5+ years of experience in risk management, GRC, information security, privacy, third-party risk, operational risk, technology risk, or a related oversight function, preferably within financial services, asset management, or another highly regulated industry. Lead review and challenge of Privacy Impact Assessments (PIAs), Data Protection Impact Assessments (DPIAs), and privacy risk assessments, including assessments involving new technologies, artificial intelligence, sensitive data, and elevated privacy risk.