الشخصية السعودية (PDPL) وتنظيمات SDAIA. ستسهل ورش العمل مع الوحدات، وتدير التقييمات، وتتعامل مع الحوادث، وتدرب أبطال الخصوصية الداخليين لتمكين المنظمة من الاعتماد على الذات.

المهام والمسؤوليات

  • إعداد سجلات أنشطة المعالجة (RoPAs): تحديد الوحدات والأنشطة غير المغطاة وبناؤها عبر ورش عمل مع الجهات المعنية، والتحقق من السجلات الحالية وتحديثها، والحصول على موافقة رؤساء الوحدات ومسؤول حماية البيانات.
  • إجراء تقييمات أثر حماية البيانات (DPIAs): تطوير منهجية لفحص الأنشطة وتحديد عالية المخاطر، وتنفيذ التقييمات، وتحديد المخاطر والضوابط، وتسجيلها في منصة GRC ومتابعة الإغلاق.
  • إدارة مخاطر الخصوصية للجهات الخارجية: تصنيف معالجي البيانات حسب المخاطر، وتقييم المعالجين ذوي المخاطر العالية، وتنسيق الإجراءات التصحيحية مع المشتريات والوحدات، ومراجعة الضوابط في اتفاقيات معالجة البيانات واتفاقيات التعاقد النموذجية السعودية.
  • إدارة خروقات البيانات: دعم مسؤول حماية البيانات في الحوادث من البداية إلى النهاية (الاحتواء، تحليل السبب الجذري، التخفيف)، والتنسيق مع فرق الاستجابة للحوادث السيبرانية والشؤون القانونية والاتصالات والموارد البشرية، ودعم الإخطارات التنظيمية والرد على استفسارات SDAIA.
  • تطبيق نموذج المحور والمركز (Hub and Spoke): تنظيم ورش عمل لتعيين أبطال خصوصية في الوحدات، وتحديد دورهم ومسؤولياتهم، وتدريبهم فرديًا، وإدارة تسليم الأنشطة مع دعم لمدة ثلاثة أشهر.
  • إدارة طلبات حقوق أصحاب البيانات (DSR): معالجة الطلبات من الاستلام إلى الإغلاق، وتحديد الاختناقات في سير العمل وتحسينها.
  • تقليل البيانات ومراجعة إشعارات الخصوصية وفترات الاحتفاظ: إجراء مراجعات لتقليل البيانات في نماذج الاستلام والمقترحات، وتحديث إشعارات الخصوصية بناءً على نتائج RoPA وDPIA، ومراجعة جداول الاحتفاظ مقابل متطلبات PDPL ودعم وضع فترات احتفاظ متوافقة وإجراءات حذف تقنية.
  • التدريب على الخصوصية: تطوير وتقديم تدريبات متخصصة داخل الموقع للوحدات، وبناء وحدات تدريب إلكترونية.
  • مهام أخرى تدعمها وظيفة حماية البيانات ومسؤول حماية البيانات حسب الطلب.

الشروط والمتطلبات

  • خبرة لا تقل عن 6 سنوات في مجال خصوصية البيانات أو حمايتها أو إدارة المخاطر والامتثال (GRC)، منها سنتان على الأقل في أعمال خصوصية عملية (وليست سياسية أو استشارية بحتة).
  • معرفة متعمقة بلائحة حماية البيانات الشخصية السعودية (PDPL) ولائحتها التنفيذية ولائحة نقل البيانات وتوجيهات SDAIA، مع تفضيل الإلمام باللائحة العامة لحماية البيانات (GDPR).
  • خبرة مثبتة في بناء وصيانة RoPAs، وإجراء DPIAs، وإدارة تقييمات مخاطر الخصوصية للجهات الخارجية.
  • خبرة في إدارة خروقات البيانات الشخصية بما في ذلك الإخطار التنظيمي.
  • خبرة في التعامل مع طلبات حقوق أصحاب البيانات والحفاظ على سجل DSR.
  • مهارات قوية في تسهيل ورش العمل وإدارة العلاقات مع فرق الأعمال والشؤون القانونية وتقنية المعلومات والأمن والمشتريات.
  • القدرة على صياغة وثائق امتثال واضحة مثل اتفاقيات معالجة البيانات والاتفاقيات التعاقدية النموذجية وإشعارات الخصوصية وجداول الاحتفاظ وتعريفات الأدوار والمواد التدريبية.
  • إتقان اللغة الإنجليزية كتابةً وتحدثًا.
  • الاستعداد للعمل في الموقع بدوام كامل في ثول، المملكة العربية السعودية.

