Summary Spec for Privacy contractor
Seeking a senior privacy professional with a minimum of 10 years of experience designing, implementing, and operationalizing enterprise privacy programs within financial institutions, preferably in the second line of defense. The contractor will support the maturation of the organization s privacy framework, governance processes, privacy risk management capabilities, regulatory compliance obligations, third party privacy oversight, Privacy Impact Assessment (PIA)/Privacy Risk Assessment (PRA) programs, and privacy reviews of Artificial Intelligence initiatives. He/she will be working closely with our partners in the first line of defense as well as in the Legal department to ensure comprehensive coverage for privacy requirements.
The ideal candidate has hands-on experience standing up or enhancing privacy programs in the second line of defense at highly regulated financial environments and can operate strategically while also delivering practical implementation artifacts.
More specific bullets for what we need:
Privacy Governance & Standards
- Support development, maintenance, and refresh of Privacy governance artifacts.
- Assist with alignment of Privacy requirements across Data Governance, Data Sharing, RIM, and AI governance initiatives.
- Track regulatory, audit, and risk management commitments impacting Privacy.
Privacy Impact Assessment (PIA) Oversight
- Support intake, coordination, tracking, and reporting of PIAs.
- Review submissions for completeness and adherence to established requirements.
- Escalate gaps and concerns for management review and challenge.
Privacy Risk Oversight
- Assist with Privacy-related RCSA and control oversight activities.
- Support risk identification, issue tracking, remediation monitoring, and reporting.
- Contribute to development of risk metrics, KRIs, and executive reporting.
Third-Party Privacy Reviews
- Support Privacy reviews associated with third-party relationships and external data usage.
- Coordinate with Procurement, Legal, Compliance, Security, and business stakeholders.
- Assist in documenting privacy risks and mitigation requirements.
AI & Privacy Integration
- Evaluate Privacy considerations associated with AI and advanced analytics use cases.
- Support Privacy-by-Design principles within AI governance activities.
- Identify intersections between Privacy, Data Sharing, Records Management, and AI risk.
Business Unit Engagement
- Provide guidance and coordination support for Business Unit Privacy activities.
- Support communication, awareness, training, and adoption efforts.
- Help aggregate enterprise-wide visibility into Privacy risks, issues, and activities.
Desired Knowledge and Skills
Foundational Knowledge
- Privacy principles and risk management concepts.
- Understanding of Personally Identifiable Information (PII) and sensitive data handling.
- Familiarity with Privacy-by-Design concepts.
- Understanding of records management and data sharing dependencies.
Governance & Risk Skills
- Second Line of Defense mindset and effective challenge.
- Governance document development and maintenance.
- Policy, standard, and procedure interpretation.
- Risk assessment and issue management experience.
- Audit and regulatory response support.
Analytical Skills
- Ability to identify trends and emerging risks.
- Executive reporting and presentation development.
- Data analysis and metric development.
- Process mapping and control evaluation.
Collaboration Skills
- Ability to coordinate across Legal, Compliance, Security, Technology, Data Management, and Business Units.
- Strong facilitation and stakeholder management capabilities.
- Ability to translate regulatory requirements into practical governance expectations.