2,480 Privacy Management jobs in the United States
Security and Privacy Risk Management Specialist, Kuiper Security

Posted today
Job Viewed
Job Description
Project Kuiper is an Amazon initiative to increase global broadband access through a constellation of over 3,000 Low Earth Orbit (LEO) satellites. Its mission is to bring fast, affordable broadband to unserved and underserved communities worldwide. At Project Kuiper, we are obsessed with customer trust and are seeking an individual contributor who is creative, and passionate about delivering Governance, Risk and Compliance solutions to meet Kuiper's regulatory and external assurance needs. In this role, you will work collaboratively with various business and security teams across Amazon to identify compliance needs, assess the maturity of processes and controls, design, build, and execute high-impact security or compliance programs and liaise with external auditors to ensure successful audit executions.
This role is open for Sunnyvale, CA, and Redmond, WA locations.
The Security Compliance Specialist in Project Kuiper's Security team will drive regulatory and certification compliance requirements for our world-class cyber and information security throughout Kuiper's technology, systems, and infrastructure. This role is at the forefront of delivering highly secure space and terrestrial broadband telecommunication services for consumer, enterprise, telecom, transportation and government customers around the world.
The ideal candidate is technically experienced and innovative security, risk, compliance, and audit professional who has the ability to understand systems, security, and privacy processes, communicate to customers, and to be able to drive innovative process changes through multiple organizations and teams. You have implemented NIST control frameworks, reviewed control activities, evidence collection, and liaised with auditors.
Export Control Requirement:
Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.
Key job responsibilities
- Play a leadership role in Kuiper Security and work closely with the Kuiper business and product community, setting direction for security of key assets, data, and business processes; serving as a subject matter expert resource for security engineers, security champions, and business leaders inside and outside of our organization
- Proactively assess, identify and develop recommendations regarding data protection, insider threat, data sharing, identity and access management, and third party risk issues and vulnerabilities by working with multiple stakeholder teams, including Privacy, Legal, HR, IT, etc
- Lead and execute internal security and data usage assessments, investigations and security audits, while also supporting enterprise wide information security and cyber risk assessments with technical and non-technical teams
- Contribute to the development of business risk, insider threat, and third party risk management strategic control requirements and roadmaps
- Contribute to new, and provide feedback on existing security standards and control requirements, GRC policy exceptions and risk issue management process
- Develop and maintain relevant security risk metrics to promote transparency across the organization; measures, monitors and reports on information security risks to management
- Provide guidance on risk, compliance, and policy to technical and non-technical internal customers, including security training and outreach to internal teams and external supply chain partners
- Apply your security and business knowledge to drive secure and pragmatic improvements broadly to Kuiper people, process, and assets, while making technical trade-offs between short versus long term security and business goals
- Strong organizational and communication skills, with a demonstrated ability to work in a multi-tasking dynamic environment while maintaining a high level of ownership and accountability is a must
About the team
Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Basic Qualifications
- BS in Cybersecurity, Computer Science, or other relevant degree
- Experience in cyber and information security functions, especially in areas including Governance, Risk and Controls (GRC), Privacy, insider threat, business information security, identity and access management, third party risk, incident response, threat modeling
- Experience in an information security leadership role
- Knowledge in navigating risk mitigation and risk issue management, policy and standards, security frameworks (e.g. NIST, ISO, etc.), managing a GRC function, and business information security / risk officer function
- Experience in web and mobile application security, and cloud technologies threats and risks
- Experience in written and verbal communication
- Experience in mentoring a non-tech community on complex technical issues or ambiguous technical challenges
Preferred Qualifications
- MS in Cybersecurity, Computer Science, or other relevant degree
- Ability to identify security issues and risks, and develop mitigation plans or solutions
- Knowledge of web and mobile application security, and cloud technologies, common vulnerabilities, attacks, and mitigation methods
- Demonstrated experience using communication skills to advocate security for both technical and non-technical audiences
- Experience in driving large scale, cross-organization initiatives
- Sharp analytical abilities and proven innovation skills to unblock adoption of security mechanisms
- Relevant industry certifications (e.g., CISSP, SANS/GIAC, CISA, OSCP/OSWA/OSWE, AWS)
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company's reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $91,800/year in our lowest geographic market up to $196,300/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit . This position will remain posted until filled. Applicants should apply via our internal or external career site.
