Title: Project Manage (Level 3)
Pay Rate: $70-80/HR
Hours:M-F 8-5
Location: Targeting New York candidates
Open to candidates in Washington DC and Seattle as well
Possible for extension? 6 months
Team Overview:
Working heavily with Techops team
Very lean tech and engineering group
Nice to have skills:
Insider risk program experience
A little more tech savvy, work with engineers and product developers
Years of Experience:
5 years of experience
Software skills:
Experience with Google Suites
JOB DESCRIPTION:
What You'll Do:
Data Privacy Program and Data Mapping / ROPA Delivery:
Serve as day-to-day Project Manager for the Protiviti-led Data Mapping, Records of Processing Activities, and Privacy Program Support engagement, helping ensure timely completion of Discovery and Design, Assessment and Validation, Reporting, and Phase 2 Planning activities.
Develop, maintain, and manage detailed project plans, workstream trackers, budget and hours-consumed reporting, risk logs, and weekly status reporting materials.
Coordinate stakeholder interviews, system-owner workshops, documentation requests, and follow-up activities across business, technology, legal, compliance, and functional teams.
Support configuration and privacy technology enablement activities in partnership with external advisors and CBRE technology stakeholders.
Help synthesize project outputs into practical implementation roadmaps supporting privacy operations integration, DSAR and PIA program maturity, data discovery, and monitoring capabilities.
Track dependencies, open issues, decisions, and required escalations to support timely execution and leadership visibility.
Cybersecurity Integration Program Enhancement:
Coordinate completion of cybersecurity integration action items, including application registration in CBRE's Application Portfolio Management system, Vulnerability Disclosure Program rollout, Cyber Risk Questionnaire and Cyber Control Self-Attestation compliance gates, and AI/ML assessment intake processes.
Partner with CBRE cybersecurity teams engineering and product stakeholders to support adoption of CBRE's Secure Development Life Cycle, infrastructure onboarding, and related security review processes.
Support execution of CBRE-aligned cybersecurity and privacy incident response processes, including tabletop exercises, escalation-path awareness, and coordination with CBRE Security Operations and Global Data Privacy stakeholders.
Maintain corrective action trackers and drive assigned owners toward timely completion of remediation activities.
Provide clear and concise status updates to Industrious leadership, CBRE integration stakeholders, and relevant governance forums.
Promote operational alignment and business adoption of cybersecurity and privacy requirements in a practical, risk-based manner.
Program and Stakeholder Management:
Support the Head of Compliance & Privacy in maintaining a consolidated tracker of Compliance and Data Privacy Integration Plan action items across governance and operating model, policies and notices, data mapping and ROPA, DSAR, PIA/DPIA, third-party risk, training, and awareness workstreams.
Assist with coordination of vendor and procurement administration for third-party engagements, including statement of work execution, requisition tracking, milestone invoicing, and related documentation.
Support and facilitate recurring cross-functional working sessions and manage action items across Industrious business, legal, technology, and compliance stakeholders and CBRE Compliance, Legal, Cybersecurity, and Digital & Technology teams.
Prepare polished, executive-ready status updates, dashboards, risk registers, and committee materials for leadership review.
Operating in both Google Workspace and Microsoft 365 environments.
Improve and change existing methods, processes, and standards within the scope of the engagement.
Lead by example and model behaviors that are consistent with CBRE RISE values.
Other job-related duties may be assigned.
What You'll Need:
To perform this role successfully, an individual will need to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and ability required.
A minimum of 5+ years of program or project management experience, ideally spanning technology, cybersecurity, data privacy, compliance, or risk-related domains.
Hands-on technology or technical program experience is required, including experience in software delivery, IT or engineering program management, cybersecurity operations, technology risk, or a similar discipline.
Demonstrated experience managing multi-workstream projects delivered with external advisory or consulting firms and internal cross-functional stakeholders.
Working knowledge of data privacy program components such as data mapping, ROPA, DSAR, PIA/DPIA, privacy technology enablement, or privacy operations is preferred.
Working knowledge of cybersecurity governance concepts such as incident response, vulnerability management, application security onboarding, secure development processes, and compliance gates is preferred.
Familiarity with privacy technology platforms such as OneTrust is a plus.
Strong proficiency with Microsoft 365 products, including Outlook, Teams, SharePoint, Excel, and PowerPoint.
Strong proficiency in Google Workspace environments, including Gmail, Drive, Meet, Calendar, and related collaboration tools, is preferred.
Exceptional organizational, communication, stakeholder management, and relationship-building skills.
Ability to translate technical, privacy, and cybersecurity details into clear, concise updates for senior leadership and cross-functional audiences.
Strong entrepreneurial mindset with the ability to work independently and collaboratively in a fast-paced, high-growth environment.
Demonstrated ability to manage change, drive accountability, and influence stakeholders in a matrixed organization.
Extensive organizational skills and an inquisitive mindset.
Kindly share resume with answers:
Q1: How many years of experience do you have managing technology, cybersecurity, privacy, compliance, or risk-related projects?
Q2: Have you worked with cybersecurity programs involving any of the following?A: Vulnerability management B: Application security C: Secure Development Lifecycle D: Cyber risk assessments E: Security controls F: Incident response G: AI/ML security assessments
Q3: Which of the following have you worked with?
A: Data Mapping B: ROPA C: DSAR D: PIA/DPIA E: Privacy Operations F: OneTrust G: Data Discovery
| Location | New York, NY |
| Salary | $70–$80 Per Hour |
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder