Bachelor’s degree in information technology, Computer Science, Information Security, Business Information Systems, Law, or related field.
Minimum 3–5 years of experience in: Data Governance, Information Security, Compliance or Risk Management or Data Privacy Management
Strong understanding of: Data governance frameworks, Data privacy and security principles, Sri Lanka Personal Data Protection Act (PDPA), Data lifecycle management, Access management and security controls
Familiarity with: Microsoft 365 Security & Compliance, Microsoft Entra ID, ERP systems such as Microsoft Dynamics 365 Business Central, web applications, mobile applications and AI concepts, frameworks, Data Loss Prevention (DLP) tools and Cloud security concepts.
Excellent analytical and problem-solving skills
Strong communication and stakeholder management abilities
High level of confidentiality and integrity
Strong documentation and reporting skills
Ability to work independently and manage multiple priorities
Lawful processing of personal data
Consent management
Data subject rights
Data retention requirements
Cross-border data transfers
Data breach management
Responsibilities of Data Controllers and Processors