Data Governance Privacy &GRC Consultant
Command Post QFZ LLC · Doha, Qatar
قدّم وتابع مع أبلاي إيدجData Governance, Privacy & GRC ConsultantLocation: Doha, Qatar or Dubai, UAE Employment Type: Full-time (On-site / Client Site) Company: Command PostAbout Command PostCommand Post is a leading cybersecurity, AI assurance, governance, risk, compliance (GRC), privacy, and data governance consulting and technology company serving organizations across the Middle East.As part of our continued growth, we are expanding our Data Governance and GRC practice and are looking for experienced professionals to join our team in Qatar and the UAE.Open PositionsWe are hiring across multiple experience levels, including:Data Governance LeadSenior Data Governance ConsultantData Governance ConsultantGRC / Compliance LeadPrivacy ConsultantData Governance AnalystData StewardRole OverviewThe successful candidate will support the design, implementation, and continuous improvement of enterprise governance, privacy, compliance, and risk management programs. You will work closely with business and technical stakeholders to establish governance frameworks, improve data quality, ensure regulatory compliance, and strengthen organizational controls.Key ResponsibilitiesData GovernanceDesign and implement enterprise data governance frameworks.Establish governance structures, decision rights, roles, and responsibilities.Define Data Owner, Data Steward, and Data Custodian operating models.Develop governance policies, standards, procedures, and operating models.Build and maintain business glossaries, metadata repositories, data dictionaries, and data catalogues.Define data quality rules, KPIs, ownership, and issue management processes.Conduct data governance maturity assessments and develop improvement roadmaps.Facilitate workshops with business and technology stakeholders.Support Data Governance Councils and governance working groups.Develop governance dashboards, KPIs, and executive reports.Data Lineage & Data Flow ManagementDocument end-to-end data flows across applications, databases, interfaces, and third-party platforms.Develop enterprise data lineage models.Identify data sources, transformations, integrations, storage locations, and downstream consumers.Validate data flows with business users, architects, engineers, and application owners.Identify governance gaps, duplicate data, uncontrolled transfers, and ownership issues.Support critical data element identification and lifecycle management.Contribute to data migration, integration, and transformation initiatives.Governance, Risk & Compliance (GRC)Design and implement enterprise GRC frameworks.Perform governance, risk, and compliance assessments.Maintain risk registers, compliance registers, control libraries, and evidence repositories.Develop policies, procedures, standards, and control documentation.Support ISO certifications, audits, and regulatory assessments.Track remediation plans, risk treatment actions, and compliance status.Support information security, privacy, AI governance, and data governance compliance initiatives.Privacy ManagementDesign and support enterprise privacy programs.Maintain Records of Processing Activities (RoPA).Conduct Data Protection Impact Assessments (DPIAs).Support privacy risk assessments.Manage Data Subject Access Request (DSAR) processes.Support consent, retention, deletion, breach management, and third-party privacy processes.Map personal data across business units and applications.Support Privacy by Design implementation.Maintain privacy documentation and compliance evidence.Data Discovery & Privacy TechnologyImplement and support data discovery and classification platforms.Identify sensitive, regulated, and business-critical information.Validate classifications, ownership, retention, and processing purposes.Configure scanning policies, taxonomies, workflows, and connectors.Integrate discovery outputs into governance and compliance processes.Experience with Fides is an advantage.AI Governance & AssuranceSupport AI governance frameworks and operating models.Build AI inventories and AI risk classification processes.Conduct AI risk and impact assessments.Support ISO/IEC 42001 implementation.Evaluate AI systems for governance, security, privacy, transparency, accountability, and operational risk.Integrate AI governance into enterprise GRC and cybersecurity programs.Experience with Qatar Central Bank AI requirements or similar regional AI regulations is desirable.Standards & Regulatory ExperienceExperience with one or more of the following is preferred:ISO/IEC 27001ISO/IEC 42001Information Security Management Systems (ISMS)AI Management Systems (AIMS)Privacy and Data Protection RegulationsQatar Data Protection LawUAE Data Protection LawQatar Central Bank AI RequirementsRisk & Control FrameworksData Governance FrameworksInternal Audit & ComplianceTechnology ExperienceExperience with one or more of the following platforms is advantageous:OneTrustCISO AssistantFidesCollibraInformaticaMicrosoft PurviewBigIDData Discovery PlatformsData Catalog & Metadata Management ToolsGRC PlatformsPrivacy Management SolutionsCompliance & Evidence Management PlatformsRequired Skills & ExperienceExperience in Data Governance, Privacy, GRC, Compliance, or Data Management.Strong understanding of governance frameworks, policies, and controls.Experience conducting risk assessments and governance workshops.Excellent stakeholder management and communication skills.Strong analytical and documentation abilities.Customer-facing consulting experience.Ability to work independently and collaboratively.Willingness to work on-site in Doha or Dubai.For Lead PositionsExperience leading governance and compliance programs.Managing project teams and stakeholder engagement.Designing governance operating models.Delivering assessments, roadmaps, and implementation projects.Managing budgets, risks, and project delivery.Mentoring junior consultants and supporting business development.For Consultant / Analyst PositionsExperience supporting governance initiatives.Documentation and policy development.Risk and compliance tracking.Privacy and data governance support.Reporting and stakeholder coordination.Preferred SkillsData Quality ManagementMaster Data Management (MDM)Cloud Data GovernanceRegulatory ComplianceAudit & Certification ReadinessAI Governance & Model RiskPrivacy EngineeringData ClassificationInformation Lifecycle ManagementData ArchitectureData EngineeringSystems IntegrationCybersecurity GovernanceMiddle East consulting experienceEducation & CertificationsDegreeBachelor's or Master's degree in Information Technology, Computer Science, Data Management, Information Security, Business, or a related discipline.Preferred CertificationsDAMA Certified Data Management Professional (CDMP)ISO/IEC 27001 Lead Implementer or Lead AuditorISO/IEC 42001 Lead Implementer or Lead AuditorCIPP, CIPM, CIPT, or equivalent privacy certificationsCRISC, CISA, CISSP, or similar GRC certificationsOneTrust CertificationsCollibra CertificationsMicrosoft Purview CertificationsInformatica CertificationsProject Management (PMP, PRINCE2)Business Analysis CertificationsRelevant practical consulting and implementation experience will be considered alongside professional certifications.Candidate ProfileWe are looking for professionals who are:Detail-oriented and highly organized.Strong communicators with excellent stakeholder management skills.Passionate about governance, privacy, AI governance, and compliance.Comfortable working with both business and technical teams.Able to translate regulatory requirements into practical governance solutions.Committed to delivering high-quality consulting services in customer-facing environments.Please submit your updated CV highlighting your experience in:Data GovernancePrivacy ManagementGRC & ComplianceData Lineage & Data Flow MappingData Discovery & ClassificationISO/IEC 27001ISO/IEC 42001AI Governance & AssuranceGovernance, Privacy, Compliance, and Data Management Technologies