An experienced AI, Data Governance & Privacy Officer is needed by a United Arab Emirates (UAE) firm to oversee corporate governance in the areas of artificial intelligence, data governance, privacy, and responsible AI. and digital risk.
The successful candidate will establish practical governance frameworks supporting regulatory compliance, privacy, information security, ethical AI, risk management, and responsible digital innovation.
The role will work with business, technology, risk, compliance, legal, cybersecurity, and data teams to govern Generative AI (GenAI), Agentic AI, machine learning, advanced analytics, intelligent automation, cloud platforms, enterprise data platforms, and AI-enabled applications.
Experience in insurance, banking, financial services, healthcare, government, or other regulated industries is preferred.
Develop and maintain an enterprise-wide AI governance framework covering policies, standards, controls, procedures, and approvals.
Establish governance requirements for Generative AI, Agentic AI, machine learning, predictive analytics, intelligent automation, and AI applications.
Establish AI use-case intake, assessment, classification, approval, and monitoring processes.
Support AI risk assessments throughout the lifecycle from development and procurement through deployment, monitoring, and retirement.
Establish controls covering transparency, explainability, fairness, bias, human oversight, accountability, prompt governance, security, monitoring, and auditability.
Maintain an enterprise AI inventory/register with appropriate risk classification.
Support responsible AI adoption while balancing innovation, business value, and risk.
Establish standards for data ownership, stewardship, quality, classification, retention, metadata, lineage, access, and lifecycle management.
Support data cataloguing, inventory, metadata management, and data quality initiatives.
Establish governance for data lakes, data warehouses, analytics platforms, cloud environments, GenAI platforms, and enterprise data ecosystems.
Promote governance of structured and unstructured data and establish data accountability across business and technology functions.
Lead privacy governance and support Data Protection Officer (DPO) responsibilities where applicable.
Maintain frameworks aligned with applicable regulations, including UAE PDPL, and where applicable, DIFC Data Protection Law, ADGM data protection requirements, GDPR, and other relevant regulations.
Conduct or oversee Data Protection Impact Assessments (DPIAs) and privacy risk assessments for technologies, products, processes, and AI use cases.
Support data subject rights, consent management, records of processing activities, privacy notices, and data protection documentation.
Assess cross-border data transfers, data residency, international data flows, and third-party processing.
Support privacy incidents and personal data breach governance, investigation, notification, and remediation.
Establish AI and model risk management standards based on system risk, business impact, data sensitivity, and regulatory requirements.
Maintain the AI inventory and coordinate periodic AI risk assessments and governance reviews.
Develop controls for model validation, performance monitoring, drift detection, explainability, robustness, human oversight, and documentation.
Monitor developments affecting AI, data, privacy, cybersecurity, and digital technologies.
Support audits, regulatory reviews, compliance assessments, reporting, and remediation.
Align governance, where appropriate, with ISO/IEC 42001, ISO/IEC 27001, ISO/IEC 27701, NIST AI Risk Management Framework, and relevant industry standards.
Define governance requirements for AI vendors, cloud providers, data processors, SaaS platforms, technology partners, and third-party AI solutions.
Conduct or coordinate assessments covering privacy, data protection, AI risk, security, compliance, data usage, and ethics.
Review data-sharing arrangements, processing agreements, AI vendor contracts, and technology procurement requirements.
Establish controls for third-party LLMs, foundation models, GenAI platforms, APIs, and AI service providers.
Develop training covering responsible AI, data governance, privacy, data protection, and information handling.
Conduct governance workshops and executive awareness sessions.
Develop KPIs, KRIs, governance dashboards, management reports, and executive reporting.
Promote data accountability, privacy, responsible AI, and risk-aware innovation.
Bachelor’s degree in Computer Science, Information Systems, Data Science, Cybersecurity, Law, or related discipline.
Master’s degree or relevant postgraduate qualification preferred.
10–15 years of experience in data governance, privacy, technology governance, information management, risk, compliance, or related areas.
At least 5 years leading enterprise governance programs or initiatives.
Practical understanding of AI/ML, Generative AI, cloud platforms, enterprise data environments, and emerging technologies.
Regulated-industry experience is an advantage.
Strong understanding of privacy regulations, AI governance, AI risk management, data protection, information governance, and enterprise controls.
Working knowledge of ISO 42001, ISO 27001, ISO 27701, NIST AI RMF, or equivalent frameworks preferred.
Experience with DPIAs, AI risk assessments, data classification, data/AI inventories, third-party assessments, and governance documentation.
Excellent communication, stakeholder management, analytical, policy-development, and executive engagement skills GCC jobs.
Ability to translate complex regulatory, technical, privacy, and AI requirements into practical enterprise policies and controls.
The ideal candidate is a strategic and hands-on AI governance, data governance, and privacy professional who can translate complex regulatory, technical, privacy, data, and AI requirements into practical enterprise controls.
The candidate should be comfortable working with senior executives, business leaders, technology, data, cybersecurity, legal, risk and compliance teams, auditors, regulators, and external technology partners.
The successful candidate will combine governance and regulatory knowledge with practical understanding of AI, data, privacy, cloud, and emerging technologies, supporting responsible innovation while maintaining appropriate risk and compliance controls.
