Senior Privacy Analyst
As a Sr. Privacy Analyst, you will be responsible for performing essential activities associated with Privacy Program, as well as contributing to other programs within the Corporate Information Security and Privacy department. Successful fulfillment of job responsibilities will be achieved through a combination of direct ownership of components of the Privacy Program, as well as through managing key business partners' priorities to ensure compliance objectives are met. This is a subset of the overall responsibilities which involves other multiple initiatives as assigned by Corporate Risk leadership.
As part of Corporate Information Security and Privacy (CISP) team, the mission is to identify threats, vulnerabilities, and risks and to help protect the people, information, and services within the organization. CISP works closely with all lines of business.
- Provide essential support to incident response program, including evaluating and advising on privacy ramifications of information security incidents, identifying root causes and contributing to corrective actions and process improvements.
- Design and/or implement controls and processes that align with the requirements of the Gramm-Leach-Bliley Act ( GLBA ), General Data Protection Regulation ( GDPR ), Healthcare Insurance Portability and Accountability Act ( HIPAA ), U.S. state privacy laws (such as the California Consumer Privacy Act or CCPA ) and the NIST Privacy Framework.
- Maintain enhanced knowledge of the above privacy laws, regulations and frameworks, as well as laws relating to data breach notification.
- Regularly monitor, inventory, assess and suggest improvements to data privacy practices across all lines of business.
- Perform periodic risk assessments to evaluate existing controls and practices for design and performance effectiveness, including identification of areas throughout the organization that are in need of risk assessments.
- Provide support to other adjacent programs, including records management and information security and privacy external communications.
- Proactively develop and maintain effective relationships with business partners across the organization.
- Lead special projects and other duties as assigned.
- Proactively develop and maintain effective relationships with business partners across Legal, Risk Management, Audit, IT, Operations, and Business Development.
Requirements:
- You have a Bachelor's degree from an accredited college or university
OR
equivalent work experience. - You have at least 3 years of experience in Risk Management, Compliance, Audit, Information Technology, Project Management, or similar disciplines.
- You have the initiative to work towards a relevant certification (i.e. CIPP/US, CIPM, CIPT through the IAPP).
- You have intermediate knowledge of privacy and/or information security incident response.
- You have proven demonstrated experience in the field of data privacy including but not limited to knowledge of the privacy laws, regulations, and frameworks.
- You can independently execute complex tasks with limited manager oversight and guidance.
- You have successfully made independent, risk-based decisions to escalate to management as needed.
About Us
ECCO Select is certified as a Women-owned, Minority-owned, Small Business Enterprise. We are a talent acquisition and advisory consulting company, specializing in providing people, process, and technology solutions for our clients' needs. ECCO Select has experience in assisting our commercial and government clients successfully manage projects and programs that transform their business operations through a variety of IT solutions. We're the talent behind the technology. To find out more about ECCO visit www.eccoselect.com
Our Commitment
We would love to have you join our team! ECCO Select is committed to hiring and retaining a diverse workforce. ECCO Select's policy is to provide equal opportunity to all people without regard to race, color, religion, national origin, ancestry, marital status, veteran status, age, disability, pregnancy, genetic information, citizenship status, sex, sexual orientation, gender identity or any other legally protected category.
Equal Employment Opportunity is The Law
This Organization Participates in E-Verify