Security and Privacy Risk Management Specialist, Kuiper Security

Posted 4 days ago
Job Viewed
Job Description
Project Kuiper is an Amazon initiative to increase global broadband access through a constellation of over 3,000 Low Earth Orbit (LEO) satellites. Its mission is to bring fast, affordable broadband to unserved and underserved communities worldwide. At Project Kuiper, we are obsessed with customer trust and are seeking an individual contributor who is creative, and passionate about delivering Governance, Risk and Compliance solutions to meet Kuiper's regulatory and external assurance needs. In this role, you will work collaboratively with various business and security teams across Amazon to identify compliance needs, assess the maturity of processes and controls, design, build, and execute high-impact security or compliance programs and liaise with external auditors to ensure successful audit executions.
This role is open for Sunnyvale, CA, and Redmond, WA locations.
The Security Compliance Specialist in Project Kuiper's Security team will drive regulatory and certification compliance requirements for our world-class cyber and information security throughout Kuiper's technology, systems, and infrastructure. This role is at the forefront of delivering highly secure space and terrestrial broadband telecommunication services for consumer, enterprise, telecom, transportation and government customers around the world.
The ideal candidate is technically experienced and innovative security, risk, compliance, and audit professional who has the ability to understand systems, security, and privacy processes, communicate to customers, and to be able to drive innovative process changes through multiple organizations and teams. You have implemented NIST control frameworks, reviewed control activities, evidence collection, and liaised with auditors.
Export Control Requirement:
Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.
Key job responsibilities
- Play a leadership role in Kuiper Security and work closely with the Kuiper business and product community, setting direction for security of key assets, data, and business processes; serving as a subject matter expert resource for security engineers, security champions, and business leaders inside and outside of our organization
- Proactively assess, identify and develop recommendations regarding data protection, insider threat, data sharing, identity and access management, and third party risk issues and vulnerabilities by working with multiple stakeholder teams, including Privacy, Legal, HR, IT, etc
- Lead and execute internal security and data usage assessments, investigations and security audits, while also supporting enterprise wide information security and cyber risk assessments with technical and non-technical teams
- Contribute to the development of business risk, insider threat, and third party risk management strategic control requirements and roadmaps
- Contribute to new, and provide feedback on existing security standards and control requirements, GRC policy exceptions and risk issue management process
- Develop and maintain relevant security risk metrics to promote transparency across the organization; measures, monitors and reports on information security risks to management
- Provide guidance on risk, compliance, and policy to technical and non-technical internal customers, including security training and outreach to internal teams and external supply chain partners
- Apply your security and business knowledge to drive secure and pragmatic improvements broadly to Kuiper people, process, and assets, while making technical trade-offs between short versus long term security and business goals
- Strong organizational and communication skills, with a demonstrated ability to work in a multi-tasking dynamic environment while maintaining a high level of ownership and accountability is a must
About the team
Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Basic Qualifications
- BS in Cybersecurity, Computer Science, or other relevant degree
- Experience in cyber and information security functions, especially in areas including Governance, Risk and Controls (GRC), Privacy, insider threat, business information security, identity and access management, third party risk, incident response, threat modeling
- Experience in an information security leadership role
- Knowledge in navigating risk mitigation and risk issue management, policy and standards, security frameworks (e.g. NIST, ISO, etc.), managing a GRC function, and business information security / risk officer function
- Experience in web and mobile application security, and cloud technologies threats and risks
- Experience in written and verbal communication
- Experience in mentoring a non-tech community on complex technical issues or ambiguous technical challenges
Preferred Qualifications
- MS in Cybersecurity, Computer Science, or other relevant degree
- Ability to identify security issues and risks, and develop mitigation plans or solutions
- Knowledge of web and mobile application security, and cloud technologies, common vulnerabilities, attacks, and mitigation methods
- Demonstrated experience using communication skills to advocate security for both technical and non-technical audiences
- Experience in driving large scale, cross-organization initiatives
- Sharp analytical abilities and proven innovation skills to unblock adoption of security mechanisms
- Relevant industry certifications (e.g., CISSP, SANS/GIAC, CISA, OSCP/OSWA/OSWE, AWS)
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company's reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $91,800/year in our lowest geographic market up to $196,300/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit . This position will remain posted until filled. Applicants should apply via our internal or external career site.
