Skip to content

Open nowPosted 10 days ago

Data Protection Officer

Workable (global search)108,016 open roles

Where
Jakarta, Indonesia
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowData Protection OfficerWorkable (global search) · Jakarta, Indonesia
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 10 days ago

Workable (global search) median: 7 days open

The posting

  • Lead the enterprise-wide data protection strategy, ensuring full compliance with UU PDP, GDPR, ISO 27701, and all applicable national and international privacy regulations.
  • Authorize data protection policies, privacy frameworks, data processing agreements, and binding corporate rules across all business entities and subsidiaries.
  • Strategize and oversee the implementation of Privacy by Design and Privacy by Default principles across all new products, systems, processes, and digital transformation initiatives.
  • Synergize with C-Suite, Board of Directors, Legal, IT, Compliance, and Business Units to embed privacy governance into organizational culture and decision-making.
  • Lead and manage Data Protection Impact Assessments (DPIAs), Records of Processing Activities (RoPAs), and privacy risk assessments across the organization.
  • Negotiate and authorize data sharing agreements, data processing agreements (DPAs), and cross-border data transfer mechanisms with third parties and regulatory bodies.
  • Strategize and lead the organization’s response to data subject rights requests (access, erasure, portability, objection) and personal data breach incidents, including regulatory notifications.
  • Lead engagement with regulators, including the National Data Protection Authority (Kominfo/BSSN), and serve as the primary point of contact for all regulatory inquiries and audits.
  • Authorize and oversee privacy training programs, awareness campaigns, and capability uplift initiatives for all staff levels, including senior leadership.
  • Synergize with the Cybersecurity and IT GRC functions to ensure alignment of information security controls with privacy obligations, including ISMS (ISO 27001) and PIMS (ISO 27701) programs.
  • Lead the development and continuous improvement of the organization’s privacy maturity model, benchmarking against global best practices and frameworks.
  • Strategize on emerging technology risks related to AI, Cloud, IoT, and Mobile, ensuring privacy considerations are proactively addressed across the technology landscape.
  • Lead the development and operationalization of a Data Security Framework covering data classification, Data Loss Prevention (DLP), encryption standards, and access governance in coordination with the CISO and Cybersecurity function.
  • Oversee and authorize cybersecurity-related privacy risk assessments including third-party vendor security reviews, cloud security assessments, and technology due diligence for data-intensive systems and digital platforms.
  • Lead coordination with the Security Operations Center (SOC) and CSIRT on personal data breach detection, containment, and regulatory notification procedures under UU PDP and applicable sectoral regulations (including BSSN directives).

Requirements

  • Bachelor’s degree in Law, Information Technology, Computer Science, Cybersecurity, or a related field; Master’s degree or postgraduate qualification in Data Privacy, Information Security, or Law is highly preferred.
  • Minimum 10 years of progressive experience in Data Privacy, Cybersecurity, IT GRC, or a related discipline, with at least 2 years in a senior DPO, privacy advisory, or data governance leadership role.
  • Demonstrated expertise in Indonesian Personal Data Protection Law (UU PDP No. 27 Tahun 2022) and GDPR, with a proven track record of regulatory compliance implementation across large or complex organizations.
  • Strong capability to lead, design, and authorize enterprise privacy programs including DPIAs, RoPAs, privacy risk assessments, and incident response frameworks.
  • Proven ability to synergize with and advise at Board and C-Suite level, translating complex privacy and regulatory requirements into strategic business guidance.
  • In-depth knowledge of international privacy and security standards and frameworks including ISO 27701, ISO 27001, NIST Privacy Framework, NIST CSF, COBIT, and PCI-DSS.
  • Experience in negotiating data processing agreements, cross-border transfer mechanisms, and regulatory submissions with government authorities and regulators.
  • Broad understanding of cybersecurity domains including Cyber Strategy, Security Architecture, Cloud Security, DevSecOps, OT/ICS Security, and Emerging Technology Risks (AI, IoT, Mobile, Cloud).
  • Strong knowledge of IT Audit, IT Risk Management, IT Governance, Enterprise Architecture, Business Continuity Management (ISO 22301), and Digital Transformation.
  • Excellent executive communication, stakeholder management, and cross-functional leadership skills, with the ability to influence and drive change at all organizational levels.
  • Demonstrated experience in acting as an Independent or External Advisor to Boards, Audit Committees, or regulatory bodies is a strong advantage.
  • Professional certifications required: one or more of CIPP/E, CIPM, FIP, CDPO, or equivalent privacy credentials. Additional preferred certifications include CISM, CISSP, ISO 27001 LA, ISO 27701 LA, ISO 22301 LA, GRCP, GRCA, CCSK, or OT Privacy Expert.

Benefits

  • Private Health Insurance
  • Pension Plan
  • Training & Development
  • Performance Bonus
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.