المهارات المطلوبة

  • شهادة CIPP/E أو CIPM أو CIPT أو شهادة خصوصية معادلة.
  • خبرة في استخدام منصات GRC مثل ServiceNow GRC أو OneTrust أو Archer لتسجيل المخاطر وتتبعها.
  • خبرة سابقة في مؤسسات التعليم العالي أو البحثية أو بيئات تتعامل مع بيانات أبحاث الأشخاص.
  • إتقان اللغة العربية.
  • خبرة في أطر أمن المعلومات مثل ISO 27001 وNCA ECC، ومراجعة الضوابط الأمنية التقنية في عقود البائعين.
عرض النص الأصلي للإعلان

About the role:


Acuative is hiring a Senior Data Privacy Consultant to be embedded within the Personal Data Protection (PDP) function of a leading research university in Saudi Arabia. You will act as a hands-on extension of the DPO's team, running the day-to-day privacy operations program and strengthening the organization's compliance posture under the Saudi Personal Data Protection Law (PDPL) and SDAIA regulations.

This is an operational role, not an advisory-only role. You will facilitate workshops with business units, populate and validate compliance artifacts, run assessments, manage incidents, and coach internal privacy champions so the organization becomes self-sufficient over time.


What you will do:


Records of Processing Activities (RoPAs)

  • Identify business units and processing activities without RoPAs and build them through stakeholder workshops.
  • Validate and update existing RoPAs with process owners, and secure sign-off from BU Heads and the DPO.

Data Protection Impact Assessments (DPIAs)

  • Develop or apply a process gating methodology to screen all processing activities and flag high-risk ones.
  • Conduct DPIAs on high-risk activities, identify privacy risks and controls, assign risk and control owners, and obtain sign-off.
  • Record all identified risks in the GRC platform and track them to closure.

Third-Party Privacy Risk Management

  • Identify data processors not yet subject to due diligence and build a High/Medium/Low risk tiering methodology.
  • Assess high-risk processors, prescribe corrective actions and timelines, and coordinate with Procurement and the relevant BUs.
  • Review vendor security controls in Data Processing Agreements (DPAs), perform transfer risk assessments, and embed required controls into DPAs and KSA Standard Contractual Clauses.
  • Develop template security controls by contract type with Information Security, and update guidance for researchers on securing human subject research data.

Data Breach Management

  • Support the DPO on privacy incidents end to end: containment, root cause analysis, mitigation, and coordination with Cyber Incident Response, Legal, Communications, and HR.
  • Support regulatory breach notifications and responses to SDAIA inquiries.

Privacy Hub and Spoke Model

  • Run workshops with BU Heads to appoint Privacy Champions across the organization.
  • Define the Privacy Champion role (responsibilities, expectations) and secure management sign-off.
  • Deliver 1-1 training to champions and manage a structured handover of privacy activities, with three months of SME support post-transition.

Data Subject Rights (DSR)

  • Handle DSR requests end to end: intake, register logging, validation, internal coordination, response, and closure.
  • Identify and fix process bottlenecks in the DSR workflow.

Data Minimization, Privacy Notices, and Retention

  • Conduct data minimization reviews on intake forms, data sharing proposals, transfer risk assessments, and DPIAs.
  • Review and update privacy notices based on RoPA and DPIA findings, changes in lawful basis, consent management, and legitimate interest procedures; draft new notices where needed.
  • Review retention schedules against PDPL requirements and support process owners and technical stewards in setting compliant retention periods and technical SOPs for deletion.

Privacy Training

  • Develop and deliver specialized on-site privacy training for units and build online training modules.

Ad-hoc Support

  • Any other privacy tasks requested by the PDP function and the DPO.


What we are looking for:


Required:

  • 6+ years in data privacy, data protection, or GRC roles, with at least 2 years of hands-on operational privacy work (not purely policy or advisory).
  • Deep working knowledge of the Saudi PDPL, its Implementing Regulations, the Data Transfer Regulations, and SDAIA guidance. Familiarity with GDPR is a strong plus.
  • Proven experience building and maintaining RoPAs, conducting DPIAs, and running third-party privacy risk assessments.
  • Experience managing personal data breaches, including regulatory notification.
  • Experience handling Data Subject Rights requests and maintaining a DSR register.
  • Strong workshop facilitation and stakeholder management skills across business, legal, IT, security, and procurement teams.
  • Ability to draft clear compliance documentation: DPAs, SCCs, privacy notices, retention schedules, role definitions, and training material.
  • Fluent English, written and spoken.
  • Willingness to work on-site full-time in Thuwal, KSA.


Preferred:


  • CIPP/E, CIPM, CIPT, or equivalent privacy certification.
  • Experience with GRC platforms (e.g., ServiceNow GRC, OneTrust, Archer) for risk logging and tracking.
  • Background in higher education, research institutions, or other environments handling human subject research data.
  • Arabic language proficiency.
  • Experience with information security frameworks (ISO 27001, NCA ECC) and reviewing technical security controls in vendor contracts.


المصدر: LinkedIn - أُضيفت للموقع في 6 سبتمبر 2026
رقم الإعلان لدى المصدر: 4461812936