Privacy Program Manager-Risk Management-PDPO-San Jose
Posted 15 days ago
Job Viewed
Job Description
Location :
San Jose
Employment Type :
Regular
Job Code :
A129593
Apply to this job
Share this listing:
Responsibilities
PDPO (Privacy and Data Protection Office) is the organization to lead, supervise, and empower all TikTok's privacy work in an accountable and industry leading way. You will join a global team driving privacy best practices across TikTok. Our focus involves ensuring compliance with global laws, regulations and the adoption of privacy best practices. In this role, you will drive multiple programs, in collaboration with colleagues around the world. You will partner with legal and technical teams to drive change across the organization. About the Role - Develop, implement, and maintain privacy risk management framework to ensure compliance with global privacy regulations such as GDPR, CCPA, etc - Execute regular privacy risk assessments and audits to identify potential privacy risks and develop mitigation strategies - Collaborate with cross-functional teams, including IT, legal, and human resources, to ensure that privacy considerations are integrated into business processes, product development, and technology solutions - Develop and maintain privacy policies, procedures, and documentation to support compliance efforts and best practices - Facilitate privacy training and awareness programs for employees to promote a culture of privacy and data protection within the organization - Monitor changes in privacy laws and regulations and assess their impact on the organization's privacy program, updating policies and practices as necessary - Serve as the point of contact for privacy-related inquiries from employees, customers, and regulators. - Provide guidance and support to business units in conducting data protection impact assessments (DPIAs) for new and existing processes - Develop standardized processes, technical solutions, and knowledge sharing tools - Excel in situations of ambiguity, leveraging a high degree of judgment and analysis to navigate uncertain regulatory landscapes and guide the organization through complex privacy challenges
Qualifications
Minimum Qualifications: - Minimum bachelor's degree - Minimum 5+ years work experience, with 2+ years of experience in privacy risk, data protection, or a related field, with a proven track record of executing privacy programs - Strong analytical, organizational, and interpersonal skills, combined with excellent verbal and written communication skills - Attention to detail, organized, resourceful, with interest and proven ability to work in a fast-paced, multi-cultural and multi-functional environment - Strong understanding of global data protection laws and regulations, including GDPR, CCPA, and industry-specific regulations. Preferred Qualifications - Experience conducting privacy impact assessments and managing privacy compliance audits. - Excellent communication skills, both written and verbal, with the ability to convey complex privacy concepts to diverse audiences. - Strong analytical and problem-solving skills, with a detail-oriented approach to managing projects and tasks. - Demonstrated ability to work effectively in environments of ambiguity and constant change. - Ability to work collaboratively in a team environment and to engage with stakeholders at all levels of the organization.
Job Information
(For Pay Transparency)Compensation Description (Annually)
The base salary range for this position in the selected city is $194000 - $355000 annually.
Compensation may vary outside of this range depending on a number of factors, including a candidate's qualifications, skills, competencies and experience, and location. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and restricted stock units.
Benefits may vary depending on the nature of employment and the country work location. Employees have day one access to medical, dental, and vision insurance, a 401(k) savings plan with company match, paid parental leave, short-term and long-term disability coverage, life insurance, wellbeing benefits, among others. Employees also receive 10 paid holidays per year, 10 paid sick days per year and 17 days of Paid Personal Time (prorated upon hire with increasing accruals by tenure).
The Company reserves the right to modify or change these benefits programs at any time, with or without notice.
For Los Angeles County (unincorporated) Candidates:
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws including the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Our company believes that criminal history may have a direct, adverse and negative relationship on the following job duties, potentially resulting in the withdrawal of the conditional offer of employment:
1. Interacting and occasionally having unsupervised contact with internal/external clients and/or colleagues;
2. Appropriately handling and managing confidential information including proprietary and trade secret information and access to information technology systems; and
3. Exercising sound judgment.
About TikTok
TikTok is the leading destination for short-form mobile video. At TikTok, our mission is to inspire creativity and bring joy. TikTok's global headquarters are in Los Angeles and Singapore, and we also have offices in New York City, London, Dublin, Paris, Berlin, Dubai, Jakarta, Seoul, and Tokyo.
Why Join Us
Inspiring creativity is at the core of TikTok's mission. Our innovative product is built to help people authentically express themselves, discover and connect - and our global, diverse teams make that possible. Together, we create value for our communities, inspire creativity and bring joy - a mission we work towards every day.
We strive to do great things with great people. We lead with curiosity, humility, and a desire to make impact in a rapidly growing tech company. Every challenge is an opportunity to learn and innovate as one team. We're resilient and embrace challenges as they come. By constantly iterating and fostering an "Always Day 1" mindset, we achieve meaningful breakthroughs for ourselves, our company, and our users. When we create and grow together, the possibilities are limitless. Join us.
Diversity & Inclusion
TikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At TikTok, our mission is to inspire creativity and bring joy. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.
