- 8+ years in Data Privacy / Privacy Compliance / GRC.
- Strong GDPR and global privacy regulation expertise.
- Hands-on PIA/DPIA experience.
- Privacy governance and risk management background.
- Experience with privacy tools (OneTrust, TrustArc, BigID, Securiti.ai, etc.).
- Solid stakeholder management and communication skills.
Key Responsibilities
- Conduct and manage Privacy Impact Assessments (PIAs) across applications and business processes.
- Develop, maintain, and enhance privacy governance frameworks, methodologies, and compliance programs.
- Identify privacy risks, recommend mitigation strategies, and drive closure with stakeholders.
- Implement and maintain GDPR and other global privacy compliance requirements.
- Ensure adherence to regional privacy regulations,
including China PII and other international privacy laws.
- Design and deliver privacy training programs for technical and non-technical audiences.
- Conduct privacy awareness workshops and measure program effectiveness through KPIs.
- Partner with Legal, Security, Engineering, Product, and Business teams to align privacy requirements with organizational goals.
- Monitor evolving privacy regulations and translate regulatory changes into actionable business requirements.
- Maintain privacy documentation, audit artifacts, and governance records for compliance readiness.
- Drive enterprise-wide privacy-by-design initiatives throughout the product lifecycle.