A newly established education venture is building technology and computing education programmes for secondary schools across the GCC — delivered in partnership with schools and taught by its own employed specialist teachers.
This is a founding-team appointment, based in Doha, reporting to the Managing Director with direct escalation to the Founder.
*Why this role matters*
The programmes will handle the personal data of children at scale. This role owns data governance, risk, and security — across both people and technology — for everything the organisation builds, with the authority to halt a release, refuse a supplier, or escalate directly.
Most of the frameworks themselves aren't the hard part — that knowledge exists, and this role will draw on it. The hard part, and the actual job, is enforcement: making sure what's designed on paper is what actually ships, and holding the line when it's commercially inconvenient to do so.
The function doesn't exist yet. Whoever takes this on will define it, not inherit it — and will spend the early part of the role working with the product and engineering teams, shaping the roadmap so compliance is built in from the start, before formalising the organisation-wide policy structure around it. It reports outside the technology and product line by design; that independence is the point of the appointment.
*What you'll own*
🔹 Data governance: lawful basis and consent architecture for minors' personal data, including parental and school consent flows
🔹 Risk: data protection impact assessments (DPIAs) for the platform and every new processing activity; enterprise, operational and third-party risk identification, assessment and remediation tracking
🔹 Security: safeguarding-by-design and security-by-design review of product and content releases before they reach schools, working closely with engineering
🔹 Retention, minimisation and deletion policy — including what happens when a student leaves the programme
🔹 Data residency and cross-border transfer requirements as a core design constraint
🔹 Supplier and processor due diligence across every third party touching student data
🔹 Breach response planning, rehearsal and ownership; input into incident response and business continuity
🔹 The external-facing role — presenting the organisation's approach to regulators, school leaders and parents
🔹 Policy, training and culture across the organisation — for teaching staff as well as product and technical teams
*What we're looking for*
✅ 5–10 years in data protection, privacy, risk, or information governance — ideally with a framework or programme you built and operated yourself, even at small scale
✅ Some direct exposure to children's personal data in education, health, social care, or child-facing technology is a strong plus; a general privacy/security/GRC background with the right mindset will also be considered
✅ Working knowledge of GCC data protection regimes, or a comparable framework with a credible path to regional competence quickly
✅ Comfort working consultatively — influencing a product roadmap early, then formalising the policy structure once the shape of the business is clearer
✅ A track record (however junior) of holding a position under commercial pressure — a decision you pushed back on, and what followed
*Strong advantage*
▪️ Arabic language capability, professional or native — this role involves regular school, parent and regulator contact
▪️ GCC experience, particularly government or regulator-facing work
▪️ A recognised privacy, risk, or information security qualification (e.g. CIPM, CIPT, CISM, CRISC, ISO 27001 Lead Implementer/Auditor)
▪️ Experience building a function at foundation stage, where the framework didn't exist yet
Full time, based in Doha, on-site. Competitive package commensurate with experience, with relocation support where relevant.
This role suits someone who is comfortable being the person who says no — and can explain why in terms a head teacher or a parent understands just as easily as a product lead. It's genuinely two disciplines (governance/privacy and risk/security) folded into one seat because, at this stage, neither is a full-time job on its own — so the person who thrives here will move fluidly between policy and product conversations. For a period, it's a role of one, with external specialist support — not a settled framework to administer.
To apply
Please submit your CV along with a one-page note describing a data protection, risk, or security position you took that was commercially inconvenient, and how you handled it.
This note is not optional. It carries as much weight as the CV, and applications without it won't be considered complete.
Appointment is subject to background and reference checks appropriate to a child-facing role.
Experienced Quality Assurance Specialist
Boeing
Quality Production Specialist
Boeing
Demi Chef De Partie - Pastry
La Petite Maison (LPM)
Senior Lecturer / Lecturer - BA (Hons) Human Resource Management
Oryxuni
Marine Operations Manager
Delphie Consulting services
Senior Tax Analyst
Nebras Energy