TikTok Accommodation
TikTok is committed to providing reasonable accommodations in our recruitment processes for candidates with disabilities, pregnancy, sincerely held religious beliefs or other reasons protected by applicable laws. If you need assistance or a reasonable accommodation, please reach out to us at
Apply to this job
Principal Cybersecurity Analyst, Privacy and Third Party Risk Management
Posted 24 days ago
Job Viewed
Job Description
Job Description
We are seeking a seasoned technical privacy specialist to join our Information Security and Cyber Resilience team.We engage proactively with our business colleagues to truly understand them and to deliver results for our company and for patients. If you thrive in a fast-paced, hands-on, and team-oriented environment where you can have a big impact on the organization, we'd love to talk to you!
The individual in this position will primarily support the Data Technology and Engineering (DTE) Privacy Lead within the Cyber Risk Management and Governance team in representing the Privacy Office, translating policy and privacy standards into requirements within our technical environments. This role will act as a technical subject matter expert on all elements related to data privacy protection and risk mitigation, within the world of DTE, and will also participate in configuring integrations between privacy technologies and other information systems, as well as configuring and testing cookie consent on Vertex's many online properties.
As part of this role, this individual will work with colleagues across DTE on building data protection and security principles into the implementation of new projects and initiatives as well as the development of compliant systems and processes. Sitting within the Information Security group, this role will help drive Vertex's information security strategy and Target State Vision, with the necessary principles and capabilities to make Privacy by Design and Security by Design common practices. It's a small and growing team where you'll get experience working on a broad range of projects.
This position is a global role reporting to the Cyber Risk Management and Governance Director with a dotted line to the DTE Privacy Lead and will be based in Vertex's global headquarters in Boston, Massachusetts. Fully remote and flex options are available to the right candidate.
The designation on this role is Hybrid - meaning three days a week onsite in our Boston office.
Key Responsibilities
- Partnering with DTE and business owners to provide advisory and consulting services around information security and data privacy to drive risk mitigation;
- Assessing current software and systems, as well as partner and vendor services, for compliance with security and data protection principles and recommending changes and new technologies to help mitigate vulnerabilities and prevent potential future risks;
- Defining and implementing risk-based solutions to ensure Privacy by Design and Security by Design are adequately embedded in technical projects and systems across the company;
- Assisting the DTE Third Party Assessment team in the assessment and revision of vendor management processes to ensure that third parties are appropriately vetted prior to engagement;
- Configuring, testing, and maintaining cookie consent technology on Vertex's 100+ websites and apps;
- Configuring integrations between privacy technologies and other technical systems; assisting other Information Security teams as necessary in appropriate integrations for Security and Data Protection;
- Assisting the DTE Privacy Lead and Cyber Risk Management and Governance Director with training and awareness campaigns, particularly with a focus on system security and data protection initiatives;
- Supporting the work of the Cyber Risk and Governance team in maintaining effective processes and controls across our computing environment;
- Assisting the Privacy Office by responding to requests from data subjects to exercise their rights, as needed;
- Providing forensics and technical assistance for any suspected personal data incidents, working with the DTE Privacy Lead and Privacy Office;
- Participating in Information Security and Cyber Resilience team and Privacy Office team meetings;
- Advising on data anonymization, pseudonymization and encryption techniques to develop systems that preserve and improve privacy protections; and
- Working with the DTE Privacy Lead, the Privacy Office, and the Internal Audit function to conduct regular privacy assessments of operational processes, identifying, and mitigating risks across the company.
Qualifications
- BS or MS degree in computer science, computer engineering, information systems, privacy engineering, information security or related field of study; or equivalent professional experience.
- 5 years' experience in information security (preferably focusing on privacy/data protection) or a graduate degree or concentration in privacy engineering
- 3 years' experience configuring integrations leveraging RESTful APIs, OAuth 2.0, and related tooling
- IAPP privacy certifications (CIPT, AIGP, CIPP, or CIPM)
- CISSP or similar security certification
- Technical experience with OneTrust
- Understanding of the principles of information protection and system security practices
- Understanding of best practices in data handling and Privacy by Design
- Familiarity with relevant data protection and information security regulatory requirements
- Experience conducting third party risk assessments
- Experience configuring RESTful API integrations
- Knowledge of data anonymization and cryptographic techniques
- Experience in incident response
- Demonstrated working knowledge of software engineering fundamentals
- Data literacy and forensics
- Attention to detail and accuracy
- Ability to prioritize and complete daily workload and projects with minimal supervision
- Demonstrated teamwork and collaboration skills
- Highly motivated to contribute and grow within a complex area of emerging importance
Pay Range:
$133,600 - $200,400Disclosure Statement:
The range provided is based on what we believe is a reasonable estimate for the base salary pay range for this job at the time of posting. This role is eligible for an annual bonus and annual equity awards. Some roles may also be eligible for overtime pay, in accordance with federal and state requirements. Actual base salary pay will be based on a number of factors, including skills, competencies, experience, and other job-related factors permitted by law.
