Job Description
Set the program strategy and architecture. Define the vision, priorities, operating model, and multiyear roadmap for privacy and data protection across sales, consulting, and technical support. Own program effectiveness. Lead privacy risk management. Identify, aggregate, assess, and prioritize systemic, emerging, and business-specific privacy risks; recommend pragmatic treatments; and drive mitigation through accountable business and technical owners. Translate obligations into scalable solutions. Convert complex privacy requirements into actionable business guidance, technical patterns, control designs, and privacy-by-design practices that teams can implement consistently. Modernize and simplify the program. Orchestrate a federated privacy model. Align distributed privacy, legal, engineering, risk, compliance, and business teams around common standards, priorities, and outcomes without relying on direct authority. Advise senior leaders. Provide clear, decision-ready insights on risk posture, control effectiveness, regulatory change, investment priorities, and opportunities to enable responsible business growth. Represent the program with credibility. Bachelor's Degree in Risk Management, Engineering, Government Intelligence, Security, or Information Technology, or related field AND 6+ years experience in risk management, privacy, security, compliance, government intelligence, operations, auditing, and/or finance OR equivalent experience. Master's Degree in Risk Management, Engineering, Government Intelligence, Security, or Information Technology, or related field AND 8+ years experience in risk management in the context of operations, engineering, information technology, business analyst, consulting, auditing, privacy, security, compliance, government intelligence, and/or finance OR Bachelor's Degree in Risk Management, Engineering, Government Intelligence, Security, Cybersecurity, or Information Technology, or related field AND 12+ years experience in risk management in the context of operations, engineering, information technology, business analyst, consulting, auditing, privacy, security, compliance, government intelligence, and/or finance OR equivalent experience. Membership with a relevant risk domain area association including: International Association of Privacy Professionals (IAPP), International Information System Security Certification Consortium (ISC)2, and Information Systems Audit and Control Association (ISACA), Certified Internal Auditor (CIA), Society for Corporate Compliance and Ethics (SCCE), Disaster Recovery Institute (DRI), Certified Business Continuity Professional (CBCB), Committee of Sponsoring Organizations of the Treadway Commission (COSO), and Institute of Internal Auditors (IIA). Experience with AI, AI-based analytical tools, AI governance, and AI governance frameworks. Experience with privacy program architecture, control design, testing, metrics, dashboards, audit readiness, and regulatory documentation such as DPIAs and records of processing activities, particularly in relation to Data Processor activities Experience in dealing with complex third-party privacy sub processor scenarios Understanding of cloud services, enterprise data ecosystems, and the privacy considerations associated with AI and emerging technologies. Excellent judgment and communication skills, with the ability to make complex privacy risks clear and actionable for technical, legal, and executive audiences. 6+ years of experience in privacy, data protection, risk management, security, compliance, audit, operations, or a related field; OR a bachelor's degree and 4+ years of relevant experience; OR equivalent experience. Demonstrated experience designing, leading, or materially transforming a privacy or data protection program in a large, complex, matrixed organization. Knowledge of global privacy and data protection obligations, privacy-by-design principles, data governance, privacy risk assessment, and accountability frameworks. Experience translating legal, regulatory, contractual, or policy requirements into practical business processes, technical requirements, and scalable controls. Proven ability to influence senior leaders and cross-functional teams, create structure in ambiguity, and drive outcomes without direct authority.