## Responsibilities:
šConduct Privacy Impact Assessments (PIAs) of the applicationās security design for the appropriate security controls, which protect the confidentiality and integrity of Personally Identifiable Information (PII)
šResponsible for the implementation of the company's domestic and international business and consumer privacy protection program
šInterpret and apply data privacy regulations, policies, standards, or procedures to specific issues
šInterpret patterns of non-compliance to determine their impact on levels of risk and/or overall effectiveness of the enterpriseās cybersecurity program
šManage and ensure the enterprise data inventory is kept up-to-date
šDevelop privacy training materials and other communications to increase employee understanding and awareness of company privacy policies, data handling practices and procedures and legal obligations
šWork with the general counsel and business teams to ensure both existing and new services comply with privacy and data security obligations
šWork with legal counsel, management, key departments, and committees to ensure the organization has and maintains appropriate privacy and confidentiality consent, authorization forms and information notices and materials reflecting current organization and legal practices and requirements
šMaintain current knowledge of applicable federal, state, and international privacy laws and accreditation standards, and monitor advancements in information privacy technologies to ensure organizational adaptation and compliance
šWork with business teams and senior management to ensure awareness of ābest practicesā on privacy and data security issues
šCollaborate with the cybersecurity and IT teams to ensure privacy requirements are translated into technical requirements and solutions are implemented correctly
šInterface with Senior Management to develop strategic plans for the collection, use and sharing of information in a manner that maximizes its value while complying with privacy regulations
šIdentify and manage privacy incidents and breaches in conjunction with the Chief Information Security Officer, legal counsel and the business units.
šOther assigned duties.
## Qualifications:
š5+ yearsā experience in a privacy / data loss prevention and protection related field
šThe ability to create a data privacy program and eventually lead a team of privacy professionals
šBachelor degree or above in information security, computer, or related majors
šThe ability and experience with working across departments and business units to implement organizationās privacy principles and programs, and align privacy objectives with security objectives
šThe ability to develop, update, and/or maintain standard operating procedures (SOPs)
šThe ability to determine whether a security incident violates a privacy principle or legal standard requiring specific legal action
šExpertise in domestic and international laws and regulations, such as cybersecurity law, GDPR, HIPPA, etc.
šThe ability to partner with lawyers and outside law firms to stay abreast of changing privacy related laws and regulations
šExperience with cloud environments (e.g., AWS, Azure, O365) and technical implementation of data security and privacy requirements
šSelf-driven with good teamwork, communication skills
šPrivacy certification preferred (e.g., CDPSE, CIPP-E, CIPP-US, CIPM, CISSP)