At Vertex, our Total Rewards offerings also include inclusive market-leading benefits to meet our employees wherever they are in their career, financial, family and wellbeing journey while providing flexibility and resources to support their growth and aspirations. From medical, dental and vision benefits to generous paid time off (including a week-long company shutdown in the Summer and the Winter), educational assistance programs including student loan repayment, a generous commuting subsidy, matching charitable donations, 401(k) and so much more.
Flex Designation:
Remote-EligibleFlex Eligibility Status:
In this Remote-Eligible role, you can choose to be designated as:
1. Remote : work remotely five days per week and come into the office on occasion - you're always welcome on-site; or select
2. Hybrid : work remotely up to two days per week; or select
3. On-Site : work five days per week on-site with ad hoc flexibility.
Note: The Flex status for this position is subject to Vertex's Policy on Flex @ Vertex Program and may be changed at any time.
Company Information
Vertex is a global biotechnology company that invests in scientific innovation.
Vertex is committed to equal employment opportunity and non-discrimination for all employees and qualified applicants without regard to a person's race, color, sex, gender identity or expression, age, religion, national origin, ancestry, ethnicity, disability, veteran status, genetic information, sexual orientation, marital status, or any characteristic protected under applicable law. Vertex is an E-Verify Employer in the United States. Vertex will make reasonable accommodations for qualified individuals with known disabilities, in accordance with applicable law.
Any applicant requiring an accommodation in connection with the hiring process and/or to perform the essential functions of the position for which the applicant has applied should make a request to the recruiter or hiring manager, or contact Talent Acquisition at
Privacy SME (Program Management)
Posted today
Job Viewed
Job Description
TechOp Solutions International is actively looking for a highly qualified and experienced Senior Privacy Subject Matter Expert (SME) to join our dedicated team in supporting the United States Department of State. This pivotal role requires a deep understanding of privacy regulations and best practices, and it presents a unique opportunity to contribute meaningfully to the Department's mission while ensuring the protection of sensitive information.
Key Responsibilities
- Provide privacy expertise and guidance in privacy compliance maintaining privacy posture.
- Serve as the primary point of contact for all privacy concerns facilitating communication and collaboration among all stakeholders.
- Conduct regular reviews and audits of privacy-related practices and provide recommendations for improvements.
- Conduct baseline assessments of the privacy program, present the findings, and make recommendations
- Support FISMA reporting activities by ensuring privacy risks and controls are accurately captured and documented in system security packages.
- Coordinate responses to privacy incidents and support remediation efforts as necessary.
- Prepare detailed reports on program status, issues, and metrics for senior management and stakeholders.
- Develop, review, and maintain privacy compliance documentation: PTAs, PIAs, and SORNs
- Develop and maintain policies, SOPs, playbooks, and training
Requirements
- Bachelor's degree is required
- 6+ years of experience in privacy management, compliance, or related fields (significant federal government experience preferred).
- Program or project management experience.
- Knowledge of federal privacy regulations, policies, and standards, including Privacy Act, E-Government Act, FISMA, GDPR, and CCPA.
- Expert knowledge of OMB A-130, NIST SP 800-53 and NIST SP 800-171
- Strong leadership abilities with experience managing client relationships.
- Excellent communication skills, with the ability to convey complex privacy concepts to diverse audiences.
- U.S. Citizenship is required, and the candidate must meet all security eligibility requirements for the position.
- Active Secret clearance (or higher) at the time of hire.
- Preferred: IAPP Certifications
Risk Management - Liquidity Risk Management - Vice President
Posted 24 days ago
Job Viewed
Job Description
As a Vice President within the Risk Management team, you will collaborate with various business units, corporate treasury, and other risk divisions to gather, comprehend, analyze, and infer potential liquidity risk implications within the firm's operations. You will be responsible for continuously evaluating emerging risks to the firm's liquidity by monitoring the evolving short-term funding markets and presenting your findings to senior management.
**Job Responsibilities**
+ Identify, assess, and monitor liquidity risks related to the firm's activities
+ Provide effective independent risk challenge and oversight on business units and liquidity management teams
+ Undertake analysis of balance sheet changes to assess liquidity risk impacts and provide risk view on day-to-day and longer-term changes in internal liquidity stress scenarios and regulatory prescribed liquidity scenarios (liquidity coverage ratio, net stable funding ratio)
+ Review liquidity forecasts to assess reasonableness and adequacy and to highlight issues and areas of improvement to Treasury and senior management
+ Monitor balance sheet through limits and indicators that are designed to control and monitor liquidity risk
+ Develop and present material for risk committees.
