HirePortal

Manager Group Data Protection & Compliance

SriLankan Airlines Ltd, the National Carrier of Sri Lanka operates with a network of destinations throughout Asia, the Middle East, Europe, and Australia. The Airline has a strong presence in the Maldives and Southern India. SriLankan is a member of the ‘oneworld’ alliance.

SriLankan IT Systems drives the airline’s IT strategy through digital transformation, technology adoption, data modeling, business intelligence, and business continuity. The focus is on transforming business and operational processes, expanding digital passenger reach, and improving customer experience through solutions design, development, and integrations while enhancing airline IT domain knowledge. Award-winning SriLankan IT team is seeking a dynamic individual to join as a Manager Group Data Protection & Compliance.

The individual is responsible for overseeing SriLankan Group’s data privacy and information security compliance programmes, work with European Regulatory Authorities is mandatory under Article 37 (EU-GDPR) for organizations handling European natural subjects.

Ensure that sound policies, procedures and systems are in place so that Sri Lankan Airlines is able to demonstrate compliance with theGeneral Data Protection Regulation (GDPR).

Management of SriLankan Groups' Information Security framework and Data Privacy through architecture of policies and implementation of processes/controls to ensure Confidentiality, Integrity, Availability and Privacy of Information as per international standards, legislative and regulatory requirements including and not limited to European Union General Data Protection Regulation (EU GDPR) and SO/IEC 27001:2013 Information Security Management System.

Key responsibilities will include:​

  • Required to be involved, and in a timely manner, in all issues which relates to the protection of personal data and information security pertaining to passengers, customers, staff, service providers and other relevant parties ensuring confidentiality concerning the performance of designated responsibilities. Thereby fulfilling EU-GDPR requirements which otherwise leads to high penalties (2% of worldwide revenue) for violation of EU-GDPR requirements.
  • Manage the assignment of responsibilities with reference to General Data Protection Regulations and ISO/IEC 27001:2013 Information Security Management Systems policies of the Group through the respective teams and champions in the Group businesses while managing a comprehensive program of awareness-raising and training to deliver compliance and to foster a data privacy and information security culture by default and by design within the Group. Continuously improve Information Security and Data Privacy of the Group.
  • Responsible of being the contact point with and co-operate with the relevant Data Protection Authorities (DPA) in respective countries in the Northern America (NA), Latin America (LATAM), Europe,The Middle east and Africa (EMEA) and Asia Pacific (APAC), and to data subjects when exercising their individual data rights as well as supervise and advise on the response to such requests.
  • Accountable to provide frequent updates and strategic direction on Information Security and Data Privacy implementations and best practices to the SriLankan Group, Board of Directors, Chief Officers, Heads of Divisions, Senior Management Committee and those of other strategic business units.
  • Responsible for effectively supervising the subordinates for continuous operation of Information Security Management and Data Privacy Protection Practices in establishing, implementing, monitoring and maintaining an Information Security and Data Privacy Management System as per the international standard ISO/IEC 27001:2013 (Information Security Management System) and General Data Protection Regulation for SriLankan Group and other Strategic Business Units.
  • Manage, facilitate, conduct and supervise periodic security reviews with internal teams and external parties for vulnerability audits, penetration assessments and the implementation of any other security tools/methodologies on business-critical Systems, Applications and Services periodically and on-demand for the Airline group. Being responsible for the conduct of Data Protection Impact Assessments as required for Applications and Services through implementation/maintenance of Network and Application Security Controls and Technologies.
  • Strategic planning and development of Information Technology Security and Data Privacy Policies/Procedures/Controls and Roles/Responsibilities for the Group, on a continuous basis, to reflect the changing environment, organization needs and evolving technologies with an emphasis on Disaster Recovery and Business Continuity Management by preserving Information Security and Data Privacy. Also being responsible for successful implementation and maintenance of same through the direct reports.
  • Liaise and consult Interested Parties (including and not limited to, DPAs, Government Authorities and Group Management) with strategic Information Security and Data Privacy related policies, feedback and direction through professional reports, graphs and work updates on efficiency of Information Security and Data Privacy initiatives. Represent SriLankan Group in oneworld Alliance Cyber Security Governance Board, Legislative/Regulatory Committees and other relevant working groups.

Requirements

Masters’ Degree or relevant Membership from a Professional Body and Bachelors’ Degree with 06 years post qualifying overall work experience with 03 years Managerial experience and 03 years in Executive level.

OR

Full professional qualification with 06 years’ overall experience with 03 years at Managerial level and 03 years at Executive level in a relevant discipline and relevant Membership from a Professional Body.

Be a Sri Lankan citizen.

The upper age limit should be 45 years as of 18 September 2026, which is the closing date.

Employment will be offered on fixed term contract.

We are an equal opportunity Organization.

Influencing will be a reflection of unsuitability.

Please note that we will correspond with you within a month of closing the advertisement in the event your application is shortlisted for consideration.

Skills

  • GDPR
  • Data Privacy
  • Information Security
  • Compliance
  • Policy Development
  • Risk Management
  • Audit

Related jobs

SriLankan AirlinesApply for this job