
Analyst II - Data Risk & Privacy Operations (IN)
- Pune, Maharashtra
- Permanent
- Full-time
Reporting to the Privacy Lead, the Data Risk & Privacy Analyst II will assist the privacy lead in leading the development, implementation and monitoring of the privacy program to align with corporate strategy and to meet state/federal/international regulatory requirements. This position formulates recommendations for mitigation of enterprise privacy risks and promotes a culture of Privacy By Design.PRIMARY DUTIES AND RESPONSIBILITIES:
- Lead complex regulatory privacy risk assessments using privacy tool One Trust based on the requirements of the Global Privacy Operations team to ensure compliance with the corporate privacy policies, standards and/or federal/state/international privacy requirements.
- Conduct reviews, analysis and research on current, proposed, and newly adopted privacy laws and regulations to advise management on the impact to the business. Monitor, identify, interpret and map privacy regulatory requirement changes and their impact across the enterprise.
- Lead privacy projects to include new businesses into global privacy program develop new or improve business processes to ensure compliance with newly adopted privacy laws and regulations.
- Review and consult on complex enterprise initiatives to determine compliant data use, permissible data sharing, and minimum necessary access requirements to ensure compliance with state/federal/ international privacy requirements, including HIPAA, GDPR, CCPA, etc.
- Conduct due diligence, review and ongoing monitoring of high-risk vendors that will send or receive personal information to identify and mitigate privacy risks. Partner with the vendor and the Business Unit to mitigate known privacy risks.
- Postgraduate Degree in a Related Field – [e.g., Data Protection, Compliance, or Business Law] OR Bachelor of Laws (LLB)
- 5 years of experience in privacy compliance within a federally regulated industry with international business operations.
- Experience/familiarity with OneTrust
- Desired:
- Certified Information Privacy Professional (CIPP-EU) certification and/or legal experience in privacy and AI governance.
- Experience of conducting privacy assessment DPIA/TIA on privacy management tool like OneTrust.
- Strong knowledge of and experience in interpreting federal/state/international and industry privacy laws, regulations, legal opinions, and providing guidance related to the identifying, interpreting and applying regulatory related issues and activities to business practices.
- Demonstrated strategic planning and leadership skills; ability to motivate and influence company associates at all levels across the organization to comply with regulatory standards.
- Excellent analytical, problem solving and negotiating skills. Ability to effectively present information and respond to questions from groups of managers, employees and Business Unit Privacy Liaisons.
- Ability to work effectively and efficiently in pressure situations and demonstrate a high level of flexibility in a rapidly changing environment while handling complex assignments simultaneously.
- Ability to work independently with strong, strategic planning and organizational skills; self-motivated and directed, adaptable, team focused and detail oriented.
- Demonstrated experience in writing, communication and presentation skills. Personal computer skills to include competency with Microsoft Office Word, Excel, Power Point, Outlook, and Smart Sheet.
- 6- 8 years of experience in Data Privacy, Privacy Operations
- Education: Bachelor’s Degree in related field of study
- Possible certifications - FIP, CIPP/E, CIPM, OneTrust, and BigID (preferred)
- Hands-on work with General Data Protection Regulation (GDPR), CA Consumer Privacy Act (CCPA) along with an extensive track record in executing organization-wide privacy compliance & governance tasks, including Privacy Impact and Data Protection Impact Assessments.
- Experience required:
- Handling of day-to-day privacy operations and strategic Data Protection Impact Assessment (DPIAs), including incident management, mailbox monitoring, data protection queries, and consolidating multiple DPIAs into single assessments for single business processes.
- Evaluation and enhancement of an overall Data Protection, Data Privacy, and Responsible AI strategy for a client engagement.
- Detail oriented mindset with strong analytical skills
- Excellent communication skills with the ability to collaborate effectively across departments.