+ Fulfil regulatory requests pertaining to liquidity risk for independent risk management.
+ Articulate key evolving risks to senior management in easy to understand manner.
+ Be involved in second line review and challenge of requirements such as change management, user testing, data and controls review and other matters that impact liquidity risk for product coverage area
**Required qualifications, capabilities, and skills**
+ Minimum 7 years of experience in banking industry across treasury, liquidity risk, market risk and/or trading of fixed income products
+ Understanding of liquidity risk concepts and requirements. Understanding of balance sheet analysis for global banks across traditional banking and complex non-banking products
+ Understanding of the governance and controls surrounding risk monitoring including, stress testing, limits and indicators, and ongoing monitoring
+ Strong grasp of basic financial theory and accounting principles
+ Working knowledge of Excel and PowerPoint
+ Effective verbal and written communication skills and strong attention to detail
+ Bachelor's degree in Finance, Economics, Mathematics or related discipline required
**Preferred qualifications, capabilities, and skills**
+ Experience in Liquidity Risk management with a wide range of experience with quantitative, financial and risk management techniques & systems preferred
+ Experience with stress testing preferred
+ Deep understanding of product knowledge and how it impacts liquidity risks (e.g. deposits, prime brokerage, secured funding, derivatives etc) is a strong plus
JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world's most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.
We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans
**Base Pay/Salary**
New York,NY $138,700.00 - $222,000.00 / year
Risk Management - Liquidity Risk Management - Vice President
Posted 21 days ago
Job Viewed
Job Description
As a Vice President within the Risk Management team, you will collaborate with various business units, corporate treasury, and other risk divisions to gather, comprehend, analyze, and infer potential liquidity risk implications within the firm's operations. You will be responsible for continuously evaluating emerging risks to the firm's liquidity by monitoring the evolving short-term funding markets and presenting your findings to senior management.
Job Responsibilities
- Identify, assess, and monitor liquidity risks related to the firm's activities
- Provide effective independent risk challenge and oversight on business units and liquidity management teams
- Undertake analysis of balance sheet changes to assess liquidity risk impacts and provide risk view on day-to-day and longer-term changes in internal liquidity stress scenarios and regulatory prescribed liquidity scenarios (liquidity coverage ratio, net stable funding ratio)
- Review liquidity forecasts to assess reasonableness and adequacy and to highlight issues and areas of improvement to Treasury and senior management
- Monitor balance sheet through limits and indicators that are designed to control and monitor liquidity risk
- Develop and present material for risk committees.
- Fulfil regulatory requests pertaining to liquidity risk for independent risk management.
- Articulate key evolving risks to senior management in easy to understand manner.
- Be involved in second line review and challenge of requirements such as change management, user testing, data and controls review and other matters that impact liquidity risk for product coverage area
Required qualifications, capabilities, and skills
- Minimum 7 years of experience in banking industry across treasury, liquidity risk, market risk and/or trading of fixed income products
- Understanding of liquidity risk concepts and requirements. Understanding of balance sheet analysis for global banks across traditional banking and complex non-banking products
- Understanding of the governance and controls surrounding risk monitoring including, stress testing, limits and indicators, and ongoing monitoring
- Strong grasp of basic financial theory and accounting principles
- Working knowledge of Excel and PowerPoint
- Effective verbal and written communication skills and strong attention to detail
- Bachelor's degree in Finance, Economics, Mathematics or related discipline required
Preferred qualifications, capabilities, and skills
- Experience in Liquidity Risk management with a wide range of experience with quantitative, financial and risk management techniques & systems preferred
- Experience with stress testing preferred
- Deep understanding of product knowledge and how it impacts liquidity risks (e.g. deposits, prime brokerage, secured funding, derivatives etc) is a strong plus
JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world's most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.
We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans
Base Pay/Salary
New York,NY $138,700.00 - $222,000.00 / year
Be The First To Know
About the latest Privacy management Jobs in United States !
Principal Cybersecurity Analyst, Privacy and Third Party Risk Management (Boston)
Posted 12 days ago
Job Viewed
Job Description
Join to apply for the Principal Cybersecurity Analyst, Privacy and Third Party Risk Management role at Vertex Pharmaceuticals .
