Description: Our client is currently seeking a Director - Privacy and Data Protection Oversight HYBRID IN SACRAMENTO, CA
Job Title: Director - Privacy and Data Protection Status: Exempt Reports To: VP - Corporate Compliance Department: Corporate Compliance
Job Overview: The Director of Privacy and Data Protection will lead the development, execution, and oversight of Golden 1's privacy program. This role involves creating and maintaining policies, notices, and documentation to support the privacy program, reviewing products and services for privacy issues, and providing consultation on privacy matters. The Director will collaborate across teams to ensure compliance with legal and regulatory requirements.
Key Responsibilities:
Promote privacy compliance awareness across the organization by building relationships with key business lines and stakeholders, and communicating effectively with senior leadership.
Collaborate with 1st Line of Defense (1LOD) stakeholders to facilitate data inventory, categorization, and mapping of systems and processes.
Provide ongoing support as part of the 2nd Line of Defense (2LOD) team.
Serve as a subject matter expert, offering actionable guidance on privacy and data protection, including data security incident handling.
Develop and maintain the Credit Union's 2LOD Privacy Compliance Program.
Stay informed on local, state, and federal privacy laws and monitor changes, reporting them to relevant parties.
Determine the applicability of law changes and work with 1LOD to implement necessary changes.
Create and maintain 2LOD Privacy Policies.
Oversee 1LOD teams on privacy compliance program elements such as procedure alignment, risk assessments, monitoring, and training.
Guide the Second Line testing team and participate in compliance reviews.
Review marketing collateral and employee communications for compliance with privacy regulations.
Prepare and present compliance reports for committees as needed.
Provide regulatory privacy expertise for new and existing products, services, procedures, and practices.
Identify and implement controls for managing privacy compliance risk in conjunction with various departments.
Provide recommendations and action plans to address audit exceptions.
Collaborate with Human Resources and the Enterprise Development Department to improve privacy compliance training materials.
Work with legal for assessment and advice on privacy-related compliance risks.
Foster a positive work environment by promoting skill development, coaching, and ensuring positive employee morale.
Qualifications:
Education: Bachelor's degree in business administration, law, finance, accounting, computer science, or a related field. An Associate's degree with commensurate experience may be considered.
Experience: 10+ years in privacy, data protection, information security, risk management, auditing, and/or compliance, preferably in the financial services industry.
Knowledge/Skills:
Knowledge of California and federal privacy laws (e.g., CCPA/CPRA, CalOPPA, GLBA, GDPR).
Experience with risk management frameworks.
Ability to manage multiple assessments and prioritize tasks.
Strong communication skills and ability to work in a dynamic team environment.
Consultative approach with all levels of management.
Strong problem-solving and organizational skills.
Proficiency in Microsoft Word, Excel, PowerPoint, Adobe Acrobat Pro, and SharePoint.
Physical Requirements:
Prolonged sitting with occasional mobility.
Normal vision and hearing (with accommodations if needed).
Ability to lift up to 15 lbs.
Occasional movement throughout the department.
Licenses/Certifications:
Privacy certification such as CIPP or CIPM is preferred.
Note: This job description is not exhaustive and may include other duties as assigned.
Contact: aflores@judge.com
This job and many more are available through The Judge Group. Find us on the web at www.judge.com