Job Description
We are seeking a seasoned technical privacy specialist to join our Information Security and Cyber Resilience team. We engage proactively with our business colleagues to understand their needs and deliver results for our company and patients. If you thrive in a fast-paced, hands-on, team-oriented environment where you can have a big impact, wed love to talk to you!
The individual in this position will support the Data Technology and Engineering (DTE) Privacy Lead within the Cyber Risk Management and Governance team, representing the Privacy Office, translating policy and privacy standards into technical requirements. This role acts as a subject matter expert on data privacy protection and risk mitigation within DTE, configuring integrations between privacy technologies and other information systems, as well as testing cookie consent on Vertexs online properties.
This role involves working with colleagues across DTE to embed data protection and security principles into new projects and systems, supporting Vertexs information security strategy, and promoting Privacy by Design and Security by Design practices. It is a global role reporting to the Cyber Risk Management and Governance Director, with a dotted line to the DTE Privacy Lead, based in Boston, MA, with remote and flexible options.
Key Responsibilities
- Partner with DTE and business owners to advise on information security and data privacy to mitigate risks.
- Assess software, systems, and vendor services for compliance, recommending improvements.
- Implement risk-based solutions to embed Privacy by Design and Security by Design.
- Support vendor management processes for third-party assessments.
- Configure, test, and maintain cookie consent technology across websites and apps.
- Integrate privacy technologies with other systems and assist security teams as needed.
- Assist with training and awareness campaigns on security and data protection.
- Maintain effective processes and controls in the computing environment.
- Respond to data subject requests and assist with data incident forensics.
- Participate in team meetings and advise on data anonymization, pseudonymization, and encryption techniques.
- Conduct privacy assessments of operational processes, identifying and mitigating risks.
Qualifications
- BSc or MSc in computer science, information systems, privacy engineering, or related field, or equivalent experience.
- At least 5 years in information security, focusing on privacy/data protection.
- 3 years configuring API integrations, leveraging RESTful APIs, OAuth 2.0.
- IAPP privacy certifications (CIPT, AIGP, CIPP, CIPM).
- CISSP or similar security certification.
- Technical experience with OneTrust.
- Understanding of information protection principles, data handling best practices, and relevant regulations.
- Experience with third-party risk assessments, data anonymization, cryptography, incident response, and software fundamentals.
- Strong attention to detail, teamwork, and motivation to grow in this emerging field.
Pay Range
$133,600 - $200,400
Additional Information
This role is eligible for bonuses, equity, and comprehensive benefits. The actual salary depends on skills and experience. The position offers flexibility with remote, hybrid, or on-site work options, subject to company policy.
Company Overview
Vertex is a global biotech company committed to innovation and equality. We provide accommodations for applicants with disabilities. For assistance, contact
#J-18808-LjbffrPrincipal Cybersecurity Analyst, Privacy and Third Party Risk Management (Boston)
Posted 12 days ago
Job Viewed
Job Description
Job Description
We are seeking a seasoned technical privacy specialist to join our Information Security and Cyber Resilience team.We engage proactively with our business colleagues to truly understand them and to deliver results for our company and for patients. If you thrive in a fast-paced, hands-on, and team-oriented environment where you can have a big impact on the organization, we'd love to talk to you!
The individual in this position will primarily support the Data Technology and Engineering (DTE) Privacy Lead within the Cyber Risk Management and Governance team in representing the Privacy Office, translating policy and privacy standards into requirements within our technical environments. This role will act as a technical subject matter expert on all elements related to data privacy protection and risk mitigation, within the world of DTE, and will also participate in configuring integrations between privacy technologies and other information systems, as well as configuring and testing cookie consent on Vertex's many online properties.
As part of this role, this individual will work with colleagues across DTE on building data protection and security principles into the implementation of new projects and initiatives as well as the development of compliant systems and processes. Sitting within the Information Security group, this role will help drive Vertex's information security strategy and Target State Vision, with the necessary principles and capabilities to make Privacy by Design and Security by Design common practices. It's a small and growing team where you'll get experience working on a broad range of projects.
This position is a global role reporting to the Cyber Risk Management and Governance Director with a dotted line to the DTE Privacy Lead and will be based in Vertex's global headquarters in Boston, Massachusetts. Fully remote and flex options are available to the right candidate.
The designation on this role is Hybrid - meaning three days a week onsite in our Boston office.
Key Responsibilities
- Partnering with DTE and business owners to provide advisory and consulting services around information security and data privacy to drive risk mitigation;
- Assessing current software and systems, as well as partner and vendor services, for compliance with security and data protection principles and recommending changes and new technologies to help mitigate vulnerabilities and prevent potential future risks;
- Defining and implementing risk-based solutions to ensure Privacy by Design and Security by Design are adequately embedded in technical projects and systems across the company;
- Assisting the DTE Third Party Assessment team in the assessment and revision of vendor management processes to ensure that third parties are appropriately vetted prior to engagement;
- Configuring, testing, and maintaining cookie consent technology on Vertex's 100+ websites and apps;
- Configuring integrations between privacy technologies and other technical systems; assisting other Information Security teams as necessary in appropriate integrations for Security and Data Protection;
- Assisting the DTE Privacy Lead and Cyber Risk Management and Governance Director with training and awareness campaigns, particularly with a focus on system security and data protection initiatives;
- Supporting the work of the Cyber Risk and Governance team in maintaining effective processes and controls across our computing environment;
- Assisting the Privacy Office by responding to requests from data subjects to exercise their rights, as needed;
- Providing forensics and technical assistance for any suspected personal data incidents, working with the DTE Privacy Lead and Privacy Office;
- Participating in Information Security and Cyber Resilience team and Privacy Office team meetings;
- Advising on data anonymization, pseudonymization and encryption techniques to develop systems that preserve and improve privacy protections; and
- Working with the DTE Privacy Lead, the Privacy Office, and the Internal Audit function to conduct regular privacy assessments of operational processes, identifying, and mitigating risks across the company.
Qualifications
- BS or MS degree in computer science, computer engineering, information systems, privacy engineering, information security or related field of study; or equivalent professional experience.
- 5 years' experience in information security (preferably focusing on privacy/data protection) or a graduate degree or concentration in privacy engineering
- 3 years' experience configuring integrations leveraging RESTful APIs, OAuth 2.0, and related tooling
- IAPP privacy certifications (CIPT, AIGP, CIPP, or CIPM)
- CISSP or similar security certification
- Technical experience with OneTrust
- Understanding of the principles of information protection and system security practices
- Understanding of best practices in data handling and Privacy by Design
- Familiarity with relevant data protection and information security regulatory requirements
- Experience conducting third party risk assessments
- Experience configuring RESTful API integrations
- Knowledge of data anonymization and cryptographic techniques
- Experience in incident response
- Demonstrated working knowledge of software engineering fundamentals
- Data literacy and forensics
- Attention to detail and accuracy
- Ability to prioritize and complete daily workload and projects with minimal supervision
- Demonstrated teamwork and collaboration skills
- Highly motivated to contribute and grow within a complex area of emerging importance
Pay Range:
$133,600 - $200,400Disclosure Statement:
The range provided is based on what we believe is a reasonable estimate for the base salary pay range for this job at the time of posting. This role is eligible for an annual bonus and annual equity awards. Some roles may also be eligible for overtime pay, in accordance with federal and state requirements. Actual base salary pay will be based on a number of factors, including skills, competencies, experience, and other job-related factors permitted by law.
At Vertex, our Total Rewards offerings also include inclusive market-leading benefits to meet our employees wherever they are in their career, financial, family and wellbeing journey while providing flexibility and resources to support their growth and aspirations. From medical, dental and vision benefits to generous paid time off (including a week-long company shutdown in the Summer and the Winter), educational assistance programs including student loan repayment, a generous commuting subsidy, matching charitable donations, 401(k) and so much more.
Flex Designation:
Remote-EligibleFlex Eligibility Status:
In this Remote-Eligible role, you can choose to be designated as:
1. Remote : work remotely five days per week and come into the office on occasion - you're always welcome on-site; or select
2. Hybrid : work remotely up to two days per week; or select
3. On-Site : work five days per week on-site with ad hoc flexibility.
Note: The Flex status for this position is subject to Vertex's Policy on Flex @ Vertex Program and may be changed at any time.
Company Information
Vertex is a global biotechnology company that invests in scientific innovation.
Vertex is committed to equal employment opportunity and non-discrimination for all employees and qualified applicants without regard to a person's race, color, sex, gender identity or expression, age, religion, national origin, ancestry, ethnicity, disability, veteran status, genetic information, sexual orientation, marital status, or any characteristic protected under applicable law. Vertex is an E-Verify Employer in the United States. Vertex will make reasonable accommodations for qualified individuals with known disabilities, in accordance with applicable law.
Any applicant requiring an accommodation in connection with the hiring process and/or to perform the essential functions of the position for which the applicant has applied should make a request to the recruiter or hiring manager, or contact Talent Acquisition at
#J-18808-LjbffrDirector of Data Protection - Technology Risk Management
Posted today